﻿File SHA1:5d9c4bbcf02faf47d504086f0b1931af29eb9625
Attention：

Tools execute contents：

Run SOS

Total Items

Create Log file

Show Message Box
此清毒工具已成功為您清除電腦中的惡意程式,建議您重新開機並更新防毒軟體病毒碼再進行系統掃瞄.\r\n\r\n若仍偵測到病毒及惡意程式,趨勢用戶請將桌面上的Upload.zip檔回傳趨勢科技技術服務中心作進一步的分析\r\n\r\n謝謝！
Certain malicious code of registry and files are deleted. Please ensure to reboot and do the complete scan with the latest pattern. If there is still malware unable to be cleaned or deleted, please send the 'Upload.zip' file on your desktop to Trend Micro Technical Support Center for further analysis. Thank you.
Version 39 update 2\r\nAnnounce date 2011/05/16
親愛的用戶您好:\r\n\r\n此清毒工具會刪除特定的惡意機碼與檔案,執行前請先暫時關閉電腦中的防毒軟體\r\n\r\n執行過程花費時間將視您的電腦效能及存在的惡意程式數量而定,請耐心等候,謝謝!
Dear Sir,\r\n\r\nThis program is customized according to your information. It will delete certain malicious code of registry and files and only for one-time use. You can click 'Clean' to run the program, thank you!

Stop TrendMicro Service

Disable specific services
123
Atiw
DescriptionHero2
360xxx
DevSvc
dfg
dfthfde
dfx
dggggh
dh
DHCP clienko
DhcpRpcLocator
Atlw258
di-r
Distributed Agent Services
1231231
361iaCeener
Distribuynv
djksa3069jkds
dkaron
DllHst
dllos
DllService
Attrdh
dmserverWmiApSrv
DMusicq
DNSHost
DOBDZGGK08
3cc6aec3
DriveHealth
Driver Desktop
drmkaudr
drtesm
dsafds
21A73
dsefc
dsfg45fj
dsgdfjghjrfrdg
dsjno
dtesm
3JYTQFG0Y4
dticem
Dtorm DCOS Sarvice
dwaq
dx
Atz
dyckdd
dztmdpeq
E5B5C058
E6733DB5
E7D0G765
E7E3FP8S48
3s
E8569209NSH
e8e18360
EA23A528
AuthariPation enP
eaf
edas
edewr
efrgt
ehResvc
EhttpSrv
ekrn
3ss
eoi1iev1e0io
erf
AuthISvc
Ergses Dnxdltxc Vrl
ersfer
ertesm
erx
escd
Esent Utl
Even Log
Event Logs
4Help32
EvtSvc
Automatic Updates.
evxx
F350155625K
F41747390K
F6941060
faes
faf
fci
fdcd
fdfdf
51KZHJ
avg8dw
fdos
fe
fef
feos Service
fffff
ffobly
fggggg
fghgfsdewe DDOS Service
FgxjiA
fhcscw
avg8mc
5CE18F38
fhddos Service
fhgos Service
fhhgfs Service
fhos Service
filar
filpp
FireFox
FireFox2
FLEXnet
1Z8JZZBD3K9O
AVP-SE
foxshell
5QVN4
foxwei
fqwerts Service
frae
frrd
frsgv
fs
FSBMUGBRLZRAHS
fsdfdg
AVP璃
fsdfs
fsdgs Service
60DFXFVR1
fsf
Fsiuvj Xycjdpcv Jdu
Fsruly Rmfostic Qfh
FsSvce
FsUsbExService
fxddos Service
fxlxc
aw
fy
fyuh
GarenaPEngine
32936173
76a1c9a0cb088633
GbHwLib
gbycn
geftei
gews
gfssdg
AwavenbssNum.
ggcrq
ggg
ggtfs
gjunj
Gmeqfpmgi
76EFD247
GmPna
GNKOCGINY
gpgftxf
GrayPigeon_Hacker.com.cn
360_Ssfe Serves
GrayPigeon_www.hmhk.cn
GrayPigeonServer
gs
gsdg
gsg
gt
77A35JV4CDXN
gtrdf
guvkygwoa
gyuapq
AwsopsdscNum
H5266EAAOK1V
hackfans
hdds Service
hdos
hdt
hhwyamxbm
hiserver
798VUVX
hjkaCwlzww
hjkjxx
AxIntSvc
HkmSrv
host
hostword
hrhgres
htdhg
htkhg
HTTP SSSL
huikhxh
8qezSbRT
hvacxd
B004CE7C
hyhyx
I2SNLW1WNFPF
icf
IdsSrv
IEudinit
ieur82
ihzaq
Iidihir
Iihvcw Kjwqnyts Sxc
8SWVG35R
ba
Ijgdux Ubhvbgsv Vtc
ijzab
ijzaq
IKEEXTENDv3.0
IKEEXTENDv3.2
ILP7Q6
infh
inHelp323444
init
iopmn
BackGround switch
945820X
iozaq
Ip6Fwq
IPRIP
IpwoAbw
iqqzab
iqzai
Iraccess
irmons
iszaq
Ati2esxx
Backup_Info
itqzab
9742C68A
IUACR7WR67
IVTR6B3QM1
ivzai
iwqzab
iyzab
IzagDvq
izzab
JAVA 6.5 Servcie Sun
Baidu
JavaQuick987
javk
9867E6CA
jaxk
jdlwjd
jfdxlizd
jfmy
jfwk
jgok
JHA6WL3
banp
jhfk
jhks
jhwuxv
9ORFQ6
Jjsgyxtfq
jmlqhktstqivc
jmoplqd
jmrovk
jpok
jqdk
bbb
jqfa
jqka
jqqk
jqtk
199854331
9XP0P
jqza
jtsk
jwam
jwfa
bbbbbbbbbb
jwig
jwrk
jwtg
jwtk
kaghkfl4
Kaspersky
a2free
kaspersky 7.0
Kaspersky Avp
Kaspersky AVP Setup
360diaCymfyb
kavsvc
Kbqphrqfi
KBXQ5Y2
kerne132
kernel32
kgqexlse
KihjOkx
aajjelnf
KingDsnid
KingDuuBa
bd
KingDuuBa A
Kingsoft Antivirus WebShield Service
KISSvc
klan
Klerter
koon
KPfwSvc
kqlfjoyd
aamvm
krtesm
bdbh
ktesk
KtmRmSrv
KtmSvc
KVSrvXP
kyqgdth
Launcher
Lcgvcp Aqhxrwbf Iqu
lcvibf
Lheoze
aasyytv7nq3r5a
BFB67F19
LiveServer mode
LmHots
Logman
lpjbht
LSAService
LtdSrv
lz2vnyhiaowie
Made in China DDoS
mbfrdgh
mbpiccvaid
bfddos
abp470n5
mbxwpo
McAfee Framework Servicrre
McAfeeFramework
MccdQaf
McComponentHostService
mchInjDrv
MD ServicesB1
mdefdf60
Media_Service
Ati2evxx
BfeSrv
MediaC
acernbm
MediaCanter
MediaCblldr
MediaCbrfty
MediaCentar
MediaCenter
MediaCentsder
MediaClkunl
MediaCmbzbl
bfgse244
MediaCniptq
MediaCqwqqs
acpi24
MediaCzxczxenter
MediaeCenterr
MediaSerial
MediayCentern
MediayCenterx
MedigCenter
MeedidCnter
BGd Switch
Messcnger
mfc42
mfc43
acpi32
Microsoft
Microsoft Updateblk.exe
Microsoft Updatelel.exe
Microsoft Updateryb.exe
Microsoft Updatezsl.exe
Microsoft VC80 MFCLOC
BitSrv
MiyaAyf
MMeica
ModemUSB
morkbd
acpi64
mrtesm
ms driver management service
MS Server Pretect
MS service dasdasd
MS Softwar Provider
BrcSrv
msan
MSCCom
mserv
MSImanage
MsiSrv
vxx
ActiveSMART Service
MSJDrvr
MSNETService
MSNSVR
Browse
MstInit
Ms-tl_Srv
Mstsc
msupdate
MSUpdqexbx
MSUpdqtehhk
msurl
ad
mtlrd
MynuCdt
360FY
MytuaCrtmlv
MyWebSearchService
mzaq
n hj
nabift
NAF0SOO
National
National Web CC
ada
National2.0
BrSerName
Nationaljrq
Nationallms
Nationallrj
Nationalmed
Nationalorn
NationalSer1.31
Nations
ndg
NesSrv
admin_service_svcname
brtdgxx
NetActive
NetClient
NEtDesvc
NetHomeIDE
Netlogin
netnls
NetPortShare
NetSharing
NETSVCS_0x0
NetSystem
bsf
ADMon
NetWare
Network Service
Network Services
NetworkAgentServices
Networks Locatin1 Aarenes
nfhy
ngkjrx
nj
nko_Service
Ati2ezz
btddos
nlymjsnx
adsnds32
NMSAccessU
nopsr
notdm
NoteBook
notesy
notgs
notwq
NrConnmags
btdh
Nsddyye
NSTOP
adsz
NtfsSvc
NTS
nvowxovq
O2SCBUS
oasnp
ockuy
OdhhJti
BTDSOS
OfklLru
ofpehzhd
oniney
AdvanceLink
OSEvent
OSS
otvtsidxz
OutpostFirewall
pang
pang9
buk
panp
pbfzmh
pbmrjv
PersonalPolice
advxx
PeService
PEVSystemStart
PisbTng
PLASvc
PLSRemoteSvc
bvaz
PlugPlayCM
pneua
Pnoioeucs
PnP plug 0n Service
PnpEnum
adw
pqjqjiw
Provides Media Center
Providesv1.2
Provitep abfsdgitb ao
bvy4,^ac1122
Provitep abfsdgitc ao
pyaxexyb
pyhhzvo
QEZCIV
qnommwq
qos
.Net CLR
AE239D9B
qpelotf
qq
cacwikpf
QQ MUSCIC
QQ Music update2
QQ Music update3
qq2
QQOoAO
qqraq
QQ秞氈
qrsytc
aecr
QS RSVP
360rp
QTTAAH7Q
querdgne
qweqweqweqwe
qzmcoimd
r_server
ramb
RavCCenter
rBpqhvFC
rc
aede
CbEvtSvc
rcmdsvc
Remote Storm Service
remotePCS
RemoteStorage
RemoteStorages
RemoteStormService
rere
rerr
restorer64_a
rf
CC2E5C7D
Aeeu
rFFrrox2
rfrr
rfs
rfy
rihdvx
rising
rising beijing
Rising Task0
RiSingKaKa
Ati2o
cdadsa
RiSingKaKaa
Aeevg
RiSingKaKaaer
RjixGta
rjzrgg
rock32 room
rpcs
rpcsvc
rrr
rsdg
cdas
rsgfr
rwjrbbfdm
AExpSrv
rwx
rYHlGiiZ
rylboz
sad
SafePrecatl
SafePrecpco
satey Service
cee
saves
SAVScan
scan
af
scelogonos
SCH0ST
ScpSrv
scvst
sdegdfgwe DDOS Service
sdewgfdge DDOS Service
CF1.5
sdfashue
sdfever
sdsweer32
sdtbns Service
AfaService
SdxName
Seagate Sync Service
Seagate Sync Service.
SeagateSyncServica
SeagateSyncService
CF1.6
sectolr
Security Bios Management
Seekeen Service
SENSMGR
Serv
afdsfds
server this
serverdk
Service
Service Controler Installer
cfv
Service.exe
serviceJS
servicev2.1
Servicev2.2
SesEnv
SessMgr
Afeu
setuplog
sfadz
sfdfa
chuguanghui
sfr
sjb1100e
skdos
SlrlFil
SmbAdpSrv
SmbApSrv
smss
.norton2009Reset
afnqxvng
smss.exe
cl200961
smssv.exe
SpecialPolice
spool.exe
spoolsvn
SqlDebuger
srgr
srivec
Sroervice
ssl
AgentSrv
360safe
ssswxplore
ssx
stgwe
Storm DDOS Service
stp Service
Sun Java 6.5 Service jdk
svchost
svchost.exe
svcname
svost
cld
agnmd
svxabnebj
swice
sxdrcb
sxx
sxxx
sxzx
syitgyvdz
synsend
sysgif32
Atishirt01
clddos
SysMains
agxeoo
systemaaaa ls
taad
taan
tacq
tads
tafc
tafl
tago
clos
takax
takfl
ajbcyk
takgu
takjl
takqz
taksw
talg
talo
tame
CmSTP
tamp
taop
tapiessNum
Alefrfeter
taqs
tasmq
tawg
tawm
tawp
taxx
CNGSrv
tazj
tcim
Tcpip0
Tcpsrvn
alert computer
TCPZ
Tencent QQ 2010
TesSrv
test1
test2
ComRepl
test22
testbb
tetye
tfraq
tgsno
alga
tgth
thgtrxx
thspaf
tkauvyfo
conime
tksso
tkwvoohvn
TolzEep
TrafficCtrl
Trewsor
Trojan
AlgSvc
Trqartebdp
trtesm
tscbs.exe
Cpq355elufa
tskdcsryp
tsraq
tstm
tt
ttaxxvuw
ttesk
ttos
Amffun Wswanyna Jec
TtslSog
txfyat
Cqytfk Dvtteujn Qyw
txlpe
Txplatform
txqqc
txqqe
tzaq
u7t
UACklltprrj
UAU7IN0T5M96
?B???t?B?
AMSSvc
CRE85ZMUYNW
UCKTFOXGPYH
UCLVHQZISBK
UhwoWsn
uhxbuexj
uj
ujftiq
umxnep
UsIxFRFp
Utility Mangserver
utk
360Tay
AniSrv
uuua9aicoue3
UV74N
uydrbg
V90drv
vare
VaultSrv
vchose
vcsdaz
vd
Ativxx
Cryptographic Service
VDLUFOXGSBK
annruljl
veast
vfd
vfdgt
vfs
vfsd
vGADown
vhost
VisionService
cs1.3
VMdDZgZo
VogpKwj
Antivirus Pro 2010
vrea
vrgv
vrs
vrsegb
vs
vsd
vse
cs1.4
vsfd
vsgv
vsr
AppropSren
vsrf
vsrfr
vsvas
vsx
vuovpiopxoqx
vvWJKhpz
cs1.5
vwqfhx
vxx a
vyjh
vytbrqk
APT9Z15L78E
w
WajiSvc
WbioSrv
WbWin
wckko
D6442DEB
WcsSrv
wedr
Weemi Service
weevx
wef
argxx
WefpGui
weqianj
weqjn
wewsee360
darkshell Server
wfsintwq
Wib5n4p32
Wib5n64p32
Wicump32
wilusbmonitor
win
arvlcuv
windosyw
Windows Adio
windows conler
dasd
Windows Help System
Windows Live Server
Windows Managemuirw
windows save server
Windows Search Page Down.
Windows Service Updates
Windows systems safe
asd
Windows Update!
Windows XP 假載陔
dasno
Windows_rejoice2010
Windows_Update
WindowsEntMianFeiV08
Windows-pass
WindowsRemote
WindowsYouti
Windriversrv32
windswe
AsiSrv
WinDX9
dassx
Winfe32
WinHbnbancaelp32
WinHe95
WinHeaqqwcxzlp32
WinHees32
WinHelduoyudehiyi
WinHelp
WinHelp2
WinHelp3
1c5a43f0155e9c67
dbdcbd60
askdtw
WinHelp32
WinHelpbs32
WinHfdselp32
WinHlp32
WinHtoxuanan
Winistelp32
WinKissdPS
WinLests32
winloginsav
Ativz
360tray
Winows
Aspnet_stater
WinQJServiceNow
winrarese
WinSCCOM
winsedx.com.cn
WinService
WinSSCOM
wintkser
wintyf
dbghelp
winvideodril
Witingsp32
aspsnet
wjjaq
WmdmPmSp
wmguldzxi
wmiApSvc
WmiSvc
wmitpfs
WMMNetworkKtx
dbsno
WMMNetworkRwa
wpa
WRF1NXEJ
ASPX
wsem
WSIVS
wtesk
WumenHelp32
wups
WVSSVC
DC693BD0
Wwgcen Deypvvpm Ccg
www.skd4s.com
www.skdos.com
www.skdqs.com
aswFsBlk
wyssbdad0
wzaq
Wzrd- Application
x
XB1OBMCVHZLC
dcafd
xbapd
xcrmu
xepnjk
xiezuebg
xiezuihr
ASWLSVC
xiezukcrs
xiezuoja
XieZurbi
xiezuvtj
DcomLaunchs
XjhgGle
xmgqdtk
XPZDP6
Xueeueusz
Xurcsiuzi
xxdos
AsyncMacq
ytfj
ytwys
yuwtnf
dcvxx
ywmzp
yxtje
yyiyhmpg
zasnp
ZdN55hm4
zgwjxiycbnwphz
ZhuDongFangYu
Atfg
zoklvj
zscgunvice
ddx
ztnssbw
Ati2e
Ati2enn
deade
DescriptionHero123321

Stop specific services
123
Atiw
DescriptionHero2
360xxx
DevSvc
dfg
dfthfde
dfx
dggggh
dh
DHCP clienko
DhcpRpcLocator
Atlw258
di-r
Distributed Agent Services
1231231
361iaCeener
Distribuynv
djksa3069jkds
dkaron
DllHst
dllos
DllService
Attrdh
dmserverWmiApSrv
DMusicq
DNSHost
DOBDZGGK08
3cc6aec3
DriveHealth
Driver Desktop
drmkaudr
drtesm
dsafds
21A73
dsefc
dsfg45fj
dsgdfjghjrfrdg
dsjno
dtesm
3JYTQFG0Y4
dticem
Dtorm DCOS Sarvice
dwaq
dx
Atz
dyckdd
dztmdpeq
E5B5C058
E6733DB5
E7D0G765
E7E3FP8S48
3s
E8569209NSH
e8e18360
EA23A528
AuthariPation enP
eaf
edas
edewr
efrgt
ehResvc
EhttpSrv
ekrn
3ss
eoi1iev1e0io
erf
AuthISvc
Ergses Dnxdltxc Vrl
ersfer
ertesm
erx
escd
Esent Utl
Even Log
Event Logs
4Help32
EvtSvc
Automatic Updates.
evxx
F350155625K
F41747390K
F6941060
faes
faf
fci
fdcd
fdfdf
51KZHJ
avg8dw
fdos
fe
fef
feos Service
fffff
ffobly
fggggg
fghgfsdewe DDOS Service
FgxjiA
fhcscw
avg8mc
5CE18F38
fhddos Service
fhgos Service
fhhgfs Service
fhos Service
filar
filpp
FireFox
FireFox2
FLEXnet
1Z8JZZBD3K9O
AVP-SE
foxshell
5QVN4
foxwei
fqwerts Service
frae
frrd
frsgv
fs
FSBMUGBRLZRAHS
fsdfdg
AVP璃
fsdfs
fsdgs Service
60DFXFVR1
fsf
Fsiuvj Xycjdpcv Jdu
Fsruly Rmfostic Qfh
FsSvce
FsUsbExService
fxddos Service
fxlxc
aw
fy
fyuh
GarenaPEngine
32936173
76a1c9a0cb088633
GbHwLib
gbycn
geftei
gews
gfssdg
AwavenbssNum.
ggcrq
ggg
ggtfs
gjunj
Gmeqfpmgi
76EFD247
GmPna
GNKOCGINY
gpgftxf
GrayPigeon_Hacker.com.cn
360_Ssfe Serves
GrayPigeon_www.hmhk.cn
GrayPigeonServer
gs
gsdg
gsg
gt
77A35JV4CDXN
gtrdf
guvkygwoa
gyuapq
AwsopsdscNum
H5266EAAOK1V
hackfans
hdds Service
hdos
hdt
hhwyamxbm
hiserver
798VUVX
hjkaCwlzww
hjkjxx
AxIntSvc
HkmSrv
host
hostword
hrhgres
htdhg
htkhg
HTTP SSSL
huikhxh
8qezSbRT
hvacxd
B004CE7C
hyhyx
I2SNLW1WNFPF
icf
IdsSrv
IEudinit
ieur82
ihzaq
Iidihir
Iihvcw Kjwqnyts Sxc
8SWVG35R
ba
Ijgdux Ubhvbgsv Vtc
ijzab
ijzaq
IKEEXTENDv3.0
IKEEXTENDv3.2
ILP7Q6
infh
inHelp323444
init
iopmn
BackGround switch
945820X
iozaq
Ip6Fwq
IPRIP
IpwoAbw
iqqzab
iqzai
Iraccess
irmons
iszaq
Ati2esxx
Backup_Info
itqzab
9742C68A
IUACR7WR67
IVTR6B3QM1
ivzai
iwqzab
iyzab
IzagDvq
izzab
JAVA 6.5 Servcie Sun
Baidu
JavaQuick987
javk
9867E6CA
jaxk
jdlwjd
jfdxlizd
jfmy
jfwk
jgok
JHA6WL3
banp
jhfk
jhks
jhwuxv
9ORFQ6
Jjsgyxtfq
jmlqhktstqivc
jmoplqd
jmrovk
jpok
jqdk
bbb
jqfa
jqka
jqqk
jqtk
199854331
9XP0P
jqza
jtsk
jwam
jwfa
bbbbbbbbbb
jwig
jwrk
jwtg
jwtk
kaghkfl4
Kaspersky
a2free
kaspersky 7.0
Kaspersky Avp
Kaspersky AVP Setup
360diaCymfyb
kavsvc
Kbqphrqfi
KBXQ5Y2
kerne132
kernel32
kgqexlse
KihjOkx
aajjelnf
KingDsnid
KingDuuBa
bd
KingDuuBa A
Kingsoft Antivirus WebShield Service
KISSvc
klan
Klerter
koon
KPfwSvc
kqlfjoyd
aamvm
krtesm
bdbh
ktesk
KtmRmSrv
KtmSvc
KVSrvXP
kyqgdth
Launcher
Lcgvcp Aqhxrwbf Iqu
lcvibf
Lheoze
aasyytv7nq3r5a
BFB67F19
LiveServer mode
LmHots
Logman
lpjbht
LSAService
LtdSrv
lz2vnyhiaowie
Made in China DDoS
mbfrdgh
mbpiccvaid
bfddos
abp470n5
mbxwpo
McAfee Framework Servicrre
McAfeeFramework
MccdQaf
McComponentHostService
mchInjDrv
MD ServicesB1
mdefdf60
Media_Service
Ati2evxx
BfeSrv
MediaC
acernbm
MediaCanter
MediaCblldr
MediaCbrfty
MediaCentar
MediaCenter
MediaCentsder
MediaClkunl
MediaCmbzbl
bfgse244
MediaCniptq
MediaCqwqqs
acpi24
MediaCzxczxenter
MediaeCenterr
MediaSerial
MediayCentern
MediayCenterx
MedigCenter
MeedidCnter
BGd Switch
Messcnger
mfc42
mfc43
acpi32
Microsoft
Microsoft Updateblk.exe
Microsoft Updatelel.exe
Microsoft Updateryb.exe
Microsoft Updatezsl.exe
Microsoft VC80 MFCLOC
BitSrv
MiyaAyf
MMeica
ModemUSB
morkbd
acpi64
mrtesm
ms driver management service
MS Server Pretect
MS service dasdasd
MS Softwar Provider
BrcSrv
msan
MSCCom
mserv
MSImanage
MsiSrv
vxx
ActiveSMART Service
MSJDrvr
MSNETService
MSNSVR
Browse
MstInit
Ms-tl_Srv
Mstsc
msupdate
MSUpdqexbx
MSUpdqtehhk
msurl
ad
mtlrd
MynuCdt
360FY
MytuaCrtmlv
MyWebSearchService
mzaq
n hj
nabift
NAF0SOO
National
National Web CC
ada
National2.0
BrSerName
Nationaljrq
Nationallms
Nationallrj
Nationalmed
Nationalorn
NationalSer1.31
Nations
ndg
NesSrv
admin_service_svcname
brtdgxx
NetActive
NetClient
NEtDesvc
NetHomeIDE
Netlogin
netnls
NetPortShare
NetSharing
NETSVCS_0x0
NetSystem
bsf
ADMon
NetWare
Network Service
Network Services
NetworkAgentServices
Networks Locatin1 Aarenes
nfhy
ngkjrx
nj
nko_Service
Ati2ezz
btddos
nlymjsnx
adsnds32
NMSAccessU
nopsr
notdm
NoteBook
notesy
notgs
notwq
NrConnmags
btdh
Nsddyye
NSTOP
adsz
NtfsSvc
NTS
nvowxovq
O2SCBUS
oasnp
ockuy
OdhhJti
BTDSOS
OfklLru
ofpehzhd
oniney
AdvanceLink
OSEvent
OSS
otvtsidxz
OutpostFirewall
pang
pang9
buk
panp
pbfzmh
pbmrjv
PersonalPolice
advxx
PeService
PEVSystemStart
PisbTng
PLASvc
PLSRemoteSvc
bvaz
PlugPlayCM
pneua
Pnoioeucs
PnP plug 0n Service
PnpEnum
adw
pqjqjiw
Provides Media Center
Providesv1.2
Provitep abfsdgitb ao
bvy4,^ac1122
Provitep abfsdgitc ao
pyaxexyb
pyhhzvo
QEZCIV
qnommwq
qos
.Net CLR
AE239D9B
qpelotf
qq
cacwikpf
QQ MUSCIC
QQ Music update2
QQ Music update3
qq2
QQOoAO
qqraq
QQ秞氈
qrsytc
aecr
QS RSVP
360rp
QTTAAH7Q
querdgne
qweqweqweqwe
qzmcoimd
r_server
ramb
RavCCenter
rBpqhvFC
rc
aede
CbEvtSvc
rcmdsvc
Remote Storm Service
remotePCS
RemoteStorage
RemoteStorages
RemoteStormService
rere
rerr
restorer64_a
rf
CC2E5C7D
Aeeu
rFFrrox2
rfrr
rfs
rfy
rihdvx
rising
rising beijing
Rising Task0
RiSingKaKa
Ati2o
cdadsa
RiSingKaKaa
Aeevg
RiSingKaKaaer
RjixGta
rjzrgg
rock32 room
rpcs
rpcsvc
rrr
rsdg
cdas
rsgfr
rwjrbbfdm
AExpSrv
rwx
rYHlGiiZ
rylboz
sad
SafePrecatl
SafePrecpco
satey Service
cee
saves
SAVScan
scan
af
scelogonos
SCH0ST
ScpSrv
scvst
sdegdfgwe DDOS Service
sdewgfdge DDOS Service
CF1.5
sdfashue
sdfever
sdsweer32
sdtbns Service
AfaService
SdxName
Seagate Sync Service
Seagate Sync Service.
SeagateSyncServica
SeagateSyncService
CF1.6
sectolr
Security Bios Management
Seekeen Service
SENSMGR
Serv
afdsfds
server this
serverdk
Service
Service Controler Installer
cfv
Service.exe
serviceJS
servicev2.1
Servicev2.2
SesEnv
SessMgr
Afeu
setuplog
sfadz
sfdfa
chuguanghui
sfr
sjb1100e
skdos
SlrlFil
SmbAdpSrv
SmbApSrv
smss
.norton2009Reset
afnqxvng
smss.exe
cl200961
smssv.exe
SpecialPolice
spool.exe
spoolsvn
SqlDebuger
srgr
srivec
Sroervice
ssl
AgentSrv
360safe
ssswxplore
ssx
stgwe
Storm DDOS Service
stp Service
Sun Java 6.5 Service jdk
svchost
svchost.exe
svcname
svost
cld
agnmd
svxabnebj
swice
sxdrcb
sxx
sxxx
sxzx
syitgyvdz
synsend
sysgif32
Atishirt01
clddos
SysMains
agxeoo
systemaaaa ls
taad
taan
tacq
tads
tafc
tafl
tago
clos
takax
takfl
ajbcyk
takgu
takjl
takqz
taksw
talg
talo
tame
CmSTP
tamp
taop
tapiessNum
Alefrfeter
taqs
tasmq
tawg
tawm
tawp
taxx
CNGSrv
tazj
tcim
Tcpip0
Tcpsrvn
alert computer
TCPZ
Tencent QQ 2010
TesSrv
test1
test2
ComRepl
test22
testbb
tetye
tfraq
tgsno
alga
tgth
thgtrxx
thspaf
tkauvyfo
conime
tksso
tkwvoohvn
TolzEep
TrafficCtrl
Trewsor
Trojan
AlgSvc
Trqartebdp
trtesm
tscbs.exe
Cpq355elufa
tskdcsryp
tsraq
tstm
tt
ttaxxvuw
ttesk
ttos
Amffun Wswanyna Jec
TtslSog
txfyat
Cqytfk Dvtteujn Qyw
txlpe
Txplatform
txqqc
txqqe
tzaq
u7t
UACklltprrj
UAU7IN0T5M96
?B???t?B?
AMSSvc
CRE85ZMUYNW
UCKTFOXGPYH
UCLVHQZISBK
UhwoWsn
uhxbuexj
uj
ujftiq
umxnep
UsIxFRFp
Utility Mangserver
utk
360Tay
AniSrv
uuua9aicoue3
UV74N
uydrbg
V90drv
vare
VaultSrv
vchose
vcsdaz
vd
Ativxx
Cryptographic Service
VDLUFOXGSBK
annruljl
veast
vfd
vfdgt
vfs
vfsd
vGADown
vhost
VisionService
cs1.3
VMdDZgZo
VogpKwj
Antivirus Pro 2010
vrea
vrgv
vrs
vrsegb
vs
vsd
vse
cs1.4
vsfd
vsgv
vsr
AppropSren
vsrf
vsrfr
vsvas
vsx
vuovpiopxoqx
vvWJKhpz
cs1.5
vwqfhx
vxx a
vyjh
vytbrqk
APT9Z15L78E
w
WajiSvc
WbioSrv
WbWin
wckko
D6442DEB
WcsSrv
wedr
Weemi Service
weevx
wef
argxx
WefpGui
weqianj
weqjn
wewsee360
darkshell Server
wfsintwq
Wib5n4p32
Wib5n64p32
Wicump32
wilusbmonitor
win
arvlcuv
windosyw
Windows Adio
windows conler
dasd
Windows Help System
Windows Live Server
Windows Managemuirw
windows save server
Windows Search Page Down.
Windows Service Updates
Windows systems safe
asd
Windows Update!
Windows XP 假載陔
dasno
Windows_rejoice2010
Windows_Update
WindowsEntMianFeiV08
Windows-pass
WindowsRemote
WindowsYouti
Windriversrv32
windswe
AsiSrv
WinDX9
dassx
Winfe32
WinHbnbancaelp32
WinHe95
WinHeaqqwcxzlp32
WinHees32
WinHelduoyudehiyi
WinHelp
WinHelp2
WinHelp3
1c5a43f0155e9c67
dbdcbd60
askdtw
WinHelp32
WinHelpbs32
WinHfdselp32
WinHlp32
WinHtoxuanan
Winistelp32
WinKissdPS
WinLests32
winloginsav
Ativz
360tray
Winows
Aspnet_stater
WinQJServiceNow
winrarese
WinSCCOM
winsedx.com.cn
WinService
WinSSCOM
wintkser
wintyf
dbghelp
winvideodril
Witingsp32
aspsnet
wjjaq
WmdmPmSp
wmguldzxi
wmiApSvc
WmiSvc
wmitpfs
WMMNetworkKtx
dbsno
WMMNetworkRwa
wpa
WRF1NXEJ
ASPX
wsem
WSIVS
wtesk
WumenHelp32
wups
WVSSVC
DC693BD0
Wwgcen Deypvvpm Ccg
www.skd4s.com
www.skdos.com
www.skdqs.com
aswFsBlk
wyssbdad0
wzaq
Wzrd- Application
x
XB1OBMCVHZLC
dcafd
xbapd
xcrmu
xepnjk
xiezuebg
xiezuihr
ASWLSVC
xiezukcrs
xiezuoja
XieZurbi
xiezuvtj
DcomLaunchs
XjhgGle
xmgqdtk
XPZDP6
Xueeueusz
Xurcsiuzi
xxdos
AsyncMacq
ytfj
ytwys
yuwtnf
dcvxx
ywmzp
yxtje
yyiyhmpg
zasnp
ZdN55hm4
zgwjxiycbnwphz
ZhuDongFangYu
Atfg
zoklvj
zscgunvice
ddx
ztnssbw
Ati2e
Ati2enn
deade
DescriptionHero123321

Terminate specific processes
97378
dasno.exe
dqi.exe
legyr.exe
_is86.exe
20344.exe
lenschk.exe
lerestarter.exe
LFE87.tmp.exe
lgameboot.exe
lgcadwx.bat
lgnaqil.exe
lgrncie.bat
Driveinfo.exe
lgvg8q.exe
lhwdcgcb.bat
libor.exe
2097.exe
LicenseMan.exe
Lilo.exe
Lin123.exe
LinkWinRGB.exe
lisvus.exe
livehelp.exe
11977387950.exe
livemessenger.com
livepeek.exe
liveplay.exe
liveseek.exe
21.exe
livetest.exe
livetiny.exe
livewood.exe
lizkavd.exe
lj.exe
drsvc.exe
lj6hdv.com
ljahv.exe
ll.exe
llhost.exe
lljyn081012.exe
21018101.exe
lljyn081014.exe
lljyn081221.exe
lljyn081228.exe
llwzjy081008.exe
drsvc12.exe
lme.exe
lnoniesvr.exe
logman.exe
Logo1_.exe
logon.exe
lousrs.exe
21122625.exe
Love info.exe
love.exe
lp3c.bat
drtesm.exe
lpanvgofcekoxm.exe
lphcv1cj0el40.exe
LPHULE6.EXE
lpryl.exe
lrg.exe
lsacms.exe
LSASS32.EXE
211234.exe
lsasss.exe
lsasvc.exe
ds.exe
LSERVICE.EXE
lsfjg.com
lsg6jj9.exe
lskeqbfc.exe
lssada999996.exe
ltc.bat
ltcna.exe
ltt.exe
2211.exe
lttime.exe
dsakfsak14.exe
lulu.exe
luyi.exe
lvmsoicons.exe
lvofflb.exe
lwd.bat
lwh.exe
lwhypertrm.exe
LWWR1.EXE
lyhwcea.exe
2214.exe
dsevos.exe
LYLeador.exe
LYLoadar.exe
LYLoadbr.exe
LYLoader.exe
LYLoadhr.exe
LYLoadmr.exe
LYLoador.exe
LYLoadqr.exe
lymstore.exe
lypeer.exe
dsfg45fj.exe
222.exe
lytavib.com
m.bat
m.exe
M001.exe
M001[1].exe
m02w2mop.exe
m1sql.exe
M3HIGHIN.EXE
M3IMPIPE.EXE
daso.exe
dsfids6.exe
M3MEDINT.EXE
2222222222222222.exe
M3SKPLAY.EXE
M3SLSRCH.EXE
m3SrchMn.exe
m6dqm2vd.exe
m6n.com
m7F5xSG70T_2263.exe
m8wafly.com
m9as2c.cmd
dsfs.exe
macjie.exe
mactool.exe
1073764
_is87.exe
2234.exe
Mags Play.exe
mahefo.bat
mail pile.exe
mail.exe
MalwareRemovalBot.exe
dsjjowsadm.exe
manol.exe
MASetupCleaner.exe
mathhopeping.exe
max.exe
maxjvq.exe
22p.exe
mayyuk9g.bat
mbcwriter.exe
mbewb2n.exe
Mbition.exe
_god.exe
Mcaerfe.exe
Mcca360.exe
McCHSvc.exe
mcsql.exe
MCWR0.EXE
mdelk.exe
231346E28D27.exe
mdllhost.exe
mdsl.exe
mdsql.exe
11d9o.exe
mduaeyk.exe
MDUQNR91.lnk.exe
mduzhl.exe
me.exe
MEDIA WAVE.exe
MediaPlayer_update.exe
meex.exe
2323.exe
mfc.bat
mfc42.exe
dsjno.exe
mfc43.exe
MFile.EXE
mFormat.exe
mfrsx.exe
mg.exe
mgsxnm.exe
mh.exe
mHotMon.exe
23281.exe
mhso.exe
Dsnid.exe
micca.exe
ming9a090213.exe
ming9b090423.exe
mircosk.exe
mka.bat
mkawgk.exe
mknygffd.exe
mkrgsc.exe
mldtpro.exe
23518.exe
dsty.com
mm6q.exe
mmchcfg.exe
MMM.exe
mmsql.exe
mmvo.exe
mnmsaccess.exe
mnso.exe
momo.exe
mon.exe
monms.exe
dtesm.exe
238781L.exe
monobj.exe
monsvc.exe
More mode long.exe
mosetup.exe
motr.exe
mouma.exe
mpdssm.exe
MpfSrv.exe
MPGR2.EXE
dts12.exe
mpproflwiz.exe
23ft.exe
mprtsclib.exe
mpsql.exe
mpstxgx.exe
mrghykh.exe
mrjj.exe
mrsne.bat
mrtesm.exe
msa.exe
dasvchost.exe
DuBa.exe
msan.exe
msbackup.exe
24464.exe
msbb.exe
mscs24.exe
msdate.exe
msdsc.exe
msexe.exe
MsgPlusUninstall.exe
msiexecs.exe
Duck.exe
msips.exe
MsMpEng.exe
msmsgrs.exe
24478.exe
msn.exe
msn_sl.exe.exe
msn080.exe
msnhostin.exe
msnmsgrs.exe
msnmsgs.exe
dudo.exe
msnsmgr.exe
msnsrv.exe
msnsvr.exe
mss.exe
_is88.exe
2461UKAAITT.exe
msseces.exe
mssrv32.exe
mstestbot.exe
mstinit.exe
duexcel.exe
mstmpxmldown.exe
mstranscoder.exe
mstsc.exe
msurl.exe
msword98.exe
mt.com
24966656.exe
mt0.cmd
mtlhieej.cmd
mtvwizard.exe
dv6pp.exe
Music.exe
muzapp.exe
mvbvz.exe
MVDNXGP.EXE
mvdw20.exe
mws.exe
mwsoemon.exe
24C493E0.EXE
mwsoemon.exe
mwssvc.exe
12.exe
mxtintlphr.exe
myccdd090118a.exe
myccdd090908a.exe
MyLoverMain.exe
mynkn.exe
MyPicture.exe
myself.exe
MyService.exe
24yO5072.exe
MySQL.exe
dvhyi.exe
myteviw.bat
MYThunder.exe
mzaq.exe
mznhizvw.exe
mzptedit.exe
mzyqmh.exe
n.bat
n.com
n.exe
26500.exe
dwaq.exe
n1235002834k.exe
n1235005667k.exe
n1235045094k.exe
n1235046101k.exe
n-168888192k.exe
n-168963568k.exe
n1m.exe
n1v93rqo.exe
N2-1EEDB.EXE
N2-56E76.EXE
dwfvi.exe
26962.exe
n29al.exe
N2-ECFFF.EXE
n6j6pc0.com
n89f1d1w.exe
natrok.exe
nbke.exe
nBwhGyYIndfV.exe
ncc.exe
ncpeer.exe
dwgrun.bat
nde.exe
26xjvg.exe
nderliveud.exe
ndexstoresvr.exe
ndmego0f.cmd
NDNuninstall4_50.exe
NDNuninstall4_80.exe
NDNuninstall5_64.exe
NDNuninstall6_10.exe
NDNuninstall6_22.exe
Daswsky.exe
dx.exe
NDNuninstall6_30.exe
NDNuninstall6_38.exe
2747.exe
ndowsxp-kb918997-v6-x86-cht.exe
ndpinball.exe
NeroStartSmart.exe.exe
NeSrv.exe
net.bat
net.exe
NetBot.exe
DX6LRB.exe
NetClient.exe
netcx.exe
netfx35setup.exe
27712.exe
netinstaller.exe
netmon.exe
netsrv.exe
netvdm.exe
netview.exe
NetWare.exe
dxatdfyk.exe
NetworkAgentServices.exe
NEVABE30.EXE
nevase.exe
NEVBEDFB.EXE
27727.exe
new.exe
new2[1].exe
new5[1].exe
new6[1].exe
NewClickTest.exe
DXDLG.exe
newsvalue.exe
NEWTEMP.BAK
NewTemp.bkk
Next1.exe
nfg.exe
_is8D.exe
27C7FD.EXE
ngg.exe
ngokwl0px1y6t.exe
ngq6hva0.exe
dxv.bat
ngt-gxp.exe
ngxkub.exe
nhg.exe
ninstall.exe
nissan.exe
nk.exe
nkmsoxmled.exe
281434.EXE
nmje9v6d.bat
nmkwj.exe
dxwName.exe
nmoffprov.exe
NMSAccessU.exe
nmurnxp.exe
nncu6kk.com
nnnn.exe
nntimidity.exe
nnxnxayj.exe
noniesvr.exe
28145.exe
nooakkv.exe
120468.exe
Norton2009Reset.exe
notdm.exe
notepod.exe
notesy.exe
notex.exe
notgs.exe
notgx.exe
notso.exe
notwq.exe
28898.exe
dxx.exe
nowmm.exe
np.exe
nq.bat
nqgcd.com
nqyltsy.exe
nrfinder.exe
NRmq1l44p.exe
nrmsimport.exe
Nsddyye.exe
nskmu.exe
Dycwywa.exe
2899A9.EXE
nstall.exe
nsv.bat
nt6ry3bn.cmd
ntaossvc.exe
ntdeiect.com
ntdelect.com
NTDETECT.EXE
ntdll64.exe
ntnq.exe
dymso7ftp.exe
ntos.exe
29124D4AA81F.exe
ntoskrnl.exesvcuvjqc.exe
ntphyy.com
nts.exe
ntserver.exe
nvikernel.exe
nvrfc.bat
nvsvc.exe
nw.exe
1101.exe
dynrn6e.cmd
nw0t1l0d.exe
nxvhpc.exe
29358.exe
ny36jjt.exe
nyat.exe
nylig.exe
nypqlaunch.exe
nzpqlaunch.exe
nzscanpst.exe
O.cmd
dyr2j6mv.exe
o.exe
o6opnro.bat
o6pq1n8.com
2995.exe
o93ml8.bat
o9o2.com
o9o2u.bat
oabws.exe
oaemwq.exe
oaljb6.exe
dyunrar.exe
oasnp.exe
obg.exe
objctf.exe
objmon.exe
2ACE4CFBAF2C.EXE
obsubstrip.exe
obtpf.bat
oc.cmd
ocbqsqj.bat
ocgien.exe
e.cmd
ockuy.com
odb.exe
odectweaktool.exe
odehehelib.exe
odexl.exe
2dxy1kc.exe
oeicwtutor.exe
OELQ8BU8.exe
ofdic.exe
oggdsuninst.exe
e.exe
ogleupdaterservice.exe
oigdfgdfl1.exe
oikcec.exe
ok1.exe
ok26[1].exe
okafb.exe
_is92.exe
2E2352.EXE
okcb32.exe
okclview.exe
E001.exe
okelg.exe
okewb.exe
okhr.exe
oklssrvc.exe
okyou.exe
ol.exe
olhrwef.exe
om.cmd
2eac1tm.exe
om0.com
e00233it.com
only hack.exe
oogdsmux.exe
oogleupdate.exe
oosoldls.exe
op.bat
opatentactivation.exe
opxypc.exe
opxyzq.exe
opxzab.exe
2FECE7.EXE
123123.exe
oqrxab.exe
ordw15.exe
ormpft.exe
oruwumymyp.bat
OSA9.EXE
osau.exe
osidrivert.exe
ot.exe
ot2.exe
otesm.exe
e0t9n6.exe
2fxt.exe
otf.cmd
otfixdownloader.exe
Other.exe
oticwconn2.exe
otnetinstaller.exe
ototypef.exe
ouildls.exe
oujutw.exe
oUrVPuPddVDgXoF.exe
e25178468t.exe
OutlOk2.exe
2g.com
ouuninst.exe
ovision.exe
ovq.exe
ox.cmd
OX-77299.EXE
oypatcher.exe
oypeerconf.exe
ozyace8q0vq.exe
dasxcsx13.exe
e3fa4e3fa248.exe
p.bat
p.cmd
2go30q.com
p.exe
P_AX_CAB_INSTALLER.exe
P001.exe
p0sc9t.cmd
p1t.bat
p3r1ud.exe
P5GIJGB.exe
E5ED8BC94A26.exe
p8ihdw.exe
p9.exe
pamn.exe
2h60k.cmd
pang.exe
pang9.exe
panp.exe
patp.exe
pbwkwj.COM
pcabyo.exe
e6.com
pcces.exe
PCCSet.exe
pchkh.cmd
pctools.exe
2jqj.bat
pcxyqr.exe
pdate_taiwan.exe
pdateisetup.exe
pdater.exe
pdbinfo.exe
e619e.cmd
pdbsrv.exe
Pe.exe
PEAK HECK.exe
PeServer.exe
pesobin.exe
2ohwUveEqL_2263.exe
pew61qeftdgqocw.exe
pffknfr.exe
pgking.exe
pgplgi.exe
e656lklfs5.exe
pgzfge.exe
photfixdownloader.exe
photo_id.exe
pikachu.exe
piljg.exe
pjhypertrm.exe
2ov3.exe
pjwtv.cmd
pkmstordb.exe
pksetexd.exe
E6IEG.EXE
pksvc.exe
pkxfkrki.bat
Player.exe
plbckgzm.exe
pllq.exe
ploice.exe
PLSRemote.exe
_isAD.exe
2px8tdn.bat
plxmpboot.exe
e898.com
pmiw4sp.exe
pnc.exe
polo.exe
poolfwc.exe
poolinfo.exe
Pop3trap.exe
popo.exe
post.exe
poviqaxi.com
2Sy.exe
e8main5.exe
powerwordlite.33626.813692.exe
PP.exe
pp05.exe
pp06.exe
PP-773C.EXE
pp-c967.exe
ppinbnp9.exe
pps.exe
pptpobj.exe
pqolreg.exe
12B71F3A.EXE
2w.exe
pqtwdz.exe
prevhndlrshim.exe
prjydpe.cmd
Proc Ace Log Vc.exe
proclsa.exe
procsrv.exe
prosetup.exe
psass.exe
psdhw.exe
eadf6s.exe
psecurity.exe
2y8la.exe
psgame_silent.exe
pstreamsetup-update1204.exe
ptbvhyrb.exe
pufuecv.exe
puiqkmw.exe
puninst.exe
put120.exe
puuleadweb.exe
dateisetup.exe
ealsched.exe
PV-773C.EXE
pvuimetool.exe
3.exe
pwicwtutor.exe
pwv.exe
px.bat
PX990401.exe
pxayzp.exe
pxbn6y.exe
pxexcelcnv.exe
ealtrimmer.exe
pygfwlive.exe
pytnmk.exe
q.bat
300y.cmd
Q.exe
Q[1].exe
Q001.exe
q0rppr.exe
q10js.exe
q1pady.cmd
eamoc.exe
q2.exe
q2vl2fiy.com
q550cpwp.exe
Q5-841A5.EXE
30152.exe
Q687B1D8.EXE
q83iwmgf.bat
Q8W7CTQU9.exe
q92k1pmu.exe
qabopx.exe
EB264CA3.EXE
qamogolipu.bat
qanhllaok.exe
qaois.exe
qb.exe
qb1.exe
304BB248.EXE
QB6816E3.EXE
qbbms.exe
qdunzip.exe
qedw15.exe
EB6C4499B05F.exe
qfile.exe
QG0XK2.exe
qghok.exe
qgsoci.exe
qh.cmd
QI31FBB0.EXE
3069.exe
QI33D4BD.EXE
qidyhixad.exe
qikal.com
eb9ehyh.exe
qjatw9aj.exe
qjfl.exe
qjso.exe
qkarc.exe
qkolx.exe
QLFQ2.EXE
qlmplayerc.exe
30c0e.cmd
qlunzip.exe
qmc.exe
ebhrtzzm.exe
qmqkq.exe
qngbvkhl.exe
qotdyl.bat
qpaybq.exe
qpe6.com
qpose.exe
QQ166859.EXE
QQ1ED1A2.EXE
_isAE.exe
30D54BF98859.exe
ebug.exe
QQgame.exe
QQmjVp.exe
qqq.exe
qqs3.exe
qr.exe
qrdialer.exe
qrmsaccess.exe
qs6m.bat
qsclview.exe
qserwija.exe
ebynowakib.exe
30ed3.exe
qsid8g.exe
QT65A959.EXE
qtplugin.exe
qtwm.exe
qumigrate.exe
quozobous  .exe
quozobous .exe
quozobous.exe
QV6C2DD3.EXE
130[2].exe
qvwmccds.exe
317836M.exe
qweqwe.exe
qwuphclean.exe
QX503B62.EXE
QX5DC8A1.EXE
qx7d6a7d.exe
QXELUBIPX.EXE
qxpaop.exe
qxzv26.exe
dbdgd.exe
EC43F6.EXE
qxzv26.exe@
qxzv85.exe
31AB48B7A1FE.exe
qxzv85.exe@
qyasplnchr.exe
QYGO7.EXE
qyswc.exe
R.bat
r.com
r.exe
ec5e.exe
r02014.exe
r05015.exe
r07004.exe
31n3b2h.exe
r08023.exe
r09022.exe
r1.exe
r120.bat
r12015.exe
r19031.exe
eceu.exe
r22023.exe
r23014.exe
r24012.exe
r27011.exe
32[1].exe
r27019.exe
r28003.exe
r2mkn.exe
r8wb.bat
r9ghv9.com
ecmplayerc.exe
rabbit[2].exe
ragonica.exe
rai.exe
Rainmeter.exe
rasctf.exe
32[2].exe
rashreporter.exe
rasim.exe
rasms.exe
rat.exe
ecn.com
ravcopy.exe
RavHelp.exe
RAVQJ.EXE
ravuusee.exe
raybpq.exe
razclientm.exe
32[3].exe
rbmcdlc.exe
rbsetup.exe
rckywlq.exe
ediainfo.exe
rcpi.exe
rcunwise.exe
rdassist.exe
rdeugekmhlaeswtu.exe
re32.exe
re47.exe
reader_s.exe
32[4].exe
real gram.exe
RealAV.exe
edsetlang.exe
realplay.exe
realplayerupdate.exe
RECserverj.exe
Recycle.exe
Recycled.exe
Reg.bat
REGEDIT.COM
regedit32.com
32[9].exe
regedit32.exe
eeditor.exe
regsvr32.exe
rehsas.com
rejoice2009.exe
Remove.exe.exe
Restore.exe
restorer32_a.exe
restorer64_a.exe
revo.exe
rf.cmd
_isEF.exe
eeqt.exe
321109.exe
RF1PBY9JAZEL.exe
rhcju0j0ea41.exe
RI770RKVH.EXE
ringttek.exe
rintingdialog.exe
rioemig50.exe
riprep.exe
risabc.exe
RiSing.exe
eewordpad.exe
RiSinge.exe
322791.exe
RiSinger.exe
rit.exe
rjiybg.exe
rjlix.exe
rjx0.exe
RL4HXEB0QPP9.exe
rlicwtutor.exe
RLM6RZA.com
dblnq.exe
130[5].exe
rlv.exe
rmfile.exe
32391.exe
rmhpfiui.exe
rmsca.exe
rmydqsiw.exe
rn.exe
rndll.exe
rocheck.exe
rock32.exe
eexn.exe
rogadgetcmserver.exe
ropatentactivation.exe
rorescueagent.exe
32446.exe
rosearchadvanced.exe
rotoolbarcomm.exe
rotoolbarupdate.exe
rpcc.exe
RpcS.exe
rqhag.exe
eftwl.exe
rrobpu.exe
rs32net.exe
RsTray.exe
rtnlpipu.com
32495.exe
rttrwq.exe
rude.bat
rudwtrig20.exe
ruhiquoobu.exe
rundl132.exe
eg1.cmd
Rundll.exe
rundll32.exe
runnuu.exe
runonce.exe
runsql.exe
32o3.cmd
runundrv.exe
rv36m1f9.exe
rvertool.exe
RVI6E20SQHH7.EXE
ehem.com
RVPWL8.exe
rwrte.exe
RWVB0.EXE
rxso.exe
RYEMUAHOWC.EXE
rynbdraef.exe
337234.exe
rysoundman.exe
s.exe
S001.exe
EHttpSrv.exe
S002.exe
S1.exe
S10.exe
S2.exe
s2vgyp.exe
S3.exe
s3_1.7.9.002003_from_1.6.6.002003.exe
3443734.exe
s3_update1.6.6.exe
s38k.exe
eikaw.exe
s39tg.cmd
s3ls2.exe
S4.exe
S5.exe
s555.exe
S5P60.EXE
s6.bat
S6.exe
351BE5E0.EXE
s660.exe
eito.exe
s6muem.cmd
S7.exe
S8.exe
S87ekhV.exe
S9.exe
s9l.exe
sa.jpg.exe
saace.exe
Safe Browse.exe
3561781.exe
ejoq.exe
safeboxTray.exe
safesys(2).exe
safesys(20).exe
safesys(21).exe
safesys(22).exe
safesys(37).exe
SafeSys.exe
SafeTest.exe
sal.exe
sarah_and_me_having_fun_in_bed.exe
EjzOX.exe
_msbackup.exe
35C4496FB94C.exe
sass.exe
sassinscreed_launcher.exe
sassum.exe
sasyg1y8.com
saw110.exe
sawvu.exe
sBiLfGvINagxmit.exe
sbwvyck.exe
dboycao.exe
ek.com
scbf.exe
SCH0ST.EXE
35e.exe
sch0sts.exe
scnet.exe
scout.exe
scphlh.exe
ScrDebugThat.exe
scrhost.exe
scrker.exe
13136.exe
SCtri.exe
scvhost.exe
scvst.exe
3602v.exe
sdc.bat
sdebugconfig.exe
sdra64.exe
sdsawq345.exe
sdtartup.exe
se11.cmd
eksdlfs5.exe
Seagat.exe
secbm.exe
secp.exe
secpol.exe
360FY.exe
secu.exe
senvjces.exe
seres.exe
serivces.exe
Serve.exe
ell.exe
server.exe
Server[1].exe
server2010.exe
Servers.exe
ServerXp.exe
360Geywt.exe
Service.exe
services.com
servises.exe
SETTINGS WAY HEART DRAW.exe
ELWR5CPVX5M.exe
setup_iesuper_0010130.exe
Setup_ver1.1431.0.exe
setup000.exe
setup1027.exe
setup1519.exe
setuplog.bat
360rp.exe
setuppp22.exe
setupyoyo.exe
SetWallpaper.cmd
em8fiv0.exe
sewdebgh.exe
sfcfdmsc.exe
SfCtlCom.exe.exe
sffgkk.exe
sffvxx.exe
sfghdfsw.exe
sfsetup.exe
360rptt.exe
sgcxcxxaspf090323.exe
sgcxcxxaspf090415.exe
emawmq.exe
sh.exe
sh17011.exe
shadu.exe
shareb.exe
Shell.exe
shengji.exe
shenren.exe
shishi.exe
360safefix.exe
shostt.exe
emb.exe
shvhost.exe
sie2v8.exe
sigcheck.com
sinashi.exe
siounins.exe
sis121b_upgrade.exe
sis121c_upgrade.exe
SiZhu.exe
sk1.exe
360Safetray.exe
eminu.com
skd4s.exe
skdos.exe
skdqs.exe
sktjn.exe
slcskxsdl7.exe
slive.exe
slphfx.bat
slq.exe
sm.exe
sm12v.exe
encoder.exe
360tay.exe
smaya.exe
smb.exe
SmcSVR.exe
smeviewer.exe
smsc.exe
smserv.exe
SMSS.bat
smss32.exe
smsss.exe
.exe
dboysb.bat
enger.exe
smssv.exe
_MSRSTRT.EXE
360tizrhdx.exe
smvss.exe
snaoc9i.exe
sndvols.exe
snss.exe
snuvcdsm.exe
snxwpqea.exe
SocksA.exe
enn.exe
Soft(240).exe
Soft(241).exe
SofwareUpdater.exe
360tray.exe
Sogou.exe
somkvmerge.exe
sonine.exe
soulost.exe
sound.exe
sound1.exe
1342A9.EXE
soundmin.exe
sovhst.exe
sovnost.exe
SP00.exe
361.cmd
spkr9wou.bat
SplshWrp.exe
spolssv.exe
spolusv.exe
spoolsvc.exe
enot.exe
SpyEmergency.exe
spywareguard.exe
SpywareRemover.exe
sqccss.exe
sql.cn.exe
361bzefo.exe
sqlserv.exe
SQLupdate.exe
sqwce.exe
SRCatbgcerp.exe
EntMian.exe
SRCHost.exe
SRCost.exe
sremove.exe
srivec.exe
sruqe.exe
srvdns.exe
36Osafe.exe
srvobj.exe
ss_src1_setup.exe
ssassinscreed_dx10.exe
eomso7ftps.exe
ssdal_nc.exe
sser.exe
SServer2010.exe
ssl.exe
start.bat
STDSB.exe
stesm.exe
37160del.bat
stgwe.exe
sticwrmind.exe
eoo1.exe
stnetlib.exe
stoolbarinstaller.exe
StopAllWorwA.exe
StopAor.exe
STT4735Z0A8.exe
stwi.com
STYQI21E.exe
suchost.exe
383875.exe
SUFBLL.exe
ep2k_certd_bc.exe
sunny.exe
SuoL5.exe
supervisor.exe
suqfl.exe
susos.exe
sv.exe
SV-773C.EXE
svc.exe
svcghos4t.exe
38s3i.exe
ep2k_mon_bc.exe
svcgnhw.exe
SVCH0ST.EXE
svchest.exe
svchoct.exe
svchos.exe
svchosc.exe
svchost -k spool.exe
svchost32.exe
SVCHOSTED.exe
svchovst.exe
eplkn.exe
3902.exe
svchqs.exe
svcigyec.exe
svcklfce.EXE
svclost.exe
svcst.exe
SVDH0ST.exe
svhcsots.exe
svhcuots.exe
svho.exe
dbsno.exe
EPSONREG.EXE.exe
svhosgy.exe
397d.exe
svhost.exe
svhost1.exe
svhost10.exe
svhost32.exe
svhost4.exe
svhoster.exe
svhosts.exe
sviq.exe
eqiwpjs0onfd.exe
SVMCOS.exe
svmssc.exe
_re47.exe
39ysi89.com
svost.exe
svw.exe
svx.exe
svzip.exe
swdtpro.exe
swice.exe
eqymmc.exe
swreg.com
SWUQUHTO.exe
swymq.exe
sxvhsot.exe
3bo9tn.cmd
sychost.exe
syf.exe
syl.exe
sys32_nov.exe
SysAnti.exe
139039text.exe
sysbar.exe
SYSCFG16.EXE
sysguard.exe
Sysitem.exe
SysLive.exe
3CC74E3FA246.exe
sysmgr.exe
syssafe.exe
system.BAK
system.bat
er.exe
System.exe
system16.BAK
system32.exe
system32StopAor.exe
system4.exe
systema.exe
3CC74E3FA248.exe
systempkb32.exe
SystemSafer.exe
systex.exe
eraseme_03267.exe
systim32.exe
systm.exe
sysumt.exe
sysutils.exe
Sysvxd.exe
syykiq.exe
t.bat
3ce.exe
t.cmd
t.exe
eraseme_03517.exe
t1xdgvq.exe
t2f.exe
t2jDx9PgC.exe
t2jl.exe
t2ydo.exe
t3.com
t82e2v.cmd
ta_ep32.exe
3config.exe
ta1.exe
eraseme_05366.exe
ta2.exe
taacecnflt.exe
taad.exe
taan.exe
tacq.exe
tads.exe
tafc.exe
tafl.exe
tagg.exe
3dohrt.com
eraseme_06143.exe
tago.exe
takfl.exe
takgg.exe
takgu.exe
takjl.exe
takqz.exe
taksw.exe
talg.exe
talo.exe
tame.exe
eraseme_20423.exe
3ds.cmd
tamp.exe
tan3yt.bat
taop.exe
taqs.exe
tar.exe
tasb32.exe
taskcore.exe
taskmagr.exe
taskmgrs.exe
dc.exe
eraseme_22657.exe
taskrg.exe
3ehxs6.cmd
tasmq.exe
tasmrs.exe
taso.exe
tavo.exe
tawg.exe
tawm.exe
tawp.exe
taxx.exe
eraseme_24452.exe
tazj.exe
tb.cmd
3ff70larq.exe
TBCOJK732K9H.EXE
tbhje.cmd
tbsetup(-33554365).exe
TC-486.EXE
TC-566.EXE
TC-686.EXE
TC-766.EXE
eraseme_25500.exe
TC-776.EXE
tcburi.exe
tcim.exe
1147018
_rejoice2009.exe
3g3.exe
tcppsap.exe
tcpsov1.exe
tcpsov3.exe
tcpsov4.exe
eraseme_54143.exe
tcpsov5.exe
tcpsov6.exe
tcpsov7.exe
tcpsvr1.exe
tcpsvr2.exe
tcpsvr3.exe
3hihyi.exe
tcpsvrs1.exe
tcpsyi2.exe
tcpsyi3.exe
_is1.exe
TC-WZ5.EXE
TC-WZ6.EXE
TC-WZ7.EXE
tdeviewer.exe
teemm386.exe
tem.exe
Tem1B.tmp.exe
3iugonx.com
Tem1D.tmp.exe
temp.exe
141c3811-d4b5-c6ef-7749-b4bd77a5169d.exe
temp1.exe
temp2.exe
temp28.exe
TempFile(1).exe
temsmsgs.exe
temtunermain.exe
TERegPct.exe
test.exe
3jkka91.com
test1.exe
eraseme_55345.exe
test2.exe
testbb.exe
tewmplayer.exe
tfa8rk6.com
tfasplnchr.exe
tfffmpeg.exe
tfimepadsv.exe
tfraq.exe
tfwq.exe
3jkkdo.exe
eraseme_61152.exe
tg.com
tgbpl.exe
tgfloppyme.exe
tgnwcdex.exe
tgpjgo.exe
tgsno.exe
tgtighg.cmd
thghikva.exe
thii09.exe
thread.exe
eraseme_66428.exe
3N-537580.EXE
thrqi.exe
thrvlf.exe
thtxx.exe
Thunkdeafgreat.exe
thwmproedt.exe
tigi.cmd
tikett.exe
Tilecomfree.com
timessquare.exe
eraseme_67822.exe
tinlater.exe
3o0fp.exe
Tinue.exe
TISSuprt.exe.exe
tj8odymw.exe
TJEnder.exe
tkchkrzm.exe
tlgspot.exe
tlmjw.cmd
tlso.exe
dc6_startupmon.exe
eraseme_70228.exe
tmd.exe
tmf3w3g0.com
3p9wj19.exe
tmf3w3go.com
tmiedw.exe
tmnero.exe
tmp.exe
TmPfw.exe.exe
tn.exe
tn0k.exe
eraseme_72111.exe
togimep.bat
tool1.exe
tool2.exe
3r33c.CMD
tool3.exe
tool4.exe
tool5.exe
toolbar.exe
toqy.bat
tosnapviewer.exe
eraseme_82065.exe
totoovou.exe
totypef.exe
tpdrvmap.exe
tprncqict.exe
3smibax.exe
tqmsohelp.exe
Trjscan.exe
trsetup.exe
trtesm.exe
true.exe
eraseme_83616.exe
ts6k.exe
TSQIF5ZCEWTL.EXE
TsSrv.exe
tstm.exe
tsxas.exe
_tmp.bat
3Sy.exe
tt.com
tt.exe
ttesk.exe
erdeIect.com
ttile.exe
TTPloyer.exe
ttwavtoasf.exe
tudqrfw.exe
tunbcore.exe
TuneUpDefragService.exe
tureviewer.exe
3vf9968r.exe
tvgogobox.exe
tvwizard.exe
erijiga.exe
twex.exe
twext.exe
twking.exe
tx.exe
TX651999.EXE
TX65FF72.EXE
txfl1rhh.com
txfyat.exe
3wy1vm.cmd
txgtaiv.exe
14604.exe
TXP1atform.exe
TXPlatform.exe
tyfr.com
type grim.exe
type store plus.exe
tyvq.exe
tzaq.exe
tzlcwg.exe
u.bat
3y.bat
erimepadsv.exe
u.cmd
u.exe
u08.cmd
u1223994543g.exe
u1224053688g.exe
u18vxqle.com
U2372.lnk.exe
u26ufgv.exe
u2by.exe
u3dsc.com
erjhni.exe
3yr1.cmd
U5-7E643.EXE
u63urr.exe
u6k.cmd
u6t7f4.exe
U-7T82.EXE
u82.exe
U9-78A2A.EXE
u99.exe
U9-E9646.EXE
ermvu8.cmd
ubabhab.exe
3zfQl.exe
ubat.exe
ubs.exe
ud.exe
udem.exe
udhwgxxs.exe
udv.exe
ueqa.exe
Uer.bat
dcadd.exe
eropatentactivation.exe
ufixitprotector.exe
ufoFly32.exe
4.exe
ufoz.bat
UfSeAgnt.exe.exe
ufvtidb.exe
ufwi6sq.exe
ugcgck.exe
ugguu.exe
ugreport.exe
erovision.exe
uh.exe
uh31.exe
uhjqlk.exe
4002.exe
uicktimeupdatehelper.exe
uifile.exe
uihrtzzm.exe
UIN_OD01.EXE
UIUCU.EXE
ujb.exe
Error.exe
ujiz.exe
ukajimoced.com
ukpudbo.exe
ukregform.exe
40102.exe
un_tc.exe
underliveud.exe
UNewCJPU.EXE
UNewCJSU.EXE
uninstal.BAT
ers_startupmon.exe
uninstal2.exe
Unl.exe
uorys.cmd
uosetup.exe
up.exe
41.exe
up0ppxwr.com
upacfa0.exe
Upd4CE.exe
Upd4Epoc.exe
ertesm.exe
update220.exe
update2201.exe
update304656.exe
updateisetup.exe
updater(2).exe
updater.exe
_wpbegone.bat
41RHMTLO.exe
updater697.exe
updates.exe
ERUNT.com
UpdateThis.exe
UpdateWindows.exe
updC.tmp.exe
updds3.exe
ups.exe
Ups3.exe
upsf.exe
uptes.exe
41UECXYCXN9.exe
uptqu.exe
erver.exe
upts3.exe
uptsd.exe
upunyxaj.exe
Upz.exe
uqautoup.exe
uqb0julr.bat
uqyqtwo.exe
urawofyje.exe
uret463.exe
42232del.bat
147261text.exe
us8amqf.exe
usanaz.exe
userini.exe
userxp.exe
usmsvc.exe
USRCRTU.EXE
UsrImpPU.EXE
usy.exe
ut.bat
ut9x.bat
erygypyb.exe
4450.exe
utcfgwiz.exe
utcn8c63.exe
Utility Mang.exe
UTKJN7SD7I.EXE
utsetup_wm.exe
utU5g.exe
uuhgt.bat
UUSEEunion_uuvod_Setup_10495.exe
uuu.exe
esentutl.exe
uuxp_d4.exe
45AD9FCA.exe
uwlmj.com
UX-51F0AC.EXE
uxkktr.cmd
uydw20.exe
uyfd9cck.cmd
uzabozyh.com
uzsetup.exe
v.exe
111h_pas20095.exe
eset.exe
v0f8rqc.cmd
v0vj.exe
46.bat
v2h3.exe
v2messen.exe
v3pif.bat
V4JHMMkCxL.exe
v86htgx.cmd
v8jh2akbdg.exe
v9l1l.com
eskislk.exe
v9l8.exe
v9ug2p2.com
vaahv.exe
46C61D.EXE
vapqpe.exe
vasyzity.com
vbicwrmind.exe
vbiw4sp.exe
vbpqboot32.exe
vbsdaas2.exe
et.exe
vbsoexq.exe
vcf0.exe
vcpupv.exe
vctio.com
47C.exe
vd91t29.exe
vdej3e.exe
vdicwconn2.exe
vfdg2evxx.exe
vfdh23g.exe
etection.exe
vfhyjh.exe
vgastate.exe
vhdlc.exe
vhosts.exe
vibimigid.bat
47F22CC4.EXE
vioFly32.exe
VirRL2009.exe
ViRsLab.exe
VirTrigger.exe
event.exe
Virus.exe
viunpack.exe
vkiioqu.exe
vkrg.exe
vlc.exe
vlhsupdate.exe
47M.exe
VLL25HZ7TK.EXE
vlshvlzm.exe
vmdetdhc.exe
Events.exe
vmhpfsched.exe
vmhr.bat
vmnates.exe
vmoffdiag.exe
vmxzmy.exe
vnkucvv.com
vnwmccfg.exe
_wuauc1t.exe
4818.exe
vonine.exe
evilif.exe
vp.exe
vpcrm.exe
vpqdgkx.com
vqg.exe
VRAVSE9PEQO.EXE
vrfebe.exe
vrsdg.exe
vschost.exe
vsdrv.exe
48230029.exe
evnerolive.exe
vsfinder.exe
vsnp2uvc.exe
vsvxx.exe
vt6e.cmd
vt-7326.exe
vt-7626.exe
vtdfhgbfv.exe
vtmsaccess.exe
VTXDATxF.bat
VUR0L.exe
14D5FC.EXE
4827.exe
vusetup.exe
vva.exe
vvmstore.exe
vvqmn.exe
vvr.exe
vvxx.exe
vwizard.exe
VWTYIQ1G.exe
vxi.exe
evxx.exe
vxnwcdex.exe
4870.exe
vyicwconn2.exe
vytwgs.exe
w.bat
w.cmd
w.exe
w0pg2p3u68s.exe
W1B169B8.EXE
w2qagd.com
dd77.exe
ewatr.cmd
w3dn9f.bat
w4[1].exe
491.exe
W4-81E9D.EXE
W57A7163.EXE
W6-50635.EXE
w6hikrv.com
W8-7D7C2.EXE
W8-C3CDB.EXE
w9fc.exe
ewClickTest.exe
washidx.exe
waw.exe
wawabmig.exe
4916624932413.exe
Wbs542.exe
Wbs62.exe
W-BT82.EXE
W-BT83.EXE
W-BT85.EXE
wcbtinint.exe
ewobis.exe
wcqww.exe
wcs.exe
wcsetup.exe
wcssvbr.exe
4956.exe
wcu.exe
wdm.exe
wdmon.exe
wdso.exe
WDVRCtrl.exe
expiorer.exe
wdwmpshare.exe
web.exe
Webhost2.exe
webhost4.exe
WebTrap.exe
4B8A877E1319.exe
wectp.exe
wedr.exe
Weeiivruved.exe
weemi.exe
explor.exe
weemi129.exe
weff3.bat
weg6sp.com
wehds63.exe
weicwconn2.exe
weqianj.exe
4creator.exe
weqjn.exe
wesetup.exe
wet.exe
explore.exe
wewt425.exe
wewtf.exe
wex.exe
wexe.exe
WFXDEL.BAT
wg0kpd.bat
WG11945D.EXE
4D1B90FDDF6B.exe
WG12007A.EXE
wg6jj0.exe
explorer32.exe
wglplm6g.bat
wgp.com
wgso.exe
whsdfda.exe
wiadss.exe
Wicump32.exe
Widuoyudehiyi.exe
wii.exe
﹛﹛﹛.exe
4FDA54.EXE
exploser.exe
wilpmove.exe
wimtareg.exe
Win.exe
wincheck.exe
WINCOOLATICE.exe
windg.exe
windosyee.exe
windosyw.exe
windosyw.exe.exe
window.exe
export.exe
4hc1.exe
WinDown.exe
Windows Adio.exe
windows.com
windows.exe
WindowsMediaUpdate.exe
windswe.exe
winexecs.exe
Winfe32.exe
WinH95.exe
15215.exe
WinHees32.exe
4Help32.exe
WinHelp.exe
WinHelp12.exe
WinHelp2.exe
WinHelp3.exe
WinHelp32.exe
WinHelpbncba32.exe
WinHelpl.exe
WinHelpz.exe
ddsa.exe
extext438220t.exe
WinHelsdawhjp32.exe
winhost.exe
4Sy.exe
wini101978.exe
wini10603.exe
wini10733.exe
winimg.exe
wininet.exe
Winistelp32.exe
winjyeexj.exe
Extra Pure.exe
winlegon.exe
WinLests.exe
winloads.exe
4V8FO7.EXE
WINLOG0N.EXE
winlogon32.exe
winlogov.exe
winlvgoh.exe
winmm16.exe
winncreg.exe
ezddtester.exe
winpows.exe
winqqej.exe
winrarese
winsccoo.exe
5.exe
winse32.exe
winser.exe
winsit.exe
winsp2.EXE
winsscoo.exe
ezojone.exe
winsys.exe
winsys2.exe
WinTcpips.exe
wintems.exe
wintkserer.com
500.exe
winup.exe
winupd01.exe
winupdate86.exe
winupdater.exe
ezpinst.exe
WinUpdter.exe
winupgro.exe
winvista.EXE
Winyoxuany.exe
wipe about poke intra.exe
wisdstr.exe
506341.exe
Witingsp32.exe
wivoog.exe
wjjaq.exe
f.bat
wjkfyup.exe
wjlc.exe
wkcay8u.cmd
WL5667B8.EXE
wl9m[1].exe
wllamek.exe
wlnin.exe
535.exe
wlso.exe
wm.exe
f.exe
wmedia32.exe
wmimngr.exe
wmivmips.exe
wmivmipse.exe
wmplayer.exe.exe
wmso.exe
wnloader.exe
woauolt.exe
5436.exe
woca.exe
F001.exe
wora.exe
wos3.exe
woso.exe
wotisspwiz.exe
wow64main.exe
wowst.exe
wpa.exe
wpkx.bat
wpmgr.exe
~.exe
f2hipwscn0erog289s.exe
55096del.bat
WPULETE2.EXE
wpv061273735655.exe
wpv071242765100.exe
wpv101273913086.exe
wpv281274083779.exe
wpv361273934964.exe
wpv371257061249.exe
wpv401254983689.exe
wpv461254042811.exe
f350155625k.cmd
wpv541273735473.exe
5705.exe
wpv551254042811.exe
wpv711257784999.exe
wpv711273931622.exe
wpv711274083878.exe
wpv741254007820.exe
wpv831272465393.exe
wpv841273913623.exe
wpv881254042811.exe
ddx.exe
153.exe
wpv961257179558.exe
WPVLUTE7.EXE
5788.exe
wrmonitor.exe
wrzgrda.exe
wscript.exe
wscsvc32.exe
wsctf.exe
wsem.exe
WService.EXE
F3C74E3FA248.333.exe
wsivs.exe
WSMSSE.EXE
wstk.exe
5858.exe
wt1toreg.exe
wt2toreg.exe
wtesk.exe
wtesk.exe
wthioreg.exe
wthtoreg.exe
F3C74E3FA248.dll.333.exe
wtjava-rmi.exe
wuauc1t.exe
wuaucldt.exe
wubrandsn.exe
5df80bmbel.exe
wue.exe
WumenHelp32.exe
wummmg.exe
wusne.exe
wuwu.exe
F3C74E3FA248.ex
wv.exe
WV255725.EXE
WV2BF1C8.EXE
WVTUIE5.EXE
wx.exe
5IrxH6iGlR_2263.exe
WX447374.EXE
WX48637B.EXE
WY0QH7.lnk.exe
wybho.exe
F3C74E3FA248.EXE
wycgb8.cmd
wyg.exe
wyqrvts.exe
WYRTL0OBMRG.EXE
wyzlo.exe
WZ7DBF79.EXE
5Sy.exe
WZ7FD28A.EXE
wz9eaaff.exe
wzaq.exe
F3SCHMON.EXE
wzt.exe
x.bat
x.cmd
X001.exe
x1.cmd
x1.exe
x1dg.exe
6.bat
X1LZ1A19V.EXE
x1o8uo.exe
F405430C86A6.exe
X2N347G12BJ3.EXE
x63rnneh.exe
X69BYXJJKP.EXE
X9-15309.EXE
X9-EEF4B.EXE
xa8v8.exe
xabzqa.exe
xadeiect.com
6.exe
xamplayer2.exe
F41747390K.cmd
xayzpq.exe
XBD14RNZ.EXE
xbpxy.exe
xc.exe
xe9fdii1.cmd
xecnfnot32.exe
xedex.exe
xene9.bat
xerks.exe
6000.exe
F5.exe
xfi.exe
xhupgrdhlp.exe
xhx .exe
xiao.exe
xiaox.exe
xievhrf.exe
xjs.exe
xjv.exe
xkufadvlog.exe
XL-25E22.EXE
F5918.com
~tmp6329.exe
6032.exe
xm.exe
xmloder.exe
xmqgdqmi.exe
xnfrqlvf.exe
XP_AntiSpyware.exe
XP-1F108B00.EXE
XP-282641C7.EXE
XP-2966CE79.EXE
ddxx.exe
faskflxld3.exe
XP-3FF170B6.EXE
XP-6FC6613F.EXE
61.exe
XP-77DE0A2B.EXE
xpa.exe
XP-BCF77097.EXE
xpcypx.exe
XP-D41D8CD9.EXE
XP-D8F9930F.EXE
xpj6rvn48.exe
15400.exe
xportcontroller.exe
xppg3r6.exe
xpq63xl.exe
625B57.EXE
xpzclientm.exe
xqayqc.exe
xqg0.exe
xqyl68.exe
xrg1.exe
xrg2.exe
fastart.exe
xruninst.exe
xrwordconv.exe
xsiscok.exe
xsn.exe
62CA11B1.EXE
xswzsepe32.exe
xtanigen.exe
XT-C58F6.EXE
xtdrvmap.exe
xtu.exe
faubroker.exe
xue.exe
xv.com
XV2269F9.EXE
XV2C6590.EXE
xvassdf.exe
62D4F8F5DDAC.EXE
xvsfxfe32.exe
xwnbcore.exe
xwpehlv.com
xwyygq.exe
favds.exe
xx.exe
XX-3F35F.EXE
xyh.exe
xymowop.com
xyoprx.exe
xyqrzc.exe
62oop0ak.bat
xyzqab.exe
XZ502A94.EXE
XZ592B9D.EXE
fbgfeje.exe
y.BAT
y.com
Y0HWA.exe
y319s.exe
Y5YMN.com
y6u.bat
y9a4rlbtyn9q.exe
6334.exe
y9rlqi.cmd
YahooMesseng.exe
fbmstordb.exe
yapwjlo.exe
yba.exe
ybghwcyy.exe
ybzcay.exe
ycioce.exe
ydmj.exe
yedkreq.exe
yevtolik4.exe
63e.exe
yf.BaT
fci.exe
yfmqo.cmd
yfpaoty.exe
ygpqboot.exe
ygvtn.exe
yh.bat
yhmsseces.exe
yhx.exe
yi9.exe
yiebfyka.exe
640.exe
fci.exe.exe
YiqilaiLyrics_2001.exe
yjkjfuo.cmd
yjpqmagic.exe
ylauncher.exe
ymeboruk.exe
ymxf3q.exe
ynicacyqo.bat
YNTUMS_A.EXE
yoqrxa.exe
yosetup.exe
fcompinstaller.exe
6516.exe
yoshvlzm.exe
yoxazx.exe
yp.bat
ypcabo.exe
ypjq1.cmd
yq.com
yq00tht.exe
yqaoqp.exe
yqprxyb.exe
11.exe
ddyikr.CMD
fdaolfdos4.exe
yqxvos.exe
~tmpb.exe
66012139987.exe
yraA.exe
YRUvoXXeDU.exe
ysoutlook.exe
ysrjj.exe
Yt.BaT
yt8a.exe
ytclview.exe
fdh23g.exe
yv.BAt
yv.exe
yw6mmv0.exe
670113362038.exe
yxxx[1].exe
yy.exe
yyy15828.exe
yzcxqx.exe
yzhwz.exe
yzpcxy.exe
15521.exe
Yzszeccoo.exe
z.bat
Z3-C1F31.EXE
Z6-55BFA.EXE
670781.exe
Z7730456.EXE
z8g5q3d3n2s9.exe
za.exe
zaking.exe
zasnp.exe
fdHrupPQg8_2263.exe
Z-BT85.EXE
ZC-D96ED.EXE
ZeSet.exe
zhahss090101.exe
zhudongfangyu.exe
682435872112.exe
zkadvx.exe
znconvert.exe
znsetup.exe
znygd.exe
fdusie.exe
ZOON-56A.EXE
ZOON-57A.EXE
ZOON-86A.EXE
ZOOP-86A.EXE
zoorfat.exe
zopqbw.exe
68578.exe
zpasplnchr.exe
zpcaop.exe
zpcaxyq.exe
fdxx.exe
ZPHULE6.EXE
zqabop.exe
zqmsohtmed.exe
zt.exe
zts3.exe
ztso.exe
zuhyryw.exe
685932861400.exe
zukeqek.bat
zumspub.exe
fedvp.exe
zunins.exe
ZVTULE6.EXE
zx.exe
zxexe.exe
zyndle081008.exe
zzjmnjdl.exe
fswagz.exe
cbzvl.exe
68fb45b.exe
691518911700.exe
femwxmlk.exe
699047678387.exe
69a8c2.exe
0.cmd
69F4CA84.EXE
6AFDCC.EXE
6C2E46F9BF9F.exe
6F7365.EXE
6hg.exe
6j2j.com
6o0.bat
fevzaq.exe
6phx.com
6qe.com
6r3p.com
0.com
6rq6.exe
6vu680.com
6wqhah.exe
6xdgw26.com
7.exe
70.exe
fewh.exe
703.exe
7040.exe
704671_xeex.exe
716.exe
1189033
0.exe
718.exe
719.exe
7254C830.EXE
727496.exe
debeja.exe
ff.exe
74BE16.EXE
777d.exe
779941CQWZ.exe
779941L.exe
779941M.exe
78A16F.EXE
000.exe
7a9cd3.exe
7U-77A62.EXE
8.exe
ff1q0gw.bat
8006.exe
8007.exe
806.com
814YSJL2K2DF.exe
82.exe
82516del.bat
82i.cmd
0001.exe
82tgk9eg.exe
83416del.bat
ffrffox2.exe
83843.exe
8386nac.com
842F0D.EXE
84352E.EXE
84361del.bat
85930del.bat
85E94AF2BCA4.exe
88EB427299AC.exe
00013.exe
89.exe
15724.exe
89064del.bat
8a.exe
8ae2q.exe
8B154471.exe
8b3.bat
8B8BA3.EXE
8BCG7Z.exe
8BF414B99AFE.exe
8CKLDNS27805.exe
00016.exe
FFrrfox2.exe
8df.EXE
8e.com
8gidy.exe
8h3hh3m.exe
8iyqbsp1.exe
8K5IO6YR.lnk.exe
8m08ty.com
8mt8bm.exe
8nlo1q.cmd
8ot8y86.exe
ffs.exe
0002.exe
8oupido.bat
8ox61l6.cmd
8q6h.exe
8Sy.exe
8tss2gwq.bat
8u.com
8uot.exe
8X-19E2F.EXE
8xlwbngd.exe
fgBatchDL.exe
9.exe
0003.exe
9017.exe
904174051500.exe
90imhpnc.exe
90r0.exe
91.exe
919.exe
91m.COM
92F54D81A560.exe
fgidh.exe
92j11sm.com
931cd8e.exe
0004.exe
9322D4F0.EXE
93555D.EXE
94.exe
95847text.exe
95920926.exe
96.com
97319text.exe
fgj3lc8.exe
976f.exe
97A03D.EXE
98313586.exe
001.exe
9961.exe
999.exe
9A285362.EXE
9b8kmipy.com
9bid6bl.exe
9dl.cmd
fhsuimain.exe
9es.com
9kupe.exe
9l66g8k1.com
9LKh3oIFUJ_2234.exe
001[2].exe
9o.exe
9ptvs1.exe
9r8hh2f.exe
9Sy.exe
9tb8ist.bat
debug2.exe
file.exe
9W-55F53.EXE
9W-70D92.EXE
9yp8nyvg.exe
a.bat
a.exe
1413147
002.exe
A00.exe
A001.exe
A002.exe
FileKan.exe
A003.exe
A005.exe
A008.exe
A009.exe
A01.exe
A010.exe
A013.exe
003.exe
A014.exe
A019.exe
filelink.exe
A02.exe
A020.exe
A024.exe
A025A3.EXE
A028.exe
A03.exe
A030.exe
A05.exe
004.exe
A07.exe
filelinkconfig.exe
A08.exe
A09.exe
a1.exe
a10.exe
A11.exe
A12.exe
A1224A67C97A.exe
A16.exe
A17.exe
005.exe
15910934.exe
A17[1].exe
A19.exe
A1A71A.EXE
a2.exe
A20.exe
A21.exe
A23.exe
A24.exe
A27.exe
A28.exe
fimepadsv.exe
006.exe
a2guard.exe
a2r.exe
a2service.exe
A30.exe
a3lun0703.exe
a4.exe
a6.exe
A6800.exe
A7800.exe
find.exe
a8.exe
00p3se.exe
a8qengab.exe
a9.exe
A95.exe
A98.exe
A9800.exe
aa.exe
aa1102265.exe
aa1102437.exe
findbasic.exe
aa162874.exe
aa195751.exe
01[1].exe
aa19999218.exe
aa19999468.exe
aa306630.exe
aa481292.exe
aa639234.exe
aa639281.exe
aa96108.exe
fipgnfww.cmd
aa980279.exe
aaa.exe
aaaa(0).exe
01[3].exe
aaaa(1).exe
aaaa(2).exe
aageok.exe
ab.cmd
AB3D72.EXE
abc.exe
firefox2.exe
Abcver.exe
abjzitqc.exe
abopxy.exe
abpcxp.exe
01[5].exe
abqk2c3i.bat
abqxyq.exe
abs.exe
abs1.exe
abs2.exe
Defender.exe
fjb2.exe
abs3.exe
abs4.exe
absgx.exe
absl.exe
A-BT85.EXE
012.exe
abyopr.exe
ACCESDeInstDAQ.exe
accwisd.bat
Acdasz.exe
fjsetup.exe
acfvu.exe
ACIPU.EXE
acpi24.exe
acpi32.exe
acpi64.exe
ACQV1.EXE
.exe
012027.exe
ActiveSMART.exe
AD.exe
Flap cake.exe
AD0317220341.exe
ad7731.exe
adba2.exe
addrun.exe
ader_sl.exe
admd.exe
admier.exe
admparsed.exe
03863121.exe
Adobe.bat
flec006.exe
AdobeUpdater InstallMgr.exe
adsntd.exe
AE31E6.EXE
Aedexx.exe
aewordpad.exe
Aewscan.exe
af.exe
af93gcf.exe
af9rgm8h.bat
04174051500.exe
flu-0103.exe
afasrv32.exe
afecubi.exe
afslkfasl10.exe
age.exe
agiexplore.exe
aglajgkd16.exe
ah.exe
ahff.exe
ajm.exe
ajtmv.exe
_is2.exe
04D668.EXE
ak4d79f.exe
AK997D6.EXE
AKE7122.EXE
akfinal.exe
aksaq.exe
alga.exe
algg.exe
ali.exe
aliwe32.exe
160440.exe
allrs.exe
0520.exe
alo.exe
alq.exe
alsched.exe
alsdlaslx13.exe
aluj8r.exe
alulin.exe
alupgrade.exe
alv.exe
fly.exe
alvsvpd.exe
Alw258e.exe
052OATNC7V.exe
alxlin.exe
AMOVE.EXE
amstreamh.exe
amvo.exe
amwva.exe
andyxp.exe
anhzxc.exe
fmsuxuf.exe
ante dale.exe
Antideqnb.exe
Antieabft.exe
096.bat
Antiehehb.exe
Antikdwub.exe
Antikrphh.exe
antimalware.exe
AntivirusPro_2010.exe
AntivirusPro2009.exe
Fnovsoriz.exe
Antivirussystempro.exe
Antivnbkw.exe
Antiwwmdw.exe
anylapadyd.com
0ap.exe
anymie360.exe
anyone360.exe
aoutfq.exe
ap.com
aplerestarter.exe
defy.exe
foofizolouf.exe
apptune1020.exe
aqoeerw.exe
Are.exe
arextloader.exe
as.exe
0c2q.com
As2es.exe
asa.exe
asdf.exe
asdls1.exe
for.exe
Ashirt01.exe
asn.exe
aspx.exe
ASWLSVC.exe
ateipr.exe
Atevxx.exe
0C9C4681802F.exe
Ati.exe
Ati2enn.exe
Ati2eo.exe
fornext1.exe
Ati2ev.exe
Ati2evx.exe
Ati2evxp.exe
Ati2ezz.exe
Ati2g.exe
Ati2ssxx.exe
Ati2vz.exe
jqzzmg.exe
0CBEA3.EXE
Ati2x.exe
found..exe
Ati2z.exe
Ati6ev.exe
Atid.exe
Atvxx.exe
atymi09.bat
Atyuhapu.exe
auncher.exe
aunchgtaiv.exe
aurealjbox.exe
0DBC50.EXE
found.exe
auto.exe
auto.pif
autoload.exe
AutoPahRun5.exe
autorun.exe
autorunx.exe
AutoUpdate.exe
autox.exe
av_md.exe
av2009.exe
found.exe.exe
0df2.exe
av360.exe
ave.exe
ave2pc_light.exe
avg.exe
avgas.exe
avmb.exe
avp.exe
avp-32.exe
avpx.exe
found.exe.exe.exe
AVR09.exe
0e.exe
avwordpad.exe
awg.exe
aws.exe
AXISNEW.exe
axovws.exe
axwinword.exe
ay8p6v3.cmd
aybpqc.exe
16220144.exe
ayp.exe
az.exe
0e2.exe
azinetwiz.exe
azojyvu.bat
b.bat
b.cmd
b.exe
b2.exe
b3.exe
FOUSET.EXE
b4.exe
B41346EFA848.exe
B56vD.exe
0eboyg.exe
B621A6.EXE
B62C36.EXE
B6OU.EXE
b7878.exe
B7879.exe
B831406A9770.exe
foxwei.exe
Backup.exe
bagfwlive.exe
baidu.exe
baizi.exe
0ix8gcdt.cmd
baizi02.exe
baksql.bat
bao0.exe
bao1.exe
barbroker.exe
dehopedoo.exe
fp.exe
bb2416e8.exe
bbb.exe
BBSr.com.cn.exe
bc5.exe
bdffg.exe
0jbnlnu8.exe
BE124B92.exe
BE8540978C80.exe
Beanfun.exe
BeatTrojanMon.exe
fphj6j31.bat
BeatTrojanSvc.exe
BeatTrojanTool.exe
beemo.exe
beropcse.exe
beupdaterinstallmgr.exe
bfgse244.exe
0jpz.exe
bgmonitor.exe
BGMVYO8R.exe
bgswitch.exe
fplatformcomsvr.exe
bhmigrate.exe
bihanutiti.exe
BinFly32.exe
bisetup.exe
bixpec.exe
bixrew.exe
bjk.exe
0ntoikb2.exe
bjmypyuuqiw.exe
bkjvqdei.exe
fpmsinfo32.exe
bmfloppyme.exe
bn0.bat
BNB_029.exe
bnkxy.exe
bnmv.exe
bnwavpack.exe
boot.com
bopxab.exe
vvxx.exe
0o.com
fprevhndlrshim.exe
bopxyz.exe
boubatoojaf.exe
bousie.exe
bowwiyjo.exe
bpcxop.exe
bpcxyq.exe
bpdjmswv.exe
bplrl98.cmd
bpvwvays.exe
bpx9q3j.exe
fqcnmxwx.exe
0odgktkm.exe
bqk.bat
brastk.exe
braviax.exe
BrCFN.exe
brmsaccess.exe
browse vga.exe
brqfd.exe
brwconf.exe
bs3ol8kd2.exe
fqfrontpg.exe
bsmain.exe
0ohqxsdx.bat
bsp.cmd
bt8vuaw.com
btddos.exe
btdsos.exe
BtSrv.exe
bugreport.exe
bunip.bat
bupdat.exe
fqmrnmxw.exe
buscanpst.exe
buu.exe
0pqb6qnj.cmd
buwmpnscfg.exe
bwf.exe
bwp.exe
bxuup9r.bat
byoprx.exe
bypxhpinst.exe
byqpra.exe
165896.EXE
BZ4U3.exe
bzqcab.exe
bzrxay.exe
0s63el.exe
c.bat
c.exe
C001.exe
C002.exe
C1E075E8.EXE
C1E075E8.EXE
FramePkg.exe
c3config.exe
c6.exe
C77EC700.EXE
c7k5nw.exe
0Sy.exe
C85880.EXE
C9395B.EXE
C9AB43.EXE
cabcax.exe
calcs.exe
112203.exe
FrameworkService.exe
cao.exe
caoni.exe
capap.exe
casarestore.exe
CbEvtSvc.exe
0t2m0.exe
cbpd.exe
cbpdix.exe
cc.exe
CC34FC9CC812.exe
FreeApp.exe
ccccc.exe
CCENTER.EXE
ccproxy.exe
ccx.exe
CD4509.EXE
CD8IDOYL.COM
0wk2.cmd
cdas.exe
cdscxx.exe
cdvot.exe
FreeApp_Rezer.exe
ceasplnchr.exe
cefile.exe
ceqfqp.bat
ceqod.exe
cerues.exe
cfaubroker.exe
cfe.exe
1.bat
cfshvlzm.exe
cfv90h.com
FreeSearchBar.exe
cggqp.exe
cgsggg.exe
check.exe
chg.exe
chipset.exe
cHJgzgXvwmFLuSTB.bat
chlf9.exe
Cilevb.com
1.exe
cilpnoi.exe
frmwrk32.exe
ciqkwn.exe
cisvc.exe
ciwouwazi.exe
ciyidces.exe
cjb.exe
cjrp8.com
ckidriver2.exe
cknhh.exe
cktmbmsrv.exe
%temp%lodl.exe
frtesm.exe
1[1].exe
ckupgrdhlp.exe
ckupnp.exe
cl200961.exe
clauncher.exe
clc1al.com
clc3k.com
clfdle.exe
clfile.exe
clidoc.exe
fsafsakx12.exe
clile.exe
1[2].exe
CLIPORV.exe
clipsrv.exe
clrpsiverc.exe
clxam6r6.exe
cm0.com
cm6.exe
cm7.exe
cmbdafk.exe
fsakfask9.exe
cmd.cmd
cmhot.exe
100001.exe
cmmon32.exe
cmon.exe
cmp.exe
cmstp.exe
cmyikdel.bat
cmyikreg.bat
cn.exe
fsdg.exe
cnpartin.exe
cnqxd.exe
cns.exe
10004.exe
co.com
Coalbrowsedataheart.exe
coinetwiz.exe
comcat.exe
comine.exe
comrepl.exe
167312.exe
comsetup.exe
config.exe
confxg.exe
conin.exe
1004.exe
conler.exe.exe
conmis.exe
connin.exe
connins.exe
cont_adservefast-remove.exe
Deleteme.bat
fsdx.exe
copetttt.com
copy.exe
country.exe
cp13cg.exe
cpa.exe
1006.exe
CPAserver.exe
cpf.exe
Cpl32ver.exe
cpqset.exe
FSProcess.exe
cpush.exe
cqbx.exe
cqsj9m.exe
cqwd9m.exe
craoek.exe
crc32.com
1042p.exe
creative heart.exe
cross.exe
crssc.exe
FsUsbExService.Exe
csceog.exe
cson.exe
csrsc.exe
csrss32.exe
csrsses.exe
ctfinfo.exe
ctfip.exe
1067A8.EXE
CTHELPER.EXE
ctsrv.exe
ft8.exe
cubp.bat
cuteftp.exe
cvija.exe
cvsdfw.exe
cvvevxx.exe
cxyqra.exe
cykawc.exe
cyoazngk.exe
108i.CMD
cyyqyr.exe
ftbckgzm.exe
czvocs.exe
czxhz.exe
d.bat
d.exe
D001.exe
D001[1].exe
d1052.exe
d218eht.exe
d22xl.bat
10Sy.exe
ftiduico.bat
d3bn0j.exe
D4289580.EXE
d44906.1830391884.exe
d4740.exe
d51613.2014718056.exe
D6442DEB.EXE
D69BE5.EXE
d6r6jmp.exe
D70895.EXE
d83a70.exe
ftpqlaunch.exe
ftpupd.exe
Fuck.exe
fufb6tq3.cmd
delnicek.exe
16827.exe
Fun.exe
FunshionInstall_C46681.exe
fusou.exe
fvan.exe
FVBDYV.exe
fvbk.exe
fvca.exe
fwcinfo.exe
fwcobj.exe
delself.bat
fwcproc.exe
1685932861400.exe
fwf.exe
fxmdk.exe
fxon.exe
fxqu.exe
fxstaller.exe
fxtjr.exe
fxx.exe
fy.exe
d8ur3qs.bat
delshare.bat
fyso.exe
g.exe
168881.exe
g0.cmd
G001.exe
G1.exe
G10.exe
G14.exe
G15.exe
g20091118.exe
desetup.exe
g2p3s.exe
G3.exe
G31.exe
1696752819875.exe
G32.exe
G4.exe
g45g.bat
g8rruyw.exe
G9.exe
g9rv.exe
desfx.exe
gaagw.bat
gabptk6d.bat
gaiie.exe
game032.exe
16E06CA0.EXE
gbatchdl.exe
gbhpfxicm.exe
gbknpfqj.exe
GBNP2.EXE
gbre.exe
Desktop Security 2010.exe
GC-286.EXE
GC-386.EXE
GC-8668.EXE
GC-8669.EXE
GC-9668.EXE
16onq.bat
gcavs.exe
GC-BZ6.EXE
gclwpivc.cmd
GC-WZ6.EXE
Desktop.exe
GC-WZ7.EXE
GC-WZ9.EXE
gdi.exe
gdk.exe
gdrecode.exe
gdsag.exe
_is31.exe
17207825.exe
gff6.exe
gfgxx.exe
DEVDET~1.EXE
gfile.exe
gfptedit32.exe
gg1.exe
gg2.exe
ggkxgvf.bat
ggl.cmd
ggqn.exe
ghdf1.com
173453.exe
ghj5.exe
df.exe
ghp32.exe
gicchk2s.exe
gix.exe
Gjd.exe
gjjx.exe
gkaossvc.exe
gkkar.exe
GKQN1.EXE
gkqqkk.exe
17406.exe
11478.exe
gksui18.exe
glecrashhandler.exe
gleupdate.exe
gmi1jxy.com
gnc.bat
gnchkrzm.exe
gnqtw.exe
gnwav.exe
gnwwy.exe
go.exe
dferp2.exe
17422.exe
god.cmd
god.exe
goods.exe
google_earth5.exe
gostrot.exe
gousoe.exe
gplpn.exe
gqnedb.exe
gqscanpst.exe
dfgc.exe
gqsk.bat
18060.exe
GRAPH8.EXE
grid show.exe
grmcdlc.exe
group.exe
gseg.exe
gsmbp.exe
gsmimo.exe
gsrdgt.exe
D91CB0.EXE
dfh43.bat
gswrij.exe
gsxlexd.cmd
182187.exe
gtgfescw.exe
gth.exe
gut.exe
gvpqboot32.exe
gx.bat
gx.com
gxcdue.exe
dfhasqb.exe
gxowsrmadm.exe
gxul.com
gygsi.exe
18303594.exe
gymussy.bat
gzip.exe
gzoemig50.exe
h.bat
h.CMD
h.exe
dfhbsming9.exe
H001.exe
H001[1].exe
H002.exe
h0j8w.exe
18467.exe
h0ti1de.bat
h2.com
h2t6u.exe
h3hi1k3.exe
h8i.com
dflljy.exe
ha_80210.exe
headphonsk.exe
help.bat
Helper32.exe
helpersscc.exe
184890.exe
helpme.exe
Helpok312.exe
hep.exe
hesrutil.exe
dfprevhndlrshim.exe
hf34h.exe
hfap.exe
hgsetup.exe
hhb.exe
hhinetwiz.exe
hhmdllhost.exe
18712304.exe
HIDE DEAF.exe
higj2p.bat
hiimccphr.exe
dgf.exe
hiserver.exe
hlsfile.exe
hmh.exe
hn.cmd
hnkvaa2.exe
home.exe
HomeAntivirus2010.exe
_is32.exe
18784278313.exe
hongscrv.exe
dgkx.exe
Hope Setup Save.exe
host.exe
hostroto.exe
HotFix.bat
HotFix2.bat
HotFix3.bat
hovrflst.bat
hp32_nword.exe
hpbxpu.exe
18874064.exe
dh66ln.cmd
HPH0WYC.EXE
hpkgteo.exe
hpkq.cmd
HPOSM.exe.exe
hpp.exe
HPWuSchde.exe
hqmiccal.exe
hqunrar.exe
hqx292nu.exe
hrveat.exe
11794.exe
19121874.exe
hsi.com
hsjnkj.exe
HSLHXM.exe
htjtq8o.exe
htkhg.exe
hunderfw.exe
hunderservice.exe
hupxj.bat
huwesa.exe
dhcore.exe
HV-544B7.EXE
19122.exe
hv8fv2.exe
hvcplutl64.exe
hvoxmq.exe
HX-10D68.EXE
hxbpamjb.cmd
hXEO6mSA.exe
hxs.bat
hydlyw.exe
d9wgrdiv1tfccbf40r.exe
dhcpcms.exe
hyh.exe
hyimecfmui.exe
19169.exe
hyj2gunw.exe
hynbye.exe
hyppstream.exe
i.bat
I.exe
I001.exe
I14L1IH.exe
dhcpnet.exe
i2.com
i-773.exe
ib3qc3t.cmd
1919.exe
Ibf4e.exe
ibpqpe.exe
icdmx.exe
iceu.exe
icf.exe
icf.exe.exe
di3su.exe
icicyo.exe
iciryqyf.bat
icn.exe
ictureviewer.exe
19335464.exe
icwsetup.exe
IdleItchPlan.exe
idyduhin.com
ie.exe
ie2.exe
dialupass.exe
ie6.exe
ie8.exe
iebtm.exe
iebtmm.exe
iebtu.exe
19985433.exe
iebu.exe
ierdfgh.exe
ieremove.exe
ieudinit.exe
diox3j.com
ieupdates.exe
iexp1ore.exe
iexpl0re.exe
IEXPLOER.EXE
if6ch9k6.bat
ig.bat
19f.exe
igcmrtjw.cmd
igehy.bat
ihav.com
Distributed.exe
ihnbsftp.exe
ihzaq.exe
iiumhvyvpmvy.exe
iiunrar.exe
ijdialer.exe
ijjua.exe
ijzab.exe
19kcv.exe
ikowin32.exe
il0byu3h.com
dixumumyva.exe
il6.exe
ilelocksetup.exe
ilicwconn1.exe
iluqcwr.exe
im.cmd
im.exe
IM84WV.EXE
IMELOADU.EXE
_is33.exe
1a.exe
djoemig50.exe
IMEREOU.EXE
imt8.cmd
inave.bat
incs.exe
indowslivesync.exe
init.exe
ins.exe
ins1.exe
inst.exe
Install[1].exe
dl_205490.exe
1aq1obb.bat
installer.exe
instasp.exe
int297092.exe
inteltrv.exe
inwsdlxsh.exe
ioautoup.exe
iok.exe
ionlinesetup_111111.exe
iounins.exe
11942.exe
iozaq.exe
1BC60B45.EXE
IPdriver.exe
ipm.exe
ipseccmd.exe
ipy.cmd
iqsuimain.exe
iqzai.exe
Ir32_a.exe
ir3601.exe
dagd.exe
dlh9jkd1q8.exe
IS15.exe
IS2010.exe
1bg.cmd
iscwam2h.cmd
isdojpweocmqrt.exe
isqsys32.exe
itjaq.exe
ityt.exe
iu.bat
iu82.exe
dllhost32.exe
iufrontpg.exe
iuyile.exe
ivcoverdes.exe
1brfrip.exe
ivzai.exe
iw.bat
iwjj.com
iwomivig.com
ixsla.exe
IXUV0.EXE
dllhst3g.exe
izzab.exe
j.bat
j0.exe
J001.exe
1D17A2DF.EXE
J001[1].exe
J002.exe
J002[1].exe
J003.exe
J0-A8829.EXE
dlregform.exe
j0jnw3iri9s76qq.exe
j0mpdkja.cmd
j1.cmd
j16dp6.exe
j1rxka1n.exe
1D54BD5BC206.exe
j3ewro.exe
j78y5iytg.exe
j83uv.exe
JACK.exe
dlscanost.exe
jagqy.exe
jahebequ.bat
jalozi.bat
jatxgwcj.bat
javk.exe
JAYZ.exe
1E0967.EXE
jbgonline.exe
jbjrjrjb.exe
jc1r11.exe
dmf.exe
jcmmawa.bat
jcojx.exe
jdsoc.exe
jdt2ofp.exe
jfmsqry32.exe
jfmy.exe
jfr.exe
1F48C3.EXE
jfwk.exe
jfxk.exe
dna.exe
jg.com
jg6w3yx.com
jgok.exe
JGPF2.EXE
jh.exe
jhcqxax.exe
jhfk.exe
jhidriver.exe
1gia.com
jhrvi.exe
dng.exe
jijpey.exe
jix9a.bat
jj2.com
jjj.exe
jjxzwzjy090330.exe
jk08.exe
jkxrox.exe
jl.com
JOHN.exe
_is34.exe
dnkgn.exe
1i.com
jolipu.exe
jolndyok.exe
joule.exe
JoyPokeForkBlue.exe
jpiaiu.exe
jpok.exe
jqdk.exe
jqfa.exe
jqka.exe
dnsrslvr.exe
jqlssrvc.exe
1irqtv.cmd
jqqk.exe
jqtk.exe
jqza.exe
jr.exe
JREA1.EXE
jtgk.exe
jtjvs.exe
jts3.exe
darkshell.exe
1197312.bat
jtsk.exe
jtso.exe
1jief.cmd
jtwmencagt.exe
jvu69.bat
jvvo.exe
jvvo0.exe
jw00.exe
jwam.exe
jwfa.exe
dnwmpnscfg.exe
jwig.exe
jwrk.exe
jwtg.exe
1n.cmd
jwtk.exe
jwugqi.exe
jxinyi.exe
jxsj.exe
jy.exe
jyhfh.exe
dobeupdatecheck.exe
k.bat
k.com
k.exe
K001.exe
1puninst.exe
k08aww.bat
k12003641319.exe
k12003641537.exe
k120036416214.exe
k120036416315.exe
Documents and Settings.exe
k12004500374.exe
k12004500385.exe
k12004500396.exe
k12072205182.exe
k12072205204.exe
1q8p0y.com
k12072205225.exe
k12072205236.exe
k12072205258.exe
k12077866362.exe
domlaun.exe
k12090846163.exe
k12090846184.exe
k12090846206.exe
k12240747577.exe
k12240747607.exe
k12240787174.exe
1rexh.com
k12240787217.exe
k122464621218.exe
k122464730418.exe
doscp.exe
k2.cmd
k66xo6mv4s4uxn.exe
k6wkwon2.exe
k9cuos2q.exe
ka1nk.bat
kacsde.exe
kafeTest.exe
1sertc.exe
kandaofk.exe
Kaspersky.exe
dots.exe
KAV.exe
kavo.exe
kavsvc.exe
kavx.exe
kavy.exe
kb2006a.exe
KB958643.exe
KB958644.exe
1Sy.exe
kbcug.exe
Down(0).exe
kbd101a.exe
kbd101b.exe
kbd101c.exe
kbsetlang.exe
kcdvo.exe
kcodu32.exe
kcomc32.exe
kcomd32.exe
kcpatch.exe
1wkwxgxw.com
Down(1).exe
Kcrner.exe
kctuyu.exe
kd25tray.exe
kdddv.exe
kdosl.exe
kdsxr.exe
kdwordconv.exe
kdxor.exe
kdy.cmd
ked.exe
Down(11).exe
_is4D.exe
1wod1.com
kedec.bat
keepSafe.exe
kelemygij.bat
KERNE132.exe
KERNEL32.exe
Kerner0826.exe
ketggk.exe
kfhg.exe
dasdsaads15.exe
Down(2).exe
kfi.exe
KFWU0.EXE
1xxec.exe
kg18j.exe
kgnkxc.exe
khbdj.exe
khgf2.exe
khrgu.exe
Kill1211.exe
KiVIR.exe
1197312.exe
kjgagklj11.exe
kjibu.com
kju.exe
2.cmd
kk.bat
KK07.exe
kk36.exe
kk38g1.exe
ko1.exe
kousie.exe
down.bat
kousoe.exe
kpvqk.exe
kqnero.exe
kqsr.exe
2.exe
krdw15.exe
KRFQAM.exe
KrMS5wpauYa.exe
krtesm.exe
krvnseuve.exe
down.exe
ksgonline.exe
ksseoc.exe
KSWebShield.exe
Kterne.exe
ktesk.exe
20.exe
ktmtsclib.exe
kudajybv.exe
kunet.exe
kuqskg2s.bat
down2.bat
kuruna.exe
kurund.exe
kuwo.com
kuyhvbv.exe
kvh.exe
kvsrvxp.exe
2008.exe
kvtrwkcc.exe
kvunrar.exe
kvwinzip32.exe
DownUpdater.exe
kwicwtutor.exe
kwlonaqc.exe
KX-AFDCE.EXE
kxvo.exe
kxvo2.exe
kya6l.bat
KZ0FAE6.EXE
2009.exe
l.exe
L001.exe
dowsxp-kb918997-v6-x86-cht.exe
l1.cmd
L1.exe
L17.exe
L2.exe
L3218.tmp.exe
l3v.exe
L4.exe
L4D1D.tmp.exe
2010.exe
l4osofyyu.exe
dp.cmd
L6.exe
l6w2eaih.exe
L72F0.tmp.exe
L758D.tmp.exe
L8.exe
ladxsetup.exe
lanmao.exe
lasas.exe
lass.exe
2012.exe
dp.exe
lass1.exe
lass10.exe
lass2.exe
lass3.exe
lass4.exe
launcher.exe
Lava3731.exe
LayerArchive.exe
lbmso7ftps.exe
lbp.exe
dpu1.exe
202tq6.exe
lbugreport.exe
Lcass.exe
lcbxv.exe
lccp.exe
ld03.exe
ld12.exe
ldgybkp.bat
ldmsacnv30.exe
ldmsimport.exe

Delete specific registry
delsubreg|HKEY_CLASSES_ROOT\BDHlprObj.BDHlprObj
delsubreg|HKEY_CLASSES_ROOT\CLSID\{FEF265AC-5A25-4A5C-8736-CBB14AEC3BE7}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AppSvc32.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91954FAC-1023-154F-895A-1458258AD819}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{00F22189-C504-46BB-983A-E6FD66609F0A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{304B9531-94D9-4F69-81A3-99B7B172220F}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91CFF913-BADF-44FC-9C44-5CC06F8696C1}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{92335157-984B-4692-8405-530335CA9F27}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9731FA19-8C71-4763-85EA-BB64CDE11D8E}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{97421D0D-E07F-40DF-8F07-99597B9585AD}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{986488AF-13D5-9DDF-4FEF-9FB88698CFC1}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9867A72A-B1F0-4AD8-BC4B-1E1065B85E13}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{98B7C13A-E9CD-4959-8B46-FBEAB41E42A8}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\APVXDWIN.EXE
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9A4E6730-B97D-43D0-979C-C81F88D78559}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D3A3726-0BCB-4474-90C7-522774D42531}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9F41E4F0-DCA2-4D4E-A51C-0CC593B5CF03}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{30618412-C528-C784-C056-C164D1F7C503}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A0113412-4022-4B59-97FE-2DBD8D710394}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A06E2720-F24E-90B3-D5C6-333C14A3F43D}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A2C3BA54-DF75-4881-8EB3-E54B26BBBBC9}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A33B53E3-404C-481D-8F9C-33E416E9D865}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5B2B651-7819-42d6-800B-E9F7FC2853C9}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A629FF4F-ACDB-5C90-A098-FACB3456A26A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{18e64250-19a8-4d10-828f-30e101a22291}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A93061FE-464A-4E95-8E96-A54CD948B0F7}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A95083BE-3D1F-4C7E-ACCC-EC11EA9D498A}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a9844b2d-fca2-45e0-9862-be24e19d06c3}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3152ACEA-61D6-4DDA-A11E-55E69C933906}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA59145F-315D-BC23-AC1F-145DF81A34AA}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA6B979A-796F-452A-94B3-DF1F17B72031}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AAB6C1A0-F3A4-4DAC-A922-F82E601E73A8}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AB692F9B-27FE-4511-8885-ED62BB45197B}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AC2DDC79-9580-4B83-A213-D6C23C4E7BC5}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ArcaCheck.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AD862DC6-37FA-4D56-B7EA-59C2522A5FC4}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF976DCD-754F-4ac2-BE49-951DC7AA57D2}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B01DED18-9E26-4F33-B373-F59758747AFF}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B03A4BE6-5E5A-483E-B9B3-C484D4B20B72}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B058B02A-AC93-4FBA-900B-FA44D9B92805}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{319675CC-4129-497f-8C7F-E2F48251019E}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B05A92B0-F7B0-4E5B-884E-3D5FB2D4552A}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B05CB5FE-1E22-43C7-93E2-4CF04C87B3CC}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B3776444-0648-41DD-8EDC-92CCB95D74F4}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B490415F-65F8-B5C5-D8BA-9405FB12054B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\arcavir.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B629FF4F-ACDB-5C90-A098-FACB3456A26B}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B69F34DD-F0F9-42DC-9EDD-957187DA688D}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B778645D-B2A0-48E5-8E43-04B02CA3EA9D}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B9751A53-4494-4d7c-9732-AE3058D8145F}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BB4C402F-882A-4526-8C08-51278EA437C1}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{31E59C8C-20C9-4B7C-A160-6983B2AAAAA1}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BB4E3499-0132-4d3f-849A-2BE1B26D84E1}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BBC92FBA-9F43-4938-8716-62D17E1A1617}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bbd4551a-9b23-41cd-9bcd-818aa2da7b63}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ArSwp.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BC8975EB-DD3E-406A-8DF9-218848C3B594}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BCBD80C9-6AD7-48ed-8DF1-6963414B3649}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BCEF561D-FD3C-4FDD-859F-F2AC43DD5101}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BD344AF4-67AB-4E19-A630-7435587D320B}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BE1A344F-9FF5-4024-949B-52205E6DB2D0}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BEE17DA4-AF94-4D82-8A8D-CF61D73AF94D}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C08DF07A-3E49-4E25-9AB0-D3882835F153}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{322302FE-90F2-41B9-95BF-FA3F4AD60B48}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c1005aa1-b41b-4057-94ec-cfa8f081d18c}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1626E66-C26B-C628-E1DF-CDACCFA26EE1}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\arvmon.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C28925ED-EBF5-4FEE-B829-B518B4CB2E10}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C34AAB30-15BF-465C-8477-E47850780BFB}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C4D2CCF4-F674-48C7-9F89-F150DF63CCAE}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C517FCA8-7040-472F-9DE5-90B990387AD7}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C5470A7F-BDF2-4D97-847B-6AA97ADCF91A}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C5F43BEF-CE2F-46D8-AFE6-A647BACD1F09}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C74B750A-3C70-4AB5-8749-2B864A9116DE}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C86488AF-13D5-4FEF-9DDF-9FB88698CFC1}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{32596546-2036-9451-6058-658402589723}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C9EACC3E-25D3-41D9-8575-410FD86DD685}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashDisp.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c9f1240b-7e43-1a8b-96a8-c32114593fd0}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CAB2E13E-848E-4DA0-A97D-53245C25449A}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CBD9FCD6-0F8C-4596-9B3F-2F6974FFE672}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CBF4E071-9785-4507-A09C-652C2862E3B9}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CCACAB8C-9218-4E37-ACF6-FF84BEBEF60A}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cd36797a-70f3-4acd-8825-623d3b896881}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CDBFB47B-58A8-4111-BF95-06178DCE326D}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CE7C3CF0-25FC-11D1-ABED-784B7D6BE0B3}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0B5AB50-711B-495A-B804-C86D9AE3D9A6}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{325A1A2D-CBE3-4411-9F41-0FFA22ACDA52}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashEnhcd.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0B7E0F1-4A38-4ACC-B3ED-5C552BDBE512}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D1CC9DC6-F0BC-40fc-9552-E497B05E05B8}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D2DF094F-19E5-4096-9E6E-CDE173909227}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D3626E66-B13B-C628-ACDF-BDABCFA265E1}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D3CD6983-551F-4CD8-B48F-FABEB7DE8F3D}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4FEDE82-C500-4AA4-BB99-A4DAE5A65A46}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D5141C2D-A732-4627-AC14-D5B54121A941}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D72860C5-2C7E-4C8C-B1C9-F6803BEB09E4}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D7515C61-A66C-4319-A0E0-D416CB8059E3}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D8CC4845-441C-44F8-9053-28F2EF67655B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashServ.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{32DC6FB6-AD66-43A4-B231-151B57A7B3F0}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D9AD332C-F0BD-FB6D-8A8F-393E0F10C0CE}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dfcdbba7-9ed7-4500-aade-c42ff96e3f9c}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E0F3526A-4165-4589-80CD-50B6FBAC3BDA}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E3019869-0038-49F8-B8CF-4170728210F1}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E3616E66-C13B-2628-2CDF-EDABCFA235E1}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E59C8BDA-489C-47EC-8967-A33C6A730B10}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E996F10E-FCAF-41CC-94C8-B8BF7D6F80AC}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA3AB1EA-AF0A-42A9-BB49-B0386462A036}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ea5fb64b-1ca5-4939-a93a-9e76234b0a67}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{FF3E3C08-0ACE-4730-AD5D-E07370B62CB3}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ashUpd.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EB6736EA-D66C-49A8-81A8-FBF9FECB62B1}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{33200C76-F883-4C5C-B1EB-F3C070DB12C6}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ECD35E39-F399-40DF-8B88-005C7A4B0ABF}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EDC8293B-C0AE-4247-9A50-7D75FEEB1AAB}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE1E1B0D-3689-402A-82DC-9689A71DBE46}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EF4A79B4-070E-4645-B732-8A4A26E18A11}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f14ef0e2-c39e-4589-93e8-52e89cb5ddb2}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F171A450-7AF5-43E1-AFED-EDC826A1B0F5}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F49C475D-5651-4A94-B289-9953F9248EF9}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F543B043-E9F5-4438-B89A-94E2BDF40B7D}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AST.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F6A454AE-156A-415E-9F89-3795677A8A91}
delsubreg|HHKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\361svc\Parameters
delsubreg|HKEY_CLASSES_ROOT\CLSID\{00F5A942-E883-4899-BD2E-1B6F926757E7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{334345F1-DACF-3452-CB7D-4620F34A1533}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F93CB274-12A2-489E-9DB6-BAAF492448D0}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fa19bd7e-50bc-4203-80ac-c4edc81ca9a3}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FBF3B337-FEB6-403B-BBE2-2B67CB6563E3}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FEF265AC-5A25-4A5C-8736-CBB14AEC3BE7}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFBA5A4F-CDD2-439E-902B-81AAAFDAD3EC}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFEECE-FFF8-8222-2FB0-2935B9081111}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aswUpdSv.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFEECE-FFF8-8222-2FB0-2935B9090315}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFEECE-FFF8-8222-2FB0-2935B9090508}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\8A?A6170-7264-4D0F-BEAE-D42A53123C75}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\A?49E9F-C8D7-4D59-B87D-784B7D6BE0B3}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{335A9BAE-19FA-42F2-AFD2-20C3275EF392}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\rsion
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\xB?J
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\?F413B-C6D2-4d91-82A9-A0F997BA588C}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{C1A8AF25-1257-101B-8FB0-0020AF039CA8}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{C27CCE38-8596-11D1-B16A-00C0F0283688}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{00000000-12C9-4305-82F9-43058F20E8D2}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{FD92DA1D-CFE5-45B7-AAAA-8D9D17A2348F}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{B03A4BE6-5E5A-483E-B9B3-C484D4B20B72}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{00180018-0018-0018-0018-00180018BB15}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{00B0B983-9D74-49BF-9C14-46788179446F}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{00F22189-C504-46BB-983A-E6FD66609F0A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{33DA3C8D-EC67-481B-B3A5-858F1CE3A899}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{0189BBFC-930D-49A2-A268-CEDBB4A0A3A0}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{01C52313-FF03-413E-A148-665C199D3279}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{0306438F-7E67-4DDA-8EF2-C0AD040FEBE0}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{03F8FE45-1FE0-4C6E-8E6F-D210867F5446}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{18EDD7A0-87EF-45B7-85CF-6A7E1341E2BB}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{04A76FFF-1AEF-456D-8E42-2862DF3CB62A}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{04FB090C-D4B7-497F-8212-433A2DD7AA5E}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{072DC5A3-0EF5-42C8-AF3A-52D74BC3CBE6}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{073B937F-266D-4FF4-B73A-41A0236DD0AA}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{085C1F40-1C33-4296-A3B3-CC47540B9A12}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{086CBBCA-8B04-47E3-B792-5E2C558F810D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3422FB0F-95EB-458A-8B56-39552017A4EF}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{086D50B6-D088-41A4-B6C8-5DF3B02FA3C7}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{08A8DAE3-31B7-4702-AF5B-558D1F84FE35}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{08DB4568-2E4B-4E13-9561-ED6B36A23376}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ati2evxx.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{08EB3951-6162-47C4-8EF5-CF51744E2B5B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{0B3358D2-410F-4693-9C14-DD01CE1698CF}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{0B43554E-BA93-429B-8531-647CC155B8D3}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{0B83E10B-88B2-4A02-B603-0494C2A87DC7}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{0BC82A03-D2E1-42BB-87BB-BDF7692AC2A7}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{0CDCBC5F-D4D5-48CC-8B20-3897858D9973}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{0CE7387E-F5AD-4169-84F5-CCE7C2D09933}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3474A8C2-BEF9-46C8-983A-A26A0030EC30}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{0EA9899F-4B12-4606-8AA7-DDF8017795DE}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{10BF3DE0-AFD1-434C-972A-AF56658D1285}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\atrack.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{10E92882-BD00-4744-A147-3047806696D0}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{1117FD09-1D3D-4807-9F25-9C8AE4C46879}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{11FFC1C5-0887-4E11-9330-18EBB026D4F3}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{12BA6240-AA6C-4F33-9048-F2168F219E42}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{12C00240-1B5A-4CC9-9DB8-F97EFD4EF36B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{13DED518-ACC3-4FA7-AF26-4E67A43B016E}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{14A0A05F-E7C4-449E-8A35-088F68B56CA4}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{1655D6CC-5FAD-4A03-9EE2-49D91A386E6D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{349F9B06-D92F-4AF9-AE96-6730A16821F9}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{16AF66EB-93C8-49F9-BB09-B4F87CEDCE46}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\auto.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{16E057AF-7204-47BC-BBF1-B6A7D2C2747B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{17276F09-EF0A-430B-9C3E-72CDD59449E3}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{185B085B-78D6-46A6-B1EB-80BD312E3E68}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{1957817A-94B2-4CAC-B113-A331809B5730}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{1962C281-E515-4D4B-A449-7E7B4B88D638}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{198FF3D8-56F1-466B-A36F-F9C28B43E440}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{1A86369A-3629-46BA-A666-D1811761D146}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{1BA683A0-8EE6-4C60-9BF2-907C2CB6B680}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{1C1BB1A6-8167-4C20-AB35-03B97A1389C8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{34A25F04-008D-403E-8EE6-2307BC02FA2E}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AUTODOWN.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{1E322963-355E-422F-BE2E-8C4667E31D10}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{1E9349CA-F39B-4BD3-8D6E-91FB532DDA86}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{1EEF419D-2264-4522-858A-5C2C31EDF2AA}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{1F2E3A6B-94A7-4355-B58D-74DF486E6C97}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{201476D0-2B18-462E-AB9F-3E2B0CC8732B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{21BE5FDF-D4CB-4850-AD99-21E68B50BF3F}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{23E6662B-FA39-4042-A240-990A5E4827AB}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{245C05BC-9441-46AD-8897-1680DAF88898}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{24EDEA54-9E75-4559-8818-F124CADF6DF8}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{263FE7C8-3E05-435A-8E58-EE78E11F3BCB}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AutoGuarder.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{34ecc7cb-0587-4420-8cca-fc441eaff885}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{26F58495-C4E4-4E64-97E2-FBD9A6080F93}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{28155D29-6AC5-4BD4-A2F4-3E46541672CF}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{286C2802-481C-4324-8D20-8E1738548D39}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{2876D76C-CAAA-4313-AF97-8D1D9A2A1087}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{2882C70A-AD5B-45BC-A8EC-D17AA8FE54FD}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{2895B086-90F7-459C-BB2E-E3AEB77A1BD6}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{289C5E9E-D431-436A-895B-74F321F3EF11}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{289F69CA-F9BC-4186-818F-3F9F3B6F3B50}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{28CD9D00-836E-4E0A-A9AA-8F4F5ECF3958}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{FFAE967F-D0FC-4D2B-A0F5-D1BF27F46418}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AutoRun.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{2A30458A-4460-426C-8D2E-189F8A42C708}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{35671234-7890-ABCD-CDEF-567801237653}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{2B660F50-0FD6-4D96-9ABA-48B731C7ABAB}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{2B94FD3C-E6C7-4E33-8966-D216D6B05ED2}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{2BD6354D-8A68-4F9A-B8D7-88A5E09BD16F}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{2C268BA0-2884-436B-9ABE-AD95BDDC6376}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{2C56D8DB-5D4B-4EA2-8B68-18F5C513E50C}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{2C846F45-2FB7-488A-A0AE-038EDEAF7E55}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{2CB77746-8ECC-40ca-8217-10CA8BE5EFC8}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{2F281C60-0A58-4E54-9369-57216CC1611A}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\autoruns.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{2F74F325-D906-41DC-95B2-4C475D41017F}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{2FED201F-5325-4EF9-8522-DB4E231EDEFA}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3575EF0F-C78B-47E3-A7B4-CEBC4907E14B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{304B9531-94D9-4F69-81A3-99B7B172220F}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{31E59C8C-20C9-4B7C-A160-6983B2AAAAA1}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{322302FE-90F2-41B9-95BF-FA3F4AD60B48}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{325A1A2D-CBE3-4411-9F41-0FFA22ACDA52}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{32DC6FB6-AD66-43A4-B231-151B57A7B3F0}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{332F8DF8-AE56-48C6-B8A2-17F82403FEC0}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{3406E485-680F-4906-AD1A-F6358D61B0B4}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\av.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{3575EF0F-C78B-47E3-A7B4-CEBC4907E14B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{358F3DF7-2CA6-4D98-B35E-08F02D2694DB}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{35CEC8A3-2BE6-11D2-8773-92E220524140}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{00F5B5BA-E3C2-4b70-BF51-42A557914FAD}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{358F3DF7-2CA6-4D98-B35E-08F02D2694DB}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{35CEC8A3-2BE6-11D2-8773-92E220524150}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{35CEC8A3-2BE6-11D2-8773-92E220524250}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{35D95784-1EB0-4494-BCBF-1F37C2AD3BF3}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{37BEAC91-ED58-4F24-A924-8BD1E46F9A2C}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{381E1F01-1254-1116-5891-0D0F0C32409F}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avadmin.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{38EEF43B-3B2E-4619-8EBE-36CFDFD13A0B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{399A4CC9-2020-43ED-8888-C3F1B536D675}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{3B2DC1F1-E030-4C51-AE8F-39929185CC21}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{3BAFECEF-0CE3-45C7-819D-57ABE5163BD8}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{3CA7A137-35F8-46CD-B83B-534CD13D5A67}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{3CC177E7-3E8D-4F5B-AF46-308380C3F6C1}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{3E090A14-E55E-4BA3-97C2-505907EAC7A7}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{3E1B07B7-6519-4BD7-9896-385B0B713525}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{3E52FA6E-D83E-4811-8FB5-1D54C0687227}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvastU3.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{3E7C9687-C865-4797-A540-0B3D4FD0FAB6}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{3EA5D055-B989-4F08-80A2-79DE32243973}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{3EFEAF36-B081-4454-9DE0-9023F21B2263}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{40B75357-A4C0-4C28-9DF9-50F288D1AC49}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{412441C4-07A6-4C62-85F1-823946775569}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{432BDC7C-DE5B-43f4-AA81-E7F8AFB0182D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{35B8D58C-B0CB-46b0-BA64-05B3804E4E86}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{434FA69C-5F0A-42e1-82B8-10AF2C8E53C6}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{4540B243-1CA5-41F5-8C80-A799B22CDB77}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{4582BCF1-1C39-4058-88B0-CDB8BB57EA61}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{1957817A-94B2-4CAC-B113-A331809B5730}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{47018D3A-8682-4D30-AC5E-F74B84189AB3}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{484DEC01-A8CA-49DC-8DA9-35FE53BA36A9}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{49762F37-EF1F-447D-A27A-967C9520A3F8}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{4A1F8C99-7A43-451A-8EF7-5EA11770A33E}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{4A26AA9C-E583-4338-9BE2-17717E8E15DA}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{4B3DA347-ACBB-497B-B62F-957C4D2B46D3}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{4B61A75D-55E6-4B35-A145-9A8DCDEC8A39}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{35C98014-DBB7-40E9-908E-0A970E82A549}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{4C31B312-1A26-4D0F-A31D-5F18F937AF50}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{4E7B7BCC-D111-49B2-A61D-26CAE048F844}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avcenter.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{4E9036D6-8BBF-48E7-82DE-A5D092EA1D45}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{4F4F0064-71E0-4f0d-0013-708476C7815F}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{4F72F83A-1C16-444C-8821-D01FF4759555}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{4F81668D-833C-4739-ACDD-267B6E3A1FDD}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{4FBFD5A4-5FE8-4444-8BD9-FD0FAFA64F96}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{5007ED72-6A0A-4D7A-8C2F-B3D9CB85186A}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{501A388B-6FBF-4150-9248-6D1E1BCF2B40}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{52345B67-1234-1234-D123-7F84D123BC7D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{35CEC8A3-2BE6-11D2-8773-92E220524140}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{52635CBE-B590-458E-86DF-E4F82348511A}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avcls.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{526403AC-FEDD-4350-946A-BC0B8114C65A}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{5350D2D5-0874-40ED-8D73-E3D0489215E0}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{5471D4CA-DADD-43B0-9FAD-009FB2D65726}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{551B11E2-DE28-41AC-95DB-15BE4804CC5D}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{5528694E-30EC-46E6-98F4-C413B5AC4DD4}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{556BA12D-13FE-41F4-9740-B6F1B8E1A8C3}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{55BD6687-15F6-41B3-959B-B69C032E7795}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{56BC86C7-0692-4F94-A2C1-6CF1DBF8096C}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{574D626F-263B-4B1B-9F38-D858CF9135FE}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{35CEC8A3-2BE6-11D2-8773-92E220524150}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconfig.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{5768264D-0CED-4643-A907-581545843629}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{58D4A9C5-DFF1-4EF6-BCA6-44D3EB4EA40A}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{5A041F13-A111-12B3-B0CF-F99818AA68A5}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{5A041F13-A111-12B6-B0CF-F99818AA68A5}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{5A0B8C1F-115F-48AE-B52F-DDA144375324}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{5A5B354D-E845-487A-8544-F111366B59E1}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{5AF04671-190D-4D5C-97AF-D8054F831E27}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{5BBFBD79-78AC-42EF-B80E-1EFD555C0675}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{5CC8752A-4131-477E-889B-B984779052CB}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{5D228D68-DD5B-4B2F-8AEB-03E4772A825E}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avconsol.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{35CEC8A3-2BE6-11D2-8773-92E220524250}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{5DDFF6E6-7FC1-4101-9B08-A9BD30446790}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{5FE66A52-8AAE-4D62-8D40-3120CA5316CD}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{610C01BA-76E0-463C-B906-73061D855AF5}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{622E84AF-AB3B-419E-AB5C-67DA236E91AE}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{6302B4AC-43E3-46D2-9969-629A0E175FB1}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{6345F11D-722C-4B9B-B99E-0E9F58F30522}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{644F71AB-1EF1-490F-B9B1-DBA314FD7B9D}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{65056902-6E7B-4bd7-95BA-688DB5FA5BEB}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{653BC427-1413-4CFA-B41F-3F0294E7640F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{FFBA5A4F-CDD2-439E-902B-81AAAFDAD3EC}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avd煦伀馮d陛侅.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{663FCF67-330C-47E9-973C-2260DE48283B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{35D95784-1EB0-4494-BCBF-1F37C2AD3BF3}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{66A11D22-9C6D-4D4D-9EA8-D8C7F69194A6}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{66E62803-BC8B-448A-A880-96322FA7E23D}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{673E3FBE-0091-4C85-B607-086996FD787D}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{67A4A417-26DB-4FA5-922C-3F036D95647A}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{68FC11DF-A032-4429-995C-730586B6114F}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{69828DCD-20B6-4588-BDC0-8A8D0656FEDC}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{6A2F86CD-BA9B-49A1-B708-9C550BEF6DA7}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{6A903CE9-E762-46BB-AFA6-2DB46482B743}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVE32.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{6A9709C3-8A46-411A-0890-35D3D3166660}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{6AA221D9-0DDD-4A03-B4EA-5360359D0AE6}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{361A1C46-F062-47FF-8E98-53F50E214691}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{6B49387C-ADC0-4E0D-960B-EB5E523741F5}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{6B9FEAD7-4319-4312-AB05-D8C9CD255BFE}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{6BB80F57-0262-4FE0-841B-5EAAB5609BF6}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{6C5DFBB6-9D4C-4C97-8073-DAA1CF156168}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{6CC3BA8B-1594-4607-BC83-E4AB6B6AF176}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{6CDC431B-5481-43EB-93DC-901CD4DB2F1E}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{704C3595-DB85-40F6-A601-8D6F346907BD}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avengine.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{70FEC77A-D5AD-4085-9DBD-6159E45BC90A}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{71152943-74C6-4DC4-8AF2-9A48ECC8BE76}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{711D85FB-681D-4F4E-A214-41A615900A20}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{369774CA-7CB4-4A3F-A9A9-77D6BC53CB3B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{71463F9C-9BA4-46A4-9AA9-61AB4D65409E}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{71A78CD4-E470-4a18-8457-E0E0283DD507}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{720A87A2-9E33-41DE-8F42-CB514BFF1F6F}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{726B4F5C-36C9-4D42-AD3A-48F768A1DF3F}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{732AD45D-A875-4019-970D-B32DA96C3EBD}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{7359CB42-AC3B-489C-89BF-7699B597B779}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgas.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{736D2B41-7BD0-45BD-BF7C-E73AACC8356B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{739A09B9-3DF2-484F-89A1-0C417E598ECD}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{73F1DAAB-0DBA-4804-81C9-BCA409393AAE}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{741D962D-B1DF-4BE4-8C92-FAF45661D30D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{0189BBFC-930D-49A2-A268-CEDBB4A0A3A0}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{36AC68E6-0C26-4D39-B98E-54B49DAB6BAA}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{74E84D48-3ED3-4DBE-A174-3997B06C56F0}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{76220F29-1F4D-4A8B-9E32-2D64FF0B41D6}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{76B9BA7A-81D0-4979-8598-8471F2AB5186}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{76D44356-B494-443a-BEDC-AA68DE4255E6}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgaurd.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{76E577DE-F8E9-40A4-A6C9-1A60218DD5DE}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{77064888-B267-464A-AB8A-BC262FB23603}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{77AC4257-6781-430B-80C1-BCA6D20C950F}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{77AE086B-ED00-4527-A208-6FFF03D92F4C}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{78D3CE11-3AAF-4312-8B75-AF3BEC0023FE}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{78DAA23D-614E-445E-942D-7E69EDA464DF}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{36EAFED6-FE52-42E5-8FEC-703424BAA9CF}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{79470BDB-086A-4A4C-90B1-66452C36E5B4}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{79B6D0EF-EA55-478A-AE4F-5E582D19D046}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{79C12B2D-3792-4FD4-924E-87272BD728A9}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVGCTRL.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{7A6DF30E-D0F2-446f-B4F0-BF4232D60E07}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{7AA8C8A1-7E40-484F-BA22-B912D74CCC6B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{7B473157-ABA4-4222-8505-42F5D34EF824}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{7BD57B5E-3091-4C33-B2E2-A39392F9F1D4}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{7C59DDC1-7792-4027-9D72-9807937E3464}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{7CA8D7D3-56A1-49A8-B167-103FCB917B1F}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{7CC1DA3B-A5C8-4329-8004-41981BA4BF86}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{37A924AF-1A5F-CF21-AB1D-1D5CF82A8A73}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{7CE999D8-CA2D-4E0A-ADA1-A0F6F78682C5}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{7D0F55B9-ED7C-466B-9852-4DEFB83B3889}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{1962C281-E515-4D4B-A449-7E7B4B88D638}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{7D5C8CCD-0111-41B4-9A61-73927EF2F242}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{7E72C5E4-028B-4C43-AE6A-52FCA04C5CB5}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{7E94C114-C874-4112-9922-054D8E5546E2}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{7F753D7F-3EC8-4467-B2DD-A148F978D29F}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{7F965200-EE7C-46B3-9A22-B010E2149769}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{7F9F521D-41E2-4DB8-936A-F126EB10EBFA}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{7FB1AE96-5CE6-4BB2-BF51-528F29F9D171}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{7FEEDEE4-D0F2-4FF8-A1AD-08C03389FB9A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{37AC9076-C898-B098-D098-A18319080973}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{803E9ADD-8D2B-4D78-AD34-D7FD790A17FB}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgnt.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{814AC387-61EE-4BAA-963A-55FF92BDDB7B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{815EDE81-767D-4636-80F5-141578667A98}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{8183F477-9E50-46A7-A3FC-35C149891BB6}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{82A8FF6D-40CD-456F-8B3C-67E46FF14D89}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{82DE2804-AF65-4CF2-BD3D-A95D734D6BDA}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{82E044C4-C4CC-4535-B731-F6CB8EB1F6D8}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{840AEC38-0194-4BA3-8621-AFC7CFA9F3F8}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{844B57D0-AD06-499F-AC52-15A4E6D14C28}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{844B8558-9E29-4D70-AF91-26319E22F1A8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{37BEAC91-ED58-4F24-A924-8BD1E46F9A2C}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avgrssvc.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{845C1D27-529C-4EA5-9796-8E71AC5933BA}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{84BD3613-EBAB-4CCA-9E94-00CE6AB956A6}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{84CC1A5C-D480-4E41-AAD2-C72B7A2635C5}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{8554F9AB-AEF3-4701-886F-4192F0CC36C0}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{8614153F-3930-448B-9AD8-E65DF6AC4750}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{87D2404F-32A3-46C1-A90A-A96D6265A122}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{88A7AF21-3F82-4298-93C9-B7D572C51277}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{892B9CC3-70DB-4E90-B57B-07A8AABB0A86}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{898E02AB-9372-4a2c-9C4A-FFE1AF61097F}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{89A7EBDB-FF5F-4D33-A578-06A20EBA0DA3}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avguard.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{37C5D66A-8B1B-4545-8112-3751194F6A4A}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{8B51E872-FBB7-4B56-99A2-816F4E531B58}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{8BEE6B12-EDA7-4111-8EE5-0947236AE4AC}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{8C8DA92A-857A-4B76-9688-BFDADEAAF495}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{8CEBFDC0-A57C-429D-8510-0E5E01AD6907}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{8CEEE744-30B0-4100-B016-46913B889857}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{8E772993-0DF1-44B8-AAC9-1FF4ABAF8AD0}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{8E97DB95-ED1B-408C-9454-02FC9990C148}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{8EDD3AA8-FE9F-469D-B307-29063DEF5263}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{8EE9AFC0-F04E-4501-8225-06F107566FE8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{16FF142F-BEBD-47CE-A3A6-D52A1A2ECB54}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avk.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{8F61586C-5D1B-4c76-BB3A-3B88F96A18B0}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{38093456-9012-4568-9076-908765467183}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{90872CA9-A763-43B9-A6BA-A8B5B17CEBC2}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{910A5582-4F7C-42A4-A070-0C91A1E68085}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{91C7DF6D-AEF5-4136-9252-AF030D7A5931}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{91CFF913-BADF-44FC-9C44-5CC06F8696C1}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{92EB19C4-F0F1-4D18-A3BC-59658F64F8EE}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{93B5C837-F80A-4337-924D-3A96D853C5A8}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{93EE42EA-B0DD-48A3-98DF-DF1C1E9D8988}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{945550DE-6D41-4182-854F-34C64F648131}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVKSERV.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{95D0AFC3-1A69-4F93-A24A-2576A536550B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{96F14DB0-A8F3-4334-BC67-89C51B609DF4}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3816D07B-D6F9-403B-B7D7-EDE52959341B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{9731FA19-8C71-4763-85EA-BB64CDE11D8E}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{97421D0D-E07F-40DF-8F07-99597B9585AD}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{97972049-FB05-4A90-A600-FE5EB197F76B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{97A32646-10D8-4EC8-8248-A27FAB047D79}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{98283B12-E35B-4051-86EA-1EE682FB369E}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{984FD966-B303-4CD8-8A6C-8D70E6B1F1E2}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{9867A72A-B1F0-4AD8-BC4B-1E1065B85E13}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avltmain.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{98C57570-8CC3-489E-8CF5-3EE644500681}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{997B14DD-E2D1-4FAA-A17E-DC4F64F8EBFC}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{99F71232-CFE3-42BD-BAEE-3E69D233A4C3}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{381E1F01-1254-1116-5891-0D0F0C32409F}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{9A14CF38-A713-4826-BBCC-53CAB88F4242}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{9A5881F2-2D40-4CAC-A8D0-10E98BFD2124}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{9B0D4EA5-8A3A-410E-A1A9-FB87FCAACF13}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{9C7A2EA9-A168-4157-A3E6-7E47A248E204}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{9CA963CA-107C-4089-B0AB-31380F90D7E3}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{9CDB5F42-D514-4487-86F8-798037428C61}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avmailc.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{9CE7556D-2193-429C-A04A-7F85213CE7CE}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{9E325A3C-2B26-4CDB-9E40-9713C2788F89}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{9E32A24D-BEFC-4BF9-A25D-91C37CEDE61B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{9E76FC33-C511-4FC6-AE7E-2639BCDA5E1D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3876F52A-C07E-A452-285A-C6EA15724E68}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{9E8287B0-0F3A-48ae-99C5-A6E0AAC36BC5}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{9FC3AD52-875C-4FF9-AA4E-5A6D86D4A0B4}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{A0113412-4022-4B59-97FE-2DBD8D710394}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{A024A926-B807-40B7-A94A-CD62D76DA0D1}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{A0C7F579-6A78-400B-83E5-545FC483E719}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvMonitor.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{A1A6BC2E-C6A1-43C1-8884-A31D772F42B8}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{A272F097-E24C-4A6E-8BCD-8C42839CE8DE}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{A2C3BA54-DF75-4881-8EB3-E54B26BBBBC9}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{A33B53E3-404C-481D-8F9C-33E416E9D865}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{A36FF2ED-2F06-4F7F-9A43-F109A8463D86}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{01AFE3DC-2242-436E-9B44-6DD1C664E828}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{38EEF43B-3B2E-4619-8EBE-36CFDFD13A0B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{A3822D97-2330-4A3F-94C1-381E37D46BED}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{A3D8CA41-41ED-405C-8BC0-65E99BE834CF}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{A43BFB0E-BF1B-47E3-8A7A-53FB4E1104FF}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avnotify.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{A5076382-B8B0-4396-A5A7-9F48FFC8549C}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{A5F2316A-F9C9-4536-9A47-AF7555FC459D}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{A5F94E96-ED20-4B34-9B59-372BEA06D319}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{A6C1FDD5-04DF-4707-A74B-92BB9D8A8F68}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{A7CD6B0D-0EB7-4476-BEA7-167E39744C66}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{A85363C1-CAB1-4999-A0D6-4951BBF69BE8}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{A9A7AE50-34D8-4726-B32F-7EDA5FDC6079}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{38FEFE05-702C-440D-AD5C-B796209A1CC5}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{AA0A58A6-5C1A-4CAA-9BCD-C2486C202073}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{AA2D2E20-4CBD-4AB2-B2B6-B356214DA8D0}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVNT.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{AA546010-1611-4616-920B-5D2D11965050}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{AB1912D5-04C9-46C3-9810-C91D388C9534}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{ab340860-fd81-4a65-b345-82eb77a66b5e}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{AB52A9B4-A995-4FA4-A11F-6178F0E61BBA}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{AB6C5D1A-EF31-49E6-9ACC-BAD329EA8D38}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{AC6F3D84-3433-4FCB-B445-3DE0C97D50EB}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{AC6FC642-201F-4397-B6E6-29276AD0A60E}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{AD26AC5F-8421-419C-8692-ED1FE74D0FE8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{39109876-7619-9101-7012-901938475193}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{AD56A0C8-8EDF-406E-AB5C-94498074CEC9}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{198FF3D8-56F1-466B-A36F-F9C28B43E440}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{AE8813B0-61B3-4F6D-8F9A-7AF223E2C46E}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{B051DBDB-8B9E-4FB1-B04A-67FC0A5DF427}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{B08DD574-5FC0-435F-A795-1CB3ED4B4181}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{B0ADE25F-5283-4EB7-84E6-45C6A02995A2}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{B10C1202-2D2A-43C3-A230-9D67F927BE18}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{B1998CE2-AAF2-4225-8D03-19F68509ACFD}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{B2C3D744-9C8E-4FCA-AA06-7A095F10EE71}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{B41816C9-9511-40C3-BAE7-F8208E9677AF}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{B4262617-467C-43DB-9B2D-C32739E5AA14}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{39349BEE-BE43-47E4-8670-8B34570E112D}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.com
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{B523D3D0-AF5C-4A25-9FBA-5243B231BFAA}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{B80AE261-15BC-4BD4-A1A6-935372C80E74}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{b89f72ec-3017-856c-4128-3017fa646e12}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{B8F4C7B3-74C8-4380-80B6-B66E5486B904}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{B955C012-E3E8-4777-86CB-73CC15890D29}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{B9ADD1A3-CEFD-40E9-9EE1-C25B28756073}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{BA16C151-EC27-4917-BA64-D9A1E0B74B75}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{BA73DD0D-D9F9-420F-B53F-E19115A6C385}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{BB136BA5-D1A5-4BD4-AC72-CAA9CB8EF992}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{BB4E3499-0132-4d3f-849A-2BE1B26D84E1}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avp.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{399A4CC9-2020-43ED-8888-C3F1B536D675}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{BC0F0A98-380F-4399-989E-737AE006CEBF}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{BC2E065D-C5AB-49A7-80E7-A23E45C5CDF1}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{BCDC783F-C3C3-426D-BB84-4F13C8B573D0}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{BD233082-E412-4667-BE66-5C9FEBB719C8}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{BDEC641B-8B04-4F94-9294-9F589E02CFFB}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{BE6661FD-2DA8-4E8A-B614-7322D4604DC3}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{BEA5B04E-545C-4386-89FD-5BB1CC5426C8}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{BEC8A03E-2E55-445A-97F3-03905BEAB07E}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{BF576861-D001-4651-9C77-BCA1F6615982}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{FFFFEECE-FFF8-8222-2FB0-2935B9081111}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVP32.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{C00B4190-B46C-4A97-9E44-4532D12BE1B4}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3A5700C3-2847-4CBE-A3E5-F0C394690C9A}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{C0CB08C1-EA7F-4092-80A2-4F648A4305A3}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{C100386D-BE28-4208-BF51-FC152AD3165C}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{C225280D-48C9-4CFA-B167-BBD91A534E29}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{C286ECE5-AC84-4B89-A219-38B876C739F2}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{C34865A9-79AE-4D44-A0AB-E623F3705442}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{C34AAB30-15BF-465C-8477-E47850780BFB}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{C3E75763-F9C7-4868-8502-81F11B41D943}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{C3F79FB7-475D-4A84-9E00-8F3570B7C26B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVPCC.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{C4E6B319-8C65-4016-8689-39ED0537D0CC}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{C5FC2AAE-C21F-4CDF-8E3C-3FE421118A1B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3A908760-8000-4000-A000-9000322145A3}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{C704DA21-F1A7-46B8-9BDC-50E506198AE3}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{C73C94FF-8E84-45BB-A81E-D47833D9B302}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{C74B750A-3C70-4AB5-8749-2B864A9116DE}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{C74EB933-C198-4F49-A63B-17DCCD4E36BB}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{C7AF807A-C1C5-436C-AB05-4E45B837007D}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{C7F56AB2-8285-4654-BE09-C6730BBF18B0}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{C85CB78B-8D31-4C27-8533-149683423BF7}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVPDOS32.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{C89E2A42-268E-4BEC-8EAB-EAC55D58EAF6}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{C8DF8B9F-692F-4F22-86F9-D8334FCA0753}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{C9EC9A56-C939-4B5A-A12E-FCFF02579770}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3B2DC1F1-E030-4C51-AE8F-39929185CC21}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{CA099F23-2E8D-4878-81B3-BD1D2D5ACD24}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{CA0CA44D-FAAB-4EAB-93DE-244EAAC18551}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{CB6E79AE-29CC-4082-A190-525D3C4A5233}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{CBF4E071-9785-4507-A09C-652C2862E3B9}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{CBF8A83B-543B-485C-8D43-4B2529A326F1}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{CC80F0B4-04D7-44D0-8DB9-9109B5B72141}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVPM.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{CCCA2FB9-2D5D-4481-8BFE-1CDDC458A3F4}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{CD575116-7FE3-4A51-A432-F061A79173E5}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{CD5EAE90-851C-48EC-BAB8-8D31A300742E}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{CD8D6EBD-22BB-4ACF-8AF2-737305B879A2}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3B62A4F2-05AC-47B2-B006-8102AF50A778}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{CE6C2B2F-B590-4EA1-9A44-5100596D7EAF}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{CF526160-CAC2-4560-AD0C-20C8D88CA4FA}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{D0052AEE-DB7E-4C36-8247-26C009D77BC1}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{D047C24E-876B-43BC-8373-5E7BE9BA9C35}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{D0B7E0F1-4A38-4ACC-B3ED-5C552BDBE512}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVPMON.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{D1C8CCFB-D10B-45A6-B9E4-1D717B0D4FC2}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{D2CCC364-CA20-4581-B6E3-7EBE086DCF27}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{D3112B69-A745-4805-874E-ABD480EA1299}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{D3CD6983-551F-4CD8-B48F-FABEB7DE8F3D}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{D3DBB332-5EBC-4713-8982-490113CC8037}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3B7AAEB1-9F3D-4491-9C06-C7165CA8D058}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{D495FADF-2A7C-4A62-A50E-D6FD9DF6FD9D}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{D50D4C49-4140-4E22-8EE7-821D2EF0E4EE}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{D67C204E-18D0-4048-9991-6D34B1738531}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{D7019B3B-ABF8-4D55-AB50-95A110373D54}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVPNT.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{D7FFD784-5276-42D1-887B-00267870A4C7}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{D806ABA9-CFCF-4100-B914-B8A067EDB967}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{D889BF1A-EDD5-4C1D-A3B7-434F4918E7C9}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{D90E7FF1-3BA4-469D-9345-86888D174D79}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{D9735121-5627-4697-A2B0-DAB75D6595FF}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{D9D0D8CF-0C6F-403B-8D57-DFB685C55B6A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{01C52313-FF03-413E-A148-665C199D3279}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3BAFECEF-0CE3-45C7-819D-57ABE5163BD8}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{D9EA901D-EE31-419C-8DD0-7E4B804C8CF3}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{DA191DE0-AA86-4ED0-4B87-293D48B2AE99}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVPTC32.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{DA1DE019-A6A8-ED40-4B87-248B2A93DE99}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{DAA9A840-0BB3-4706-9160-C5BF58D79C31}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{DAF11377-E995-4BDE-9561-FE28E14734B9}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{DC7245D3-CAB7-4D91-8715-EB5F4AA6241F}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{DCBC4DF7-09A8-42D0-BCF4-299F72F40EAD}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{DD1F3EAC-D200-4D70-B846-7A272C0A7867}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{DD247050-3EA7-43D1-88DB-8C79E8E3F04F}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{DD3129DE-81B7-48D7-AC9F-819A3FBBF2E8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3C954872-1230-6541-9548-6541025884C3}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{DD696DC3-7803-4750-8EFC-C10F6D900D2A}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVPUPD.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{DDFDCED2-075A-4910-986E-B2BDA2B0E916}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{DE43F05E-1CE8-4B5D-A8C3-982437642A1C}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{DE64EA3B-53E5-461D-96B1-38A8BBD36ED2}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{DF12F8AB-9A00-469C-B9D4-425C1BE3E1E6}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{DFEAF1AB-1B26-4ACF-A97A-BEF452ACBB4F}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{E035AC3D-B5A8-43A7-9944-8BB333A90D2A}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{E0CCDEEB-344A-4848-9AB9-6D39065FF118}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{E0F3526A-4165-4589-80CD-50B6FBAC3BDA}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{E18B360E-5548-4773-9F75-29E0D0319895}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{1A698452-C5D8-C584-C256-C264C987C5A1}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{E23C6000-0BBE-463B-AFEA-D5EF4E6245FE}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{E3019869-0038-49F8-B8CF-4170728210F1}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{E30AFD4A-110D-4FD6-A698-EE9D2BD98C7A}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{E3789A02-334D-43C9-AA31-6152094BA26B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{E3BE119A-F7B9-4E82-9D41-C4B8C8166190}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{E46276C8-FA5E-489E-A78E-5182B652E5C7}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{E4814792-EFA3-4C20-93D0-8B130A59F9A8}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{E4CC0B6B-93B1-4766-AE5E-3FE89FD6DD6F}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{E53443AE-A4E2-4218-A938-3EB1032FCE20}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{e57ce738-33e8-4c51-8354-bb4de9d215d1}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avscan.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3CA7A137-35F8-46CD-B83B-534CD13D5A67}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{E58B05EE-6CA5-42E1-A0CE-82169DDEE42C}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{E6243EB4-6253-4F95-866C-C3F58B3D2BEB}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{E742740B-BF6B-4119-BF4B-0D8F9B00DC2F}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{E75B29ED-F3D2-46D8-9EF3-B088068CB58C}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{E7ABF01D-9B5C-40C1-85BB-3EAEDEAB46A5}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{E8908346-8B0A-4EE3-8AEE-84502544688F}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{E912513C-22DA-4200-BB9D-4D36BB294B22}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{E918A05E-0FC7-4077-8ED4-ED1D6CEC0E8A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{FFFFEECE-FFF8-8222-2FB0-2935B9090315}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVSCHED32.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{EA4D8F95-8F2E-4658-A234-E8F4C9AC21C5}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3CBB135A-485D-4B93-AFB6-4EA39CC40864}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{EB34007A-BD36-43DD-89FF-7A8C8538FFBB}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{EB5D4E06-B487-4150-A19B-08B6F50F7BA5}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{EB965722-E1B1-4098-9DE5-D9CE34110DCE}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{EBD2EAD0-88A7-477C-9664-BC42F1CDC312}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{EC1E8459-B93E-4D9E-9D58-A2263C95E9F7}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{ECC8E4BF-44DE-4B8D-A591-80845E6A7863}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{ECD35E39-F399-40DF-8B88-005C7A4B0ABF}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avsynmgr.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{EE1CCAC2-F78B-4CB6-80F8-58DB08F87F8E}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{EE4CEE03-3174-43FC-99D6-A435EF5A9D64}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3CC177E7-3E8D-4F5B-AF46-308380C3F6C1}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{EE71D987-9436-43A9-B5C4-5FFFB0AD7A81}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{EE9EBB5C-5B4C-48d3-8BDD-0EDBF4F720B4}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{EF20A659-32BA-4A38-BECD-4CC2F3089C0A}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{EFBF72E3-4A08-40B1-8B93-44171A960791}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{F01CD512-AE66-45BD-B182-EED2D68E9FA2}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{F03905AC-469B-4617-A984-44F245F29981}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{F0930A2F-D971-4828-8209-B7DFD266ED44}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avtask.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{F0C9FBC2-6FA2-479d-B65D-F9D65C613ECC}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{F197AA18-AF63-46CF-A6E5-F1F291BAC921}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{F65BDEC7-4BF3-4512-840F-68B166B6D7AC}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3D144530-43DA-47CC-B7C7-A3A9F3B9A6B2}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{F6ECA821-B4FE-41BF-85FA-7BA54ED88176}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{F718AEF5-84CF-46AC-951D-3915D838897E}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{F7776F24-A299-492D-8E5D-409140455376}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{F7B7E354-C12F-4C4A-AAAF-A21C61ED8561}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{F836F78C-B66E-420F-AED6-B1F7FFD256D9}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{F8DCF40F-6746-4823-9575-59DBD84B64B4}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AvU3Launcher.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{F8E45003-3AAB-4F7C-AF06-725A2559E55B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{F9A03C13-B2AA-4579-8403-8DBD3A2EBC9C}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{FA9B58AA-6759-4C02-B37F-572FC2F1A231}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{FB628720-6493-4AD5-AD46-AEF90A005475}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3D490B56-425C-4B8F-889E-0E391AD54DE8}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{FB7247A4-5F09-472F-961B-68F7645EBE9E}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{FBA9B4CB-D3B1-44C8-8555-AF65C7929222}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{FC769E66-3862-4F80-A24D-E2F1EA7260D8}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{FC8F4603-4AB2-4A0D-B17F-886CC8AAAFD2}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{FCC4B6C0-5959-4664-B1C6-2B86F5136B63}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avwebgrd.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{FD428244-8EE5-4155-95DF-B07E8C304A39}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{FDE7B169-1290-4543-AF4E-0583CFE8367E}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{FE8B267E-D504-4FA8-AC3C-3214C27C5A5F}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{FEC2C7D9-F200-4C18-9F23-194A71874710}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{FEF08182-D075-403A-8117-C894067EC79D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3D698451-2015-6358-9871-2015987452D3}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\{FFF9E9B2-FB7B-4D9A-81F1-1D49F3D2D322}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\360hotfix.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\360rpt.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\360safe.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVWIN95.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\360safebox.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\360tray.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\agentsvr.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\apvxdwin.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\ast.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\avcenter.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3DCB9005-ABA0-47F8-8C40-49ABC04AE5EE}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\avengine.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\avgnt.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\avguard.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVWUPD32.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\avltmain.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\avp.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\avp32.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\avtask.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\bdagent.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\bdwizreg.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\boxmod.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{021F087F-4378-545F-74FA-37D345AD7A8C}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3E090A14-E55E-4BA3-97C2-505907EAC7A7}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\ccapp.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avxonsol.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\ccenter.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\ccevtmgr.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\ccregvfy.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\ccsetmgr.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\egui.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\ekrn.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\extdb.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\frameworkservice.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\frwstub.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3E1B07B7-6519-4BD7-9896-385B0B713525}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avz.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\guardfield.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\iparmor.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\kaccore.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\kasmain.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\kav32.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\kavstart.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\kavsvc.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\kavsvcui.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\kislnchr.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\kissvc.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{1A86369A-3629-46BA-A666-D1811761D146}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3e301889-882f-4abb-a2d8-4e75db3f3020}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\kmailmon.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\knownsvr.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\kpfw32.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\kpfwsvc.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\kregex.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\kvfw.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\kvmonxp.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\kvmonxp.kxp
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\kvol.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{FFFFEECE-FFF8-8222-2FB0-2935B9090508}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avz_se.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\kvprescan.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3E52FA6E-D83E-4811-8FB5-1D54C0687227}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\kvsrvxp.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\kvwsc.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\kvxp.kxp
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\kwatch.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\livesrv.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\makereport.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\mcagent.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\mcdash.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\avz4.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\mcdetect.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\mcshield.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3E7C9687-C865-4797-A540-0B3D4FD0FAB6}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\mctskshd.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\mcvsescn.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\mcvsshld.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\mghtml.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\naprdmgr.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\navapsvc.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\navapw32.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\b}|`y`?dhk鞜瀎鞜hfe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\navw32.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\nmain.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\nod32.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3E8C8B7C-369D-47D6-B53F-E1880DC3DA17}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\nod32krn.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\nod32kui.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\npfmntor.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\oasclnt.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\pavsrv51.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\pfw.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdagent.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\psctrls.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\psimreal.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\psimsvc.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\qqdoctormain.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3EA18648-FAF6-490D-9C92-8FD729028A58}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\ras.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\ravmon.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\ravmond.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\ravstub.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\ravtask.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdinit.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\rfwcfg.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\rfwmain.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\rfwproxy.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\rfwsrv.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\rsagent.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3EFEAF36-B081-4454-9DE0-9023F21B2263}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\rsmain.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\rsnetsvr.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\rssafety.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\rstray.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdwizreg.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\safebank.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\safeboxtray.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\scan32.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\scanfrm.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\sched.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\seccenter.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3f4dffdc-1bd0-4368-87b4-c97ae21fde40}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\secnotifier.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\SetupLD.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\shstat.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BLACKD.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\smartup.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\sndsrvc.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\spbbcsvc.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\symlcsvc.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\tbmon.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\uihost.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\ulibcfg.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3F74CB3A-F095-45D7-AE11-F4535A990B83}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\updaterui.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\uplive.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BLACKICE.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\vcr32.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\vcrmon.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\vptray.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\vsserv.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\vstskmgr.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\webproxy.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\xcommsvr.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\ImageFileExecutionOptions\xnlscn.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{0220FBE7-F757-4C74-B246-D6703DCF1087}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3FA3CAD1-C5D8-48B9-800A-A7B2D2A23044}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\boxmod.exe
delsubreg|HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
delsubreg|HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa
delsubreg|HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA
delsubreg|HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srosa
delsubreg|HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\360FkAdv
delsubreg|HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\360FkAdv.sys
delsubreg|HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BFSDRV.sys
delsubreg|HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BREGDRV.sys
delsubreg|HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rgadta.sys
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ vxx
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\caav.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3FDEB171-8F86-0003-0001-69B8DB553683}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\.Net CLR
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\.norton2009Reset
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\?B???t?B?
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0000230f
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00015bb7
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\000175f6
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\000179ee
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00018085
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00018121
delsubreg|HKEY_CLASSES_ROOT\CLSID\}1DBD6574-D6D0-4782-94C3-69619E719765}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{1B0E7716-898E-48cc-9690-4E338E8DE1D3}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001816f
delsubreg|HKEY_CLASSES_ROOT\CLSID\{3FDEB171-8F86-0004-0001-69B8DB553683}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\000181fc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00018269
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\000182e6
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001849c
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\000184da
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00018529
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\000185c5
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00018603
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\caavguiscan.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00018642
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\000186ee
delsubreg|HKEY_CLASSES_ROOT\CLSID\{40618412-C528-C784-C056-C164D1F7C504}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00018836
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00018855
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\000189bc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\000189cc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00018a2a
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00018a97
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00018af5
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cacls.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00018c7c
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00018c9b
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00018cf9
delsubreg|HKEY_CLASSES_ROOT\CLSID\{407C7A80-4656-4C4A-81C6-DFFB8009B80F}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00018d66
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00018e41
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00018e7f
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00019006
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001914e
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00019258
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\casecuritycenter.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00019332
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\000193cf
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001941d
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00019517
delsubreg|HKEY_CLASSES_ROOT\CLSID\{40B75357-A4C0-4C28-9DF9-50F288D1AC49}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\000195b3
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001967e
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001969d
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001971a
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00019862
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccapp.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\000198b1
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001997c
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00019db2
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00019ebb
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00019ecb
delsubreg|HKEY_CLASSES_ROOT\CLSID\{412441C4-07A6-4C62-85F1-823946775569}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00019f58
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001a2a3
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001a35f
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001a3cc
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CCenter.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001a514
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001a69b
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001aed8
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001af55
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001b5be
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001b5ce
delsubreg|HKEY_CLASSES_ROOT\CLSID\{41912A21-4337-4E99-8C30-80A8434B0793}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001b8cb
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001bddc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001c04d
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccevtmgr.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001c1e3
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001c60a
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001c752
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001c7cf
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001c83c
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001c86b
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001c8aa
delsubreg|HKEY_CLASSES_ROOT\CLSID\{41AE6BB6-3815-4F48-8FA4-920B586BA193}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001cadc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001ccf0
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccregvfy.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001ccff
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001cd5d
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001cdf9
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001ce18
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001cea5
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001d126
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001d183
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001d1b2
delsubreg|HKEY_CLASSES_ROOT\CLSID\{41D2953A-CB90-485A-8673-6975088309F7}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001d25e
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccsetmgr.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001d2fa
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001d387
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001d404
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001d4c0
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001d53d
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001d7ec
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001da2e
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001dd5b
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001de84
delsubreg|HKEY_CLASSES_ROOT\CLSID\{02845FCC-2BF4-4191-888D-18030FAA2074}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccSvcHst.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{42752A70-C149-4995-AE4A-AB81F12E9BC3}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001eae7
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001f085
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001f1cd
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0001fa0a
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\000223e9
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00022e59
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\000238d9
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00023e86
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0002400c
delsubreg|HKEY_CLASSES_ROOT\TypeLib\{CE7C3CE2-4B15-11D1-ABED-709549C10000}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ccupdate.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00024154
delsubreg|HKEY_CLASSES_ROOT\CLSID\{427E02E6-39DB-4424-A49C-7553CD1331F5}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\00025a0d
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\012A6CC4
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\017056bcacc9a780
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\09acbf9b
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\09fe46084be51e4c
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0B2F10D9
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0B834E5C
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\0f244108581299cb
delsubreg|HKEY_CLASSES_ROOT\CLSID\{1B1D8534-8B2E-4DF0-B92B-C878E4DB0F0B}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\111111s1ro1s1a
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\123
delsubreg|HKEY_CLASSES_ROOT\CLSID\{42B244BB-E8F8-4878-B4BC-BFC602FC1D3A}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\1231231
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\1231236700
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\1231239381
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\1231285995
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\1231286856
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\1231287283
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\1231292185
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CFIADMIN.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\1231372732
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\1231459057
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\1231459677
delsubreg|HKEY_CLASSES_ROOT\CLSID\{42C50607-D944-41A9-9B67-720AFBE8C22C}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\199854331
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\19b5406
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\1c5a43f0155e9c67
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\1Z8JZZBD3K9O
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\21A73
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\24024350
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CFIAUDIT.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\271b9742
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\2AU4Z2RGBP
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\2D627001
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\2TIC57I
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4306D2B4-1D20-4E23-AE74-3CE99776DBC6}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\32936173
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\360_Ssfe Serves
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\360diaCymfyb
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\360netmon
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\360rp
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CFIND.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\360safe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\360SelfProtection
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\360svc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\360Tay
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\360tray
delsubreg|HKEY_CLASSES_ROOT\CLSID\{434FA69C-5F0A-42e1-82B8-10AF2C8E53C6}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\360xxx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\361iaCeener
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\3cc6aec3
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\3dd78e68
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CFINET.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\3JYTQFG0Y4
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\3s
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\3ss
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\432E64CA
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\4433d5d3
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\457DMPA
delsubreg|HKEY_CLASSES_ROOT\CLSID\{43512378-9874-5641-1025-985420368734}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\4901228
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\4A0V5YVK7
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\4c70249
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CFINET32.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\4Help32
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\5075cd1e
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\5102a80
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\51KZHJ
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\5329ed20cba38711
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\58ED077C
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\5a9535a887186b1e
delsubreg|HKEY_CLASSES_ROOT\CLSID\{43ACDCC5-9009-4AF4-B80A-93BC656EF298}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\5C2A9C66
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\5CE18F38
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfp.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\5QVN4
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\60DFXFVR1
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\61cc9974b4cbd243
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\6457aed
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\6494d226
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\666666666666666666666666666
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\6979b56
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\6bfec438f5fbcf47
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4486FE99-9018-4E49-A6E7-28CBCAC846FE}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\6F5Y8F4AS
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cfpupdat.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\6MIV5D35Z
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\6OIIPJ
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\71VS7Z
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\724GAGKMZ
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\74d09421
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\76a1c9a0cb088633
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\76EFD247
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\77A35JV4CDXN
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\796A3998
delsubreg|HKEY_CLASSES_ROOT\CLSID\{45671234-7890-ABCD-CDEF-567801237654}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\chrome.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\798VUVX
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\823bca4830c88d47
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\8882fa1
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\8b1c3d14c902f43b
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\8b52f47
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\8cnvni4frx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\8EB51335
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\8j89l
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\8qezSbRT
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\8SWVG35R
delsubreg|HKEY_CLASSES_ROOT\CLSID\{00000000-0593-4356-9CF7-1D8C2B3343C0}
delsubreg|HKEY_CURRENT_USER\Software\3721
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CLAW95.EXE
delsubreg|HKEY_CLASSES_ROOT\CLSID\{029D18CB-8632-463c-93B7-C210AE50C722}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4582BCF1-1C39-4058-88B0-CDB8BB57EA61}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\93A732B2
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\945820X
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\9742C68A
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\9867E6CA
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\9cq81oao
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\9f903385
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\9fd8db
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\9ORFQ6
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CLAW95CF.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\9XP0P
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\a2free
delsubreg|HKEY_CLASSES_ROOT\CLSID\{45AADFAA-DD36-42AB-83AD-0521BBF58C24}
delsubreg|HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\a347scsi\Config\jdgg40
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\aajjelnf
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\aasyytv7nq3r5a
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ab0cc23
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\abopx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\abopxy
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\abp470n5
delsubreg|HKEY_CLASSES_ROOT\CLSID\{1BA683A0-8EE6-4C60-9BF2-907C2CB6B680}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\abpbp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\abpcx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\abpcxy
delsubreg|HKEY_CLASSES_ROOT\CLSID\{461D2AB4-29A5-45C2-9134-D52272D3DE38}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\abqab
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\abyoq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\abzpc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\acernbm
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\acpi24
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\acpi24Drv
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CLAW95CT.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\acpi32
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\acpi32Drv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\acpi64
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\acpi64Drv
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4629FF4F-ACDB-5C90-A098-FACB3456A264}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\acpidisk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ad
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ada
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ADBLOCK.DLL
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\admin_service_svcname
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CLEANER.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ADMon
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\adsz
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AdvanceLink
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\advxx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\adw
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4642593F-4159-4C7B-9036-33D6CD7F1750}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AE239D9B
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AE56BF14
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\aecff9
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\aecr
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CLEANER3.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\aede
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Aeeu
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Aeevg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\aefre
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\aeoha
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AExpSrv
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4679E74B-E5EE-458F-B613-2324AA1C817E}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\af
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AfaService
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\afdsfds
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Client.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Afeu
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\afex
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\afmom
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\afnqxvng
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AgentSrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\agxeoo
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Ahd64
delsubreg|HKEY_CLASSES_ROOT\CLSID\{470165F1-9F65-569F-F895-F14F58F41074}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ajbcyk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AlcwDrv
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Alefrfeter
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\alert computer
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\alga
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AlgSvc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\aliimz
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\alm
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Amffun Wswanyna Jec
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AMSSvc
delsubreg|HKEY_CLASSES_ROOT\CLSID\{47018D3A-8682-4D30-AC5E-F74B84189AB3}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AniSrv
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmdagent.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\anoko
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\aoqpx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AppropSren
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\APT9Z15L78E
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\argxx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\aroqs
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ARP.DLL
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\asd
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\asdcfvgtyuam
delsubreg|HKEY_CLASSES_ROOT\CLSID\{47544506-3C22-BBB6-9E9F-489B4B645F24}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\combofix.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AsiSrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\askdtw
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Aspnet_stater
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\aspsnet
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ASPX
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\aswFsBlk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ASWLSVC
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AsyncMacq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ATE_PROCMON
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Atfg
delsubreg|HKEY_CURRENT_USER\Software\AvScan
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cross.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{478932A2-862F-4A34-A264-54A6EB998FDE}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Ati2e
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Ati2enn
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Ati2esxx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Ati2evs
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Ati2evxp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Ati2evxx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Ati2ezz
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Ati2o
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Ati6ev
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cscript.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Atishirt01
delsubreg|HKEY_CLASSES_ROOT\CLSID\{02D83959-FAB9-4FCA-9A14-B71E4C1753F1}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{47958181-270d-4547-a2c8-d73002b9a922}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Ativxx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Ativz
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Atiw
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Atlw258
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Attrdh
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Atz
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AudioServic
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctfmon.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AuduoServic\Parameters
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AUJEV8M2AX
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AuthariPation enP
delsubreg|HKEY_CLASSES_ROOT\CLSID\{47994C89-1857-4D33-B196-263ED6FA4CFF}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AuthISvc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Automatic Updates.
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\autorun
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\avg8dw
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\avg8mc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AVP-SE
delsubreg|HKEY_CLASSES_ROOT\CLSID\{1C0D6505-4198-4783-82F4-C6683FF6C4EF}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AVPsys
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AVP璃
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\aw
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AwavenbssNum
delsubreg|HKEY_CLASSES_ROOT\CLSID\{484DEC01-A8CA-49DC-8DA9-35FE53BA36A9}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\awtxj
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\axboqr
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AxIntSvc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\axyoq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AYML9M
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DAVPFW.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\b
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\B004CE7C
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\b160485
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\b1a18a3e
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\b71fe93
delsubreg|HKEY_CLASSES_ROOT\CLSID\{487C9905-26A8-42C8-8033-C58AD3D2AEC3}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\b770ca2
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ba
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BackGround switch
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Backup_Info
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dbg.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\banp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BAPIDRV
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bbb
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bbbbbbbbbb
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bd
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bdbh
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4894F5C2-169D-4DAC-A982-444B9BDB3AC4}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BdGuard
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bdlal
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bDMusicb
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\debu.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BeatTrojanHelperOne
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BFB67F19
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bfddos
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BfeSrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bfgse244
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BFSDRV
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BGd Switch
delsubreg|HKEY_CLASSES_ROOT\CLSID\{489873CE-F3E1-44A3-8E89-04BE26BE4446}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bgh
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BitSrv
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Discovery.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BlbSrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bnfxh
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bnrdm
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bopab
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bopxy
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bopxyz
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\boqpxa
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bpcxy
delsubreg|HKEY_CLASSES_ROOT\CLSID\{49109876-7619-9101-7012-901938475194}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bpcxyq
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DrvAnti.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bpcxyz
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bpqcxb
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bqhpg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BrcSrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Browse
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BrSerName
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\brtdgxx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bsf
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BTDDOS
delsubreg|HKEY_CLASSES_ROOT\CLSID\{495271CA-D0C6-4052-ABE6-5B01C73CDFB0}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwadins.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BTDSOS
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\buk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\burti
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bvaz
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bvy4,^ac1122
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bxuje
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\bzpca
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\c362051765
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\c551839
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\c56bcc1
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\3721
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DRWEB32.EXE
delsubreg|HKEY_CLASSES_ROOT\CLSID\{49762F37-EF1F-447D-A27A-967C9520A3F8}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\c6424110
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\c9d9e2ce
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ca99d57
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cabyop
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cacwikpf
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\catchme
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\caukv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\CbEvtSvc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\CC2E5C7D
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\drwebupw.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cccDrv
delsubreg|HKEY_CLASSES_ROOT\CLSID\{49E0E0F0-5C30-11D4-945D-000000007667}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ccfmj
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cdadsa
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cdas
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cee
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\CF1.5
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\CF1.6
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cfsjp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cfv
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DSMain.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\CH341
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\chuguanghui
delsubreg|HKEY_CLASSES_ROOT\BDHlprObj.BDHlprObj.1
delsubreg|HKEY_CLASSES_ROOT\CLSID\{02EFB688-A21E-42d1-A830-2D67143FF0C3}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4A26AA9C-E583-4338-9BE2-17717E8E15DA}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\city
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cl200961
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cld
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\clddos
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cldos
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DV95.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\clos
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\CNGSrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\CO_Mon
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\CONTENT.DLL
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cpuz131
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4A698102-5904-AFD0-20DF-CD1A65829CA4}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Cqytfk Dvtteujn Qyw
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\CRE85ZMUYNW
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\CRWL5CZ
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Cryptographic Service
delsubreg|HKEY_CLASSES_ROOT\CLSID\{0005A87D-D626-4B3A-84F9-1D9571695F55}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cs1.3
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cs1.4
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cs1.5
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\csxxr
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\CtmSrv\Parameters
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cvafq
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4B00FA79-7C1A-41F1-AF62-C7FF0D3B96A7}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cvcbhyjhgbvgfredfrtgfvbgtyhgbhg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cvmvb
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cxbyq
delsubreg|HKEY_CLASSES_ROOT\CLSID\{1C1BB1A6-8167-4C20-AB35-03B97A1389C8}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cxopx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cxxqb
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cxyqr
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\cxyqra
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\d4f876
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\D6442DEB
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\d7b49fa
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4B00FA80-7C1A-41F1-AF62-C7FF0D3B96A7}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\d7ba6e
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\d812a079
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DV95_O.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\daaacad85ed21fff
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\daazw
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dafe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\darkshell Server
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dasd
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dasno
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dassx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\daxud
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4B00FA89-7C1A-41F1-AF62-C7FF0D3B96A7}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dbdcbd60
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DVP95.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dbghelp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dc2c8bcc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DC693BD0
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dcafd
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DcomLaunchs
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dcvxx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ddx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\deade
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dehdks
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4B3DA347-ACBB-497B-B62F-957C4D2B46D3}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DVP95_0.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DEKT3
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Description
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DescriptionHero123321
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DescriptionHero2
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DevSvc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dfg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dfhiyupp742xxvfrtynvs
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dflooi
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dfthfde
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dfx
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ECENGINE.EXE
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4BF9CBA3-8DEE-41A1-8BDB-FC28D30E949F}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dggggh
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dh
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DHCP clienko
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DhcpRpcLocator
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\di-r
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Distributed Agent Services
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Distribuynv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Djc50
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\djksa3069jkds
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Antivirus System PRO
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EFINET32.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dkaron
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4C648541-1025-9650-9057-6541258720C4}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DKRYEMSBJPWCJPW
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dllos
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DllService
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DltsSrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dmqoa
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dmserverWmiApSrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DMusicq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dndkn
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\efix.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DNSCACHE.DLL
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DNSHost
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4CAFE568-1C3A-4edd-856D-2B14249777CF}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DOBDZGGK08
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DogKiller
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DriveHealth
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Driver Desktop
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\drmkaudr
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\drtesm
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DrvKiller
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EGHOST.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dsafds
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dsefc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dsfg45fj
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4D023DE9-F4B5-4BE0-99C6-7C7AD0CF5426}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dsgdfjghjrfrdg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dshga
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dsjno
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dtesm
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dtgoitvoykl
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dticem
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\egui.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Dtorm DCOS Sarvice
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dwaq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dxdbt
delsubreg|HKEY_CLASSES_ROOT\CLSID\{0306438F-7E67-4DDA-8EF2-C0AD040FEBE0}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4D165A2A-4BC1-4CA8-8299-08E05AAAB5A4}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\dztmdpeq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\e4e5db6004258cf9
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\E5B5C058
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\E6733DB5
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ekrn.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\E7D0G765
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\E7E3FP8S48
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\E8569209NSH
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\e8e18360
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\EA23A528
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\eaf
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4D698451-2015-6358-9871-2015987452D4}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\eamon
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ED637B6
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\edas
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ESAFE.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\edewr
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\eeCtrl
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\eemxp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\efipsk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\efrgt
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ehdrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ehResvc
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4E3FBFA4-F1CC-4B66-B333-B9F0FF4B4748}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\EhttpSrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ekrn
delsubreg|HKEY_CLASSES_ROOT\CLSID\{1DBD6574-D6D0-4782-94C3-69619E719765}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\emxql
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\eoi1iev1e0io
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\epfw
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Epfwndis
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\epfwtdi
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\eqqcn
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\EraserUtilRebootDrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\erf
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4E5CFE74-700B-4A8B-B0BF-A6B47D896C18}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Ergses Dnxdltxc Vrl
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ESPWATCH.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ersfer
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ertesm
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\erx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\escd
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Event Logs
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\EvtSvc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\evxx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ewmqj
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\f1201c65
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4E7B7BCC-D111-49B2-A61D-26CAE048F844}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\f28907d
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\F41747390K
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\F6941060
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\f6f429501b983062
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\F8998C4F
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\faes
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\faf
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fci
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fdcd
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fdfdf
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorewclass.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4EFDDEBE-303C-4D1A-8C9E-E4F215C43651}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fdos
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fef
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\feos Service
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fffff
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fflqs
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fggggg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fghcyuaqu
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fghgfsdewe DDOS Service
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ghevqgrkho
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EXPWATCH.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\FgxjiA
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4F34C688-FD49-42FC-97F7-87D2F5791612}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\FgxjiA\Parameters
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fhddos Service
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fhfy
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fhhgfs Service
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fhos Service
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\filar
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\filpp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\FireFox
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\extdb.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\FireFox2
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\FLEXnet
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4F4F0064-71E0-4f0d-0013-708476C7815F}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fmtjb
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\foxshell
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\foxwei
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fpids32
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fqwerts Service
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\frae
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\frjnvcz
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\F-AGNT95.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\frrd
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\frs
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\frsetrfr
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4F5EEDE5-1687-49D2-8A17-FF0B454FB37B}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\frsgv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fs
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\FSBMUGBRLZRAHS
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fsdfdg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fsdfs
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fsdgs Service
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FAMEH32.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fsf
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Fsiuvj Xycjdpcv Jdu
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Fsruly Rmfostic Qfh
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\FsSvce
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4F72F83A-1C16-444C-8821-D01FF4759555}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\FsUsbExDisk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\FsUsbExService
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\FTP
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\FTPFILT.DLL
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ftvfk
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FESCUE.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fvgtyhj
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fxddos Service
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fxlxc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fy
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fyddos_service_name
delsubreg|HKEY_CLASSES_ROOT\CLSID\{030A0F33-5B99-482E-83F5-2EEB8457878B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4F81668D-833C-4739-ACDD-267B6E3A1FDD}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fytawerf
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\fyuh
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gAGP440p
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FileDsty.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\GanDiao
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gcbg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gdnbhn
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\geftei
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\geftei\Parameters
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\GENERIC
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gerxw
delsubreg|HKEY_CLASSES_ROOT\CLSID\{4FBFD5A4-5FE8-4444-8BD9-FD0FAFA64F96}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gews
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gfssdg
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\filemon.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ggtfs
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ghhxg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gjunj
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\glux
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gmczb
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\GmPna
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\GNKOCGINY
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gonweokinzhhhcz
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5007ED72-6A0A-4D7A-8C2F-B3D9CB85186A}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gorpk
delsubreg|HKEY_CLASSES_ROOT\CLSID\{1E322963-355E-422F-BE2E-8C4667E31D10}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\goxrf
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\GrayPigeon_Hacker.com.cn
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\GrayPigeon_www.hmhk.cn
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\GrayPigeonServer
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\GrayPigeonServer2.03
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gs
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gsdg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gsfck
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gsg
delsubreg|HKEY_CLASSES_ROOT\CLSID\{500BCA15-57A7-4eaf-8143-8C619470B13D}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\findt2005.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gt
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gtgfescw
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gthcg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gtI67
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gtrdf
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\guardian
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gvfncp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gvgfp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\gyuapq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\H5266EAAOK1V
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FINDVIRU.EXE
delsubreg|HKEY_CLASSES_ROOT\CLSID\{501A388B-6FBF-4150-9248-6D1E1BCF2B40}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\hackfans
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\hahpc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HBKernel
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HBKernel32
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\hbxqf
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\hcpidesk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\hdds Service
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\hdos
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\hdt
delsubreg|HKEY_CLASSES_ROOT\CLSID\{171565E3-F0BB-4FF0-9A42-C9406C79DB78}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fir.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Hdv32
delsubreg|HKEY_CLASSES_ROOT\CLSID\{50632D5C-B71B-4ba0-B012-3DC6F15C011B}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HG7XT9HCSEV
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\hha
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\hhwyamxbm
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\hiserver
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\hjkaCwlzww
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\hjkjxx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HkmSrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HNNIW1OFZKP
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\firefox.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\host
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\hostword
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5086CD29-ED02-41A0-B571-ACDA0C33BA94}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\hrhgres
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\htdhg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\htkhg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HTMLFILT.DLL
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HTTP SSSL
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HTTPFILT.DLL
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\huigx
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FPAVServer.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\hvacxd
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\hwksp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\hyhyx
delsubreg|HKEY_CLASSES_ROOT\CLSID\{50940F85-F015-14F1-A05F-F69858AC6D05}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\I2SNLW1WNFPF
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\IcePoint
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\icf
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\idnaux
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\IdsSrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\IdsSrv\Parameters
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FPROT.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ieur82
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ig2gx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ihzaq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Iidihir
delsubreg|HKEY_CLASSES_ROOT\CLSID\{50EBD6A5-0CF6-4E59-AE08-CCD991AA0596}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Iihvcw Kjwqnyts Sxc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\iiloylve
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\iirvlcu
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Ijgdux Ubhvbgsv Vtc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ijzab
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\F-PROT.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\IKEEXTENDv3.0
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\IKEEXTENDv3.2
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ikgir
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\IkjdPdp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ILP7Q6
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5123A024-BAB1-4DFD-A6F9-CE92A4DE8ED1}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\IlvMoneyDRIVER53
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\IMAPFILT.DLL
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\iMSPCLOj
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\incs
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\F-PROT95.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\infh
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\init
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\IogcWtf
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\iopmn
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\iozaq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Ip6Fwq
delsubreg|HKEY_CLASSES_ROOT\CLSID\{037C7B8A-151A-49E6-BAED-CC05FCB50328}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{512EABF9-6550-4B48-B46F-C6CE65F9D2C6}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\IPRIP
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\IPRIP\Parameters
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fpscan.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\IpwoAbw
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\iqzai
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Iraccess
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\IRANCH
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\IRENUMq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\irmons
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\irrzsvfly
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\is-QMM4Hdrv
delsubreg|HKEY_CLASSES_ROOT\CLSID\{51716C09-6B08-4CCF-B526-718E912C0573}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\IUACR7WR67
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FPWin.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\iuunk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\IVTR6B3QM1
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ivzai
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\iyzab
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\IzagDvq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\izzab
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jatmlano
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\JAVA 6.5 Servcie Sun
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\JavaQuick987
delsubreg|HKEY_CLASSES_ROOT\CLSID\{51AA0D89-E9A9-4284-93E8-40C0FDD59304}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{1E51C0FD-EE36-434B-AD2A-FD1FF3731C38}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\javk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jaxk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jbridgep
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jdlwjd
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jfmy
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jfwk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jgameenp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jgok
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jgrnq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jgyofsse
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FP-WIN.EXE
delsubreg|HKEY_CLASSES_ROOT\CLSID\{51B15F5A-E98B-4658-B9CB-9307B74773A7}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\JHA6WL3
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jhfk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jhks
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jhwuxv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jhwuxv\Parameters
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jlo
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jmlqhktstqivc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jmrovk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\johnx
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.lseiyejjmd
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Frameworkservice.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jpok
delsubreg|HKEY_CLASSES_ROOT\CLSID\{51F88A10-09E6-4763-948F-1C8861003255}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jqdk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jqfa
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jqka
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jqqk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jqtk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jqza
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jtsk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jvqjj
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FRW.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jwam
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jwfa
delsubreg|HKEY_CLASSES_ROOT\CLSID\{51FC2309-B81E-4542-A0F1-E9A51297F2F4}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jwig
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jwrk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jwtg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jwtk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\jyqjk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\kaghkfl4
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Kaspersky
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\frwstub.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\kaspersky 7.0
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Kaspersky Avp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Kaspersky AVP Setup
delsubreg|HKEY_CLASSES_ROOT\CLSID\{52023698-6984-8541-9654-698745012525}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\KAVSafe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\kavsvc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\KBXQ5Y2
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\kerne132
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\kernel
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\kernel32
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsav32.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\KihjOkx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\killvv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\KingDsnid
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\KingDuuBa
delsubreg|HKEY_CLASSES_ROOT\CLSID\{52345B67-1234-1234-D123-7F84D123BC7D}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\KingDuuBa A
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Kingsoft Antivirus WebShield Service
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\klan
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Klerter
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\klpit
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fsgk32st.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\koon
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\krtesm
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ktesk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\KtmRmSrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\KtmSvc
delsubreg|HKEY_CLASSES_ROOT\CLSID\{52635CBE-B590-458E-86DF-E4F82348511A}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ktrrg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\kvmgu
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\KVSrvXP
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\lasas
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FSMA32.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Launcher
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Lbd
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\lbjfsfqi
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\lboyzde
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\lbvvs
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Lcgvcp Aqhxrwbf Iqu
delsubreg|HKEY_CLASSES_ROOT\CLSID\{526403AC-FEDD-4350-946A-BC0B8114C65A}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\lcvibf
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\lgpjds
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LiveServer mode
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\F-STOPW.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LmHots
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LongRADrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\lpjbht
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LSAService
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\lsowx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LtdSrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LtdSrv\Parameters
delsubreg|HKEY_CLASSES_ROOT\CLSID\{038AEFD0-22F5-407F-9C49-8CC52462356D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{526EB425-7F56-4773-8D70-B8E45AA8E2B6}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\lutggsni\Parameters
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FTCleanerShell.e
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\lxkvn
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\lz2vnyhiaowie
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Made in China DDoS
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MAILFILT.DLL
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mamgpej
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mbfrdgh
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mbpiccvaid
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mbxwpo
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\McAfee Framework Servicrre
delsubreg|HKEY_CLASSES_ROOT\CLSID\{528DF602-9541-A985-210A-984A698C6F25}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FTCleanerShell.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\McAfeeFramework
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mcagx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MccdQaf
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\McComponentHostService
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mchInjDrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MD ServicesB1
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mdefdf60
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Media_Service
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MediaC
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MediaCanter
delsubreg|HKEY_CLASSES_ROOT\CLSID\{1EBA4EB0-24EE-4310-8F6C-7F5D6EDC19F4}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5350D2D5-0874-40ED-8D73-E3D0489215E0}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MediaCblldr
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MediaCbrfty
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MediaCentar
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MediaCenter
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MediaCenter\Parameters
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MediaCentsder
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MediaCentsder\Parameters
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MediaClkunl
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MediaCmbzbl
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.tmrxlcnlul
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ftp.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MediaCniptq
delsubreg|HKEY_CLASSES_ROOT\CLSID\{53915AE3-2660-4870-B092-C9E5A292D327}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MediaCqwqqs
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MediaCzxczxenter
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MediaeCenterr
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MediaSerial
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MediayCentern
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MediayCenterx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MedigCenter
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MeedidCnter
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FWMon.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\meng5555
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Messcnger
delsubreg|HKEY_CLASSES_ROOT\CLSID\{53D44DB6-E22B-4B17-97D3-572C96CCA6E1}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MFC\Parameters
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mfc42
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mfc43
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mferkdk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mfhtt
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mgxij
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mhfp
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FYFireWall.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Microsoft
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Microsoft Updateblk.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Microsoft Updatelel.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5405A7B2-F3F5-446F-8715-2A4EF674E079}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Microsoft Updateryb.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Microsoft Updateuxn
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Microsoft Updatezsl.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Microsoft VC80 MFCLOC
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MintRoot
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MiyaAyf
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GFRing3.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ML4FN
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mlng
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MMeica
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mmqpi
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5419706F-9AD1-49BB-A91F-EE6B62E2881E}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mnugg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ModemUSB
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\morkbd
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MprvSrv\Parameters
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mrrrsxrp
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GFUpd.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mrtesm
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ms driver management service
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MS NET Service
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MS Server Pretect
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MS service dasdasd
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5471D4CA-DADD-43B0-9FAD-009FB2D65726}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MS Softwar Provider
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\msan
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSCCom
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\msfpfis64
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ghost.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\msiffei
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSImanage
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MsiSrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSJDrvr
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\msnapa
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSNETService
delsubreg|HKEY_CLASSES_ROOT\CLSID\{54DA5754-2475-4B55-8DFA-D0327C8F4A9E}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSNSVR
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\msp2p32
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\msqmx
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GreenBrowser.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Ms-tl_Srv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\msupdate
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSUpdqexbx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSUpdqtehhk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\msurl
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mtlrd
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Music
delsubreg|HKEY_CLASSES_ROOT\CLSID\{54DE8BF2-906A-445A-8575-CCB08E809495}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mutacv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MYLOVERSYS
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\guangd.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MynuCdt
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MyProt
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MytuaCrtmlv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MyWebSearchService
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\mzaq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\n hj
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\nabift
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NAF0SOO
delsubreg|HKEY_CLASSES_ROOT\CLSID\{03F8FE45-1FE0-4C6E-8E6F-D210867F5446}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{54F6A1F0-18CD-4A8E-B08B-6A5203AADE30}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\guard.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NAIMServInst
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\National
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\National Web CC
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\National2.0
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Nationaljrq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Nationallms
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Nationallrj
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Nationalmed
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Nationalorn
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NationalSer1.31
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\guardfield.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{54FAE856-AD58-20CB-A025-CD4895FA6E45}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Nations
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\nbhgtrfdcfrew
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ndg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NDISPROX
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\neclf
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NesSrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Net Logins
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NetActive
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NetClient
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.yibibjb
delsubreg|HKEY_CLASSES_ROOT\CLSID\{1EEF419D-2264-4522-858A-5C2C31EDF2AA}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NetDDEsvc
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5528694E-30EC-46E6-98F4-C413B5AC4DD4}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NEtDesvc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NetHomeIDE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\netnls
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NetPortShare
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NetSharing
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NETSVCS_0x0
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NetSystem
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NetWare
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\guardgui.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Network
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Network Service
delsubreg|HKEY_CLASSES_ROOT\CLSID\{55694105-5108-9405-3695-954187462155}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Network Services
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NetworkAgentServices
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Networks Locatin1 Aarenes
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\nfhy
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ngkjrx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\nj
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\nko_Service
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\guardxservice.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NMSAccessU
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NNTPFILT.DLL
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\nopsr
delsubreg|HKEY_CLASSES_ROOT\CLSID\{556BA12D-13FE-41F4-9740-B6F1B8E1A8C3}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\notdm
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\notesy
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\notgs
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\notwq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\npkycryp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NrConnmags
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\guardxup.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Nsddyye
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NsDlRK250
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NsPsDk00
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NsPsDk01
delsubreg|HKEY_CLASSES_ROOT\CLSID\{556F0F4D-9CD8-4C91-A95B-0F88D638406A}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NsPsDk02
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NsPsDk03
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NsPsDk04
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NsRk1
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NSTOP
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HelpSvc.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NtfsSvc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ntio256
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NTS
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Nvidia32
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\nvmini
delsubreg|HKEY_CLASSES_ROOT\CLSID\{557217a4-234c-bafe-f52a-595f0a4aeb50}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NVR0FLASHDev
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\nwelx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\O2SCBUS
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\oasnp
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HijackThis.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ockuy
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\OdhhJti
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\odujf
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\OfklLru
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ofpehzhd
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ojwub
delsubreg|HKEY_CLASSES_ROOT\CLSID\{55BD6687-15F6-41B3-959B-B69C032E7795}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Oll81
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\oniney
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\opabbaa
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hsreg.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\oprabz
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\oprbz
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\oprxy
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\opxabz
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\opxyz
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\opxyzq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\opyzq
delsubreg|HKEY_CLASSES_ROOT\CLSID\{55D0FADF-CACC-495D-8400-7E7FA75CA4E1}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\oqrxa
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\oqrxab
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IAMAPP.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\oreans32
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\OSEvent
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\osogv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\OSS
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\OutpostFirewall
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ovssa
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pang
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pang9
delsubreg|HKEY_CLASSES_ROOT\CLSID\{56BC86C7-0692-4F94-A2C1-6CF1DBF8096C}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\panp
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IAMSERV.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Passthru
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pavboot
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pbfzmh
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pbmrjv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\PCICtrl
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\PCSCFW2
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pcxab
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pcxopx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pcxypx
delsubreg|HKEY_CLASSES_ROOT\CLSID\{04A76FFF-1AEF-456D-8E42-2862DF3CB62A}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IBMASN.EXE
delsubreg|HKEY_CLASSES_ROOT\CLSID\{56CF31C1-A46F-4B57-886C-6638DA412087}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pcxyq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pcxyqr
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\PersonalPolice
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\PeService
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\PEVSystemStart
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pfcjf
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\phphx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\PisbTng
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\PLASvc
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zjqpgkv
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IBMAVSP.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\PLSRemoteSvc
delsubreg|HKEY_CLASSES_ROOT\CLSID\{56E800F9-8E27-451B-B960-53EC724C3A87}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\PlugPlayCM
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pneua
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pnlilx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Pnoioeucs
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\PnP plug 0n Service
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\PnpEnum
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\POP3FILT.DLL
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\PORTMON
delsubreg|HKEY_CLASSES_ROOT\CLSID\{1F2E3A6B-94A7-4355-B58D-74DF486E6C97}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pouvm
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ppwgc
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5731EA1D-6AAF-4DE9-BDDA-7B390A75B286}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\presafe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\prnqs
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ProSafe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\PROTECT.DLL
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Provides Media Center
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Providesv1.2
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Provitep abfsdgitb ao
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ice.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Provitep abfsdgitc ao
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\prxyb
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\psmhq
delsubreg|HKEY_CLASSES_ROOT\CLSID\{574D626F-263B-4B1B-9F38-D858CF9135FE}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\psrui
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ptlbf
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Ptserlp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pwuaiseakxazttq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pxbpcx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pxyzq
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IceSword
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pxyzqa
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pxyzqo
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pxyzzb
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\pyhhzvo
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5768264D-0CED-4643-A907-581545843629}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qabop
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qabprb
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qabxz
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qaxyo
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qayoxa
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IceSword.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qcaxy
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qcxbyq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\QEZCIV
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qnommwq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qos
delsubreg|HKEY_CLASSES_ROOT\CLSID\{57AC9076-C898-B098-D098-A18319080975}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qpelotf
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qpraybpq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qprxb
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qpxay
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ICLOAD95.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\QQ MUSCIC
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\QQ Music update2
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\QQ Music update3
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qq2
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qqabo
delsubreg|HKEY_CLASSES_ROOT\CLSID\{589E405E-6C09-4341-862A-FFFEBD5C3C8C}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\QQOoAO
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qqqqqrrr
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\QQ秞氈
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ICLOADNT.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qrabp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qrabpc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qraqa
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qrazq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qrlee
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qrsytc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qrsytc\Parameters
delsubreg|HKEY_CLASSES_ROOT\CLSID\{58D4A9C5-DFF1-4EF6-BCA6-44D3EB4EA40A}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\QS RSVP
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qtfro
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ICMON.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\QTTAAH7Q
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qujis
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qutmdserv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qutmipc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qweqweqweqwe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qwesxcfvgby
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\qzmcoimd
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\r_server
delsubreg|HKEY_CLASSES_ROOT\CLSID\{58FF3024-8A83-4B1A-88E9-302F47646EEE}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rabpc
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ICMOON.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rabpcp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rabpcx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rabyqa
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\racxa
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ramb
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\RapSys
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rapzq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\RaSy6JD
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\RaSy6JD\Parameters
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5934EA2B-B2C4-4BE7-BF7A-FBA781A12E40}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ICSSUPPNT.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\raybpq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rayzp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rbpcx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rBpqhvFC
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rcmdsvc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rdkkg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\reaaew
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\RegSafe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Remote Storm Service
delsubreg|HKEY_CLASSES_ROOT\CLSID\{16BC0F81-410C-41DF-A902-1B04368BA8AE}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\afnv
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ICSUPP95.EXE
delsubreg|HKEY_CLASSES_ROOT\CLSID\{05AD2E16-C6EF-6AC1-136A-CE3FD8EF5613}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{59703ED2-799E-4F3F-9EBB-41B2F1F65C07}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\remotei
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\remotePCS
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\RemoteStorage
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\RemoteStorages
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rere
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rerr
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\RESSDT
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\RESSDT_MAIN_DOS2008
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ICSUPPNT.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rfclt
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rFFrrox2
delsubreg|HKEY_CLASSES_ROOT\CLSID\{59DA0F12-24E3-4616-83FC-7925675F2A30}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rfrr
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rfs
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rfy
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rgadta
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rgt
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rihdvx
delsubreg|HKEY_CLASSES_ROOT\CLSID\{1F71CA42-7E7B-4A47-A923-B5F4231617E2}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rising
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rising beijing
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Rising Task0
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5A041F13-A111-12A5-B0CF-F99818AA68A5}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\RiSingKaKa
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\RiSingKaKaa
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\RiSingKaKaaer
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\RjixGta
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rjmwg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rjzrgg
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\idag.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rkdph
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rock32 room
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\RouAcc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rpcs
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5A041F13-A111-12A8-B0CF-F99818AA68A5}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rpcsvc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rrr
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rsgfr
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rtgt
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\runtime
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IFACE.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\runtime2
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rwtwv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rwx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rxabz
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rxayz
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5A041F13-A111-12B0-B0CF-F99818AA68A5}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rxbzcb
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rxybpq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\rYHlGiiZ
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ryzqa
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iom.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\s0gmt7hz2s
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\S3chipid
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\s9pth1
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sad
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SafeBoxKrnl
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SafeMon0
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5A041F13-A111-12B3-B0CF-F99818AA68A5}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SafeMon1
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SafePrecatl
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SafePrechls
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IOMON98.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SafePrecpco
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SafeSysDrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\satey Service
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\scan\Parameters
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ScdSvr
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\scelogonos
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SCH0ST
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5A041F13-A111-12B6-B0CF-F99818AA68A5}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\schsys
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SCPDFV4ReadSpool
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iparmo.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ScpSrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\scvst
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\scxae
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sdegdfgwe DDOS Service
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sdewgfdge DDOS Service
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sdfashue
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sdfever
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sdrfgtyh
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5A069845-2036-6084-9054-6087502480A5}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sdsweer32
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Iparmor.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sdtbns Service
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SdxName
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Seagate Sync Service
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Seagate Sync Service.
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SeagateSyncServica
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SeagateSyncService
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SECRET.DLL
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sectolr
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Security Bios Management
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5A0B8C1F-115F-48AE-B52F-DDA144375324}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\irsetup.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Seekeen Service
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SENSMGR
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Serv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\server this
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\serverdk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Service
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Service Controler Installer
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Service.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\serviceJS
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Servicev2.0
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\aobacmli
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IsHelp.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5A5B354D-E845-487A-8544-F111366B59E1}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\servicev2.1
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Servicev2.2
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SesEnv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\setuplog
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sfadz
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sfr
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sh3fbus
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sh3fmdfl
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sh3fmdm
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\isPwdSvc.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sh3fmgmt
delsubreg|HKEY_CLASSES_ROOT\CLSID\{05FADA96-DDAF-4CCC-AC9C-41D3551945D5}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5ADD154A-2990-49F7-99D8-922E7D292E61}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sh3fobex
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sjb1100e
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sK9Ou0s
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\skdos
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SlrlFil
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SmbAdpSrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SmbApSrv
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\JED.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\smrkbdd
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\smss
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\smss.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5AF04671-190D-4D5C-97AF-D8054F831E27}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\smss.exe\Parameters
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\smssv.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SnmpTray
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\snqq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SPBBCDrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SpecialPolice
delsubreg|HKEY_CLASSES_ROOT\CLSID\{1FB3B422-7793-455A-8802-660853A9D102}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\spool.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\spoolsvn
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sppci
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SqlDebuger
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5B0C7E2C-3257-4619-8282-A173017B16E2}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\srgr
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\srivec
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Sroervice
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SSHNAS\Parameters
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ssl
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\JEDI.EXE
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ssswxplore
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ssx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\stgwe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Storm DDOS Service
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\stp Service
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5B1AEF69-DDAE-FDAD-DCAB-698F026ABDB5}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Sun Java 6.5 Service jdk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\svchose
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\svchost.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\svcname
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\JMPPWallUI.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SVKP
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\svnk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\svost
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\swice
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SwprSrv\Parameters
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sxdrcb
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5B77087D-AB76-4C22-B0A6-C34D1F438E55}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sxx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sxxx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sxzx
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Kabackreport.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\syitgyvdz
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SYMIDSCO
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SymIM
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SymIMMP
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\synsend
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sys_com001
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SysMains
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5B953C72-A6FF-11E0-9A84-00C04FD8DBD8}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\szace
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\taad
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kabaload.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\taan
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tacq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tads
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tafc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tafl
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tagg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tago
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\takfl
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5BBEB45A-1387-4FEA-AE57-74273B8C33C2}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\takgu
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kaccore.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\takjl
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\takqz
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\taksw
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\talg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\talo
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tame
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tamp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\taop
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tapiessNum
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5BBFBD79-78AC-42EF-B80E-1EFD555C0675}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KaScrScn.SCR
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\taqs
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tasmq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tasnp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tawg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tawm
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tawp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\taxx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tazj
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tcim
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip0
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bfgtthtvx
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KASMain.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5C648541-1025-9650-9057-6541258720C5}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\TCPZ
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\TDDI
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tdfgrsh
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tdgfv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tech\Parameters
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tencent QQ 2010
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\TesSrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\test1
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\test2
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KASTask.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\test22
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5C7596CB-C3CC-6BA3-BE52-8EEA63F9C61D}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\testbb
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tetye
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tfraq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tgsno
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tgth
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\thgtrxx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ti21sony
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tkauvyfo
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAV32.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tksso
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tlagif
delsubreg|HKEY_CLASSES_ROOT\CLSID\{06EA0A93-F850-4155-B819-BD0D9B5F25EE}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5C901F36-6395-4667-AF85-B1B64AD3693F}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\TolzEep
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tqnlhe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\TrafficCtrl
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\TrchSrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Trewsor
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Trojan
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVDX.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\trtesm
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\TSBSHZKDA
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tscbs.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tsebn
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5CEA2D14-E3C1-4EA7-BCFD-C79FC6EF28A7}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tshmn
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tskdcsryp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\TSKSP
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\TSP
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tsrIde
delsubreg|HKEY_CLASSES_ROOT\CLSID\{201476D0-2B18-462E-AB9F-3E2B0CC8732B}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tstm
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tt
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ttaxxvuw
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ttesk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ttos
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5D52083D-E1FC-42A4-802A-CA40106ECB2E}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\TtslSog
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\txfyat
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Txplatform
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\txqqc
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVPF.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\txqqe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tzaq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\tzdaely
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\u7t
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\UAU7IN0T5M96
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ucajzlbu
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5D7ED61B-DB3E-44EC-BED5-40307384FF81}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\UCKTFOXGPYH
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\udhwgxxs
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ufad-dns60
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVPFW.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\UhwoWsn
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\uj
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ukqhn
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ulenc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\umxnep
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\unjep
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\UPDATEDATA
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5DA743EA-6725-4ADE-BF17-C328743011FD}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\uqhq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\urdpb
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVSetup.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\usb6xxxk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\USBKMUS
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\usbmouseb
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\UsIxFRFp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\utcuaece
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Utility Mangserver
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\utk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\uuua9aicoue3
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5DDFF6E6-7FC1-4101-9B08-A9BD30446790}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\UV74N
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVStart.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\uvxuj
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\uxkhsa
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\uydrbg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\uyhgvfdc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\V90drv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vare
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VaultSrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vb
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vcsdaz
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5E7B90C2-75FE-4B5D-A3BE-68ABB8785400}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVsvc.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vd
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VDLUFOXGSBK
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vdthg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vdudb
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\veast
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vfd
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vfdgt
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vfgbhytgfvcdswewsazxsdfvbghyujnm
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VFILT
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vfs
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bolqdaiom
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KAVSvcUI.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5E907A48-400E-4EA8-9792-FFAE052D59E9}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vfsd
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vfvgt
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vGADown
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vgadrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vhost
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VisionService
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VMdDZgZo
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VogpKwj
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vrea
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kernelwind32.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vrgv
delsubreg|HKEY_CLASSES_ROOT\CLSID\{5EEEA400-799B-4A55-8F17-E03795052FD0}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vrs
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vrsegb
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vs
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vsd
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vsdf
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vse
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vsfd
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vsgv
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\killhidepid.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vsr
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vsrf
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6049BC02-7EDA-4C41-B4AB-D5398607C39E}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vsrfr
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vsvas
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vsx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vtdgt
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vuovpiopxoqx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vvebc1ntDrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vvgop
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KISLnchr.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vvWJKhpz
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vwqfhx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\vyjh
delsubreg|HKEY_CLASSES_ROOT\BDHook.BDSrchHook
delsubreg|HKEY_CLASSES_ROOT\CLSID\{072DC5A3-0EF5-42C8-AF3A-52D74BC3CBE6}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{60A345CD-ABCD-EFAB-CDEF-ABCD01020306}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\w
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WajiSvc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\waodj
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wazkcas
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kissvc.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WbioSrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WbWin
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WbWin\Parameters
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wckko
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wcssrv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WebClients\Parameters
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6101B532-3E30-49FB-8594-F9B22338FF4A}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wedr
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\weebe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Weemi Service
delsubreg|HKEY_CLASSES_ROOT\CLSID\{00180018-0018-0018-0018-00180018BB15}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\weevx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wef
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WefpGui
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\weqianj
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\weqjn
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wewsee360
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wgcoh
delsubreg|HKEY_CLASSES_ROOT\CLSID\{610B6886-2A1A-475A-A842-65A613C70460}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\whetg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Wib5n4p32
delsubreg|HKEY_CLASSES_ROOT\CLSID\{202AEF39-2BFA-4A5F-B526-390FDE0BC675}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Wib5n64p32
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Wicump32
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wilusbmonitor
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\win
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\windosyee
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\windosyw
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Windows Adio
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\windows conler
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6212B202-7BBF-4B40-9AFC-A88133B84018}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Windows Help System
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KMailMon.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Windows Live Server
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Windows Managemuirw
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\windows save server
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Windows Search Page Down.
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Windows Service Updates
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Windows systems safe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Windows Update!
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Windows Video
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Windows_rejoice2010
delsubreg|HKEY_CLASSES_ROOT\CLSID\{622E84AF-AB3B-419E-AB5C-67DA236E91AE}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KMFilter.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Windows_Update
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WindowsEntMianFeiV08
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Windows-pass
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WindowsRemote
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WindowsYouti
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Windriversrv32
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\windswe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Winfe32
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinHbnbancaelp32
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinHe95
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\knownsvr.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{62C2B451-2F5B-4A7F-84DD-F2FBC3735E4F}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinHeaqqwcxzlp32
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinHees32
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinHelduoyudehiyi
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinHelp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinHelp\Parameters
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinHelp2
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinHelp3
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinHelp30
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinHelp32
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\cdpxdcvhnfsp
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFW32.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinHelp323444
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6302B4AC-43E3-46D2-9969-629A0E175FB1}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinHelp32666
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinHelpbs32
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinHfdselp32
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinHlp32
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinHtoxuanan
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinHttpSvc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Winistelp32
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinLests32
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFW32X.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\winloginsav
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Winows
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6345F11D-722C-4B9B-B99E-0E9F58F30522}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinQJServiceNow
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\winrarese
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinSCCOM
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\winsedx.com.cn
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinService
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinSSCOM
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wintkser
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPFWSvc.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wintyf
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\winvideodril
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Witingsp32
delsubreg|HKEY_CLASSES_ROOT\CLSID\{63C8062F-BA71-44A1-8322-1C9A84783778}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wjjaq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WM
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wmiApSvc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WmiSvc
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wmitpfs
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WMMNetworkKtx
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KPPMain.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WMMNetworkRwa
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WmpNetwk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wmpobj
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wnfrm
delsubreg|HKEY_CLASSES_ROOT\CLSID\{648B6B95-9B30-47F2-AA08-AA0E665128ED}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wpa
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wpkxxi
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wqogl
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WRF1NXEJ
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wsem
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KRegEx.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WSIVS
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wtesk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wuausvce
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WumenHelp32
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wups
delsubreg|HKEY_CLASSES_ROOT\CLSID\{073B937F-266D-4FF4-B73A-41A0236DD0AA}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{65056902-6E7B-4bd7-95BA-688DB5FA5BEB}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WVSSVC
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Wwgcen Deypvvpm Ccg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\www.skd4s.com
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KRepair.COM
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\www.skdos.com
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\www.skdqs.com
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wyddqlm
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wyssbdad0
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wzaq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wzcsvcnetsvcs_0x0
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Wzrd- Application
delsubreg|HKEY_CLASSES_ROOT\CLSID\{653BC427-1413-4CFA-B41F-3F0294E7640F}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\x
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\X5S1QUIRP3O
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KRF.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xabzrx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xayzpq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xayzpqa
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\XB1OBMCVHZLC
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xbpxyo
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xcdfvbgt
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xdrsuqve
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\XDva269
delsubreg|HKEY_CLASSES_ROOT\CLSID\{65C5C134-DB66-43EB-829E-C973D5F9CEEE}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\XDva279
delsubreg|HKEY_CLASSES_ROOT\CLSID\{20618412-C528-C784-C056-C164D1F7C502}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xfnir
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xhhcsvhwwfndu
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xiezuebg
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xiezuihr
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xiezukcrs
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xiezuoja
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\XieZurbi
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xiezuvtj
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\XjhgGle
delsubreg|HKEY_CLASSES_ROOT\CLSID\{65D89E28-6877-480F-85EE-B67147796C82}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\krnl360svc.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xmgqdtk
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xopay
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xpluv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\XPZDP6
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xryqa
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\XTrapD12
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xtrlj
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Xueeueusz
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Xurcsiuzi
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xx
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KsLoader.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{663FCF67-330C-47E9-973C-2260DE48283B}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xxdos
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xycaxp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xyqra
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xyqrab
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xyqrap
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xyqrq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xyqryz
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xyqxy
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xyrabp
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1f4de370-d627-11d1-ba4f-00a0c91eedba}\Shell\扽俶(&D)
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kswebshield.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xyxyz
delsubreg|HKEY_CLASSES_ROOT\CLSID\{66AFCB56-FAA9-42D2-8C72-2767A46C7FA8}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xyzbra
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xyzqa
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xyzqab
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xyzqo
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\xyzqxy
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\yahoo
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ybfzmhyf
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ybpcxy
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVCenter.kxp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ybzcab
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ycvibfvf
delsubreg|HKEY_CLASSES_ROOT\CLSID\{66D2E7CF-582B-4146-85B3-93224CB76DC9}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ygxeoofu
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ymrovkru
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\yoklvjdp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Yonline
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ypcxbo
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\yqfprhqr
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\yqrab
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvDetect.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\yqrabp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\yqrzq
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ytfj
delsubreg|HKEY_CLASSES_ROOT\CLSID\{66E62803-BC8B-448A-A880-96322FA7E23D}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ytwys
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\yuwtnf
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\yydrbgpv
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\yzcxy
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\yzqab
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\yzqabo
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvfw.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\yzqxy
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\zasnp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ZdN55hm4
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\zgwjxiycbnwphz
delsubreg|HKEY_CLASSES_ROOT\CLSID\{670D0417-CD55-4C33-94A6-BA5CDA0876A3}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ZhuDongFangYu
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\zijahrxj
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Zloguwzp
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\zoklvj
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\zpcaxy
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvfwMcl.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\zpqcx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\zqabo
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\zqabop
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\zqbnyvy
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\zscgunvice
delsubreg|HKEY_CLASSES_ROOT\CLSID\{674de1aa-facf-47a5-a4cf-9ef05f9a1b2a}
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\zx
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\瑞堁厙釐堤
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\6E2F5689
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\057B5CEE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVMonXP.exe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MpKsl5d04b853
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MpKsl75cb81fe
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MpKsl834fa970
delsubreg|HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MpKslc81d2729
delsubreg|HKEY_CLASSES_ROOT\CLSID\{074616A6-5ADC-4A3F-B252-E1D605228B5C}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{67A4A417-26DB-4FA5-922C-3F036D95647A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6826A3DB-EA8E-4E67-880D-53D04C7C0BD8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{68F7767A-090C-4BBF-A015-720ACC6706E2}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{68FC11DF-A032-4429-995C-730586B6114F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{695C5A80-18A5-4CD2-A911-4DBEBE92F18D}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVMonXP.kxp
delsubreg|HKEY_CLASSES_ROOT\CLSID\{69828DCD-20B6-4588-BDC0-8A8D0656FEDC}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{69B265A2-A172-4D27-BDF1-917E6D8B1DCC}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6A041F13-A111-12A3-B0CF-F99818AA68A6}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6A069845-2036-6084-9054-6087502480A6}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6A2F86CD-BA9B-49A1-B708-9C550BEF6DA7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{076FB645-17A5-4DE6-B23E-C90FAB741CB0}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6A8D34D7-08D7-421F-AFF6-956A0BD6F0BF}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6A908760-8000-4000-A000-9000322145A6}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6A9709C3-8A46-411A-0890-35D3D3166660}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6AA221D9-0DDD-4A03-B4EA-5360359D0AE6}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVMonXP_1.kxp
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6AF45C53-676C-451F-A4A9-DC8D61D9D46A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6B1AEF69-DDAE-FDAD-DCAB-698F026ABDB6}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6B9FEAD7-4319-4312-AB05-D8C9CD255BFE}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6BB80F57-0262-4FE0-841B-5EAAB5609BF6}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6C5DFBB6-9D4C-4C97-8073-DAA1CF156168}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6C648541-1025-9650-9057-6541258720C6}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6C8D1401-A58D-A81C-CD24-A5915C4517C6}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6CC3BA8B-1594-4607-BC83-E4AB6B6AF176}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6CDC431B-5481-43EB-93DC-901CD4DB2F1E}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{20909876-4567-3908-4056-909834565102}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6D4C8213-9FF7-7C76-29A2-083C0C7BB02F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6E28339B-7A2A-47B6-AEB2-46BA53782379}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6E753CA1-7CED-11d8-A178-000BCDB8C679}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6E7ADF53-1A96-42E8-BB07-53A8EA8BAAA4}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{6FD45A54-9875-698F-E56E-65102358FDF6}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{704C3595-DB85-40F6-A601-8D6F346907BD}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{08223B03-1B38-4A33-A83A-A4D3CC1D6E4E}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{70C09FA4-3B41-4E53-B195-F547FE88FF73}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{71046DD5-E136-4C4B-A6B5-91C30CB15291}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvol.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{711D85FB-681D-4F4E-A214-41A615900A20}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{71463F9C-9BA4-46A4-9AA9-61AB4D65409E}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7152C68A-D93C-49BF-AFEF-6B4576849A7E}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{71A78CD4-E470-4a18-8457-E0E0283DD507}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{720A87A2-9E33-41DE-8F42-CB514BFF1F6F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{72236771-3891-46BF-B185-1D816A09333F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7242A763-6114-4045-9970-07C545D72C45}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{726B4F5C-36C9-4D42-AD3A-48F768A1DF3F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{083A5F21-BCB9-4B21-A121-2584BEEFBFEF}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{72B29486-39B6-4241-B234-B57DEF78302F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{1719B301-B494-4185-9379-242461F9CF02}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvolself.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7319A1F1-9410-9654-3201-345FFA349137}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{732AD45D-A875-4019-970D-B32DA96C3EBD}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{734447EB-69B4-418B-8CCF-F92047108F51}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7345AD03-BF1E-4B23-8ABA-646A8E085BA1}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7359CB42-AC3B-489C-89BF-7699B597B779}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{736D2B41-7BD0-45BD-BF7C-E73AACC8356B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{737858A9-9AEA-4838-9B49-54DA731F7F37}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{739A09B9-3DF2-484F-89A1-0C417E598ECD}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{73AE86E6-7F03-4C3B-8980-FB1DA157D3C7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{085C12EA-A2F6-B840-62C9-57F44DC40C47}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVPreScan.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{73F1DAAB-0DBA-4804-81C9-BCA409393AAE}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{740D3283-A18C-4F48-8D65-2745215026AE}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{741D962D-B1DF-4BE4-8C92-FAF45661D30D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7488E47D-E8F3-41C0-B2DA-9B2BD8803A80}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{748EFE3C-3192-7C2B-AD61-BA112A31CFBF}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{749E4FEF-6AFF-41A6-AED8-364222D455A7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{74C557B4-3E0B-4289-87E4-6AC8CB4FF099}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{74DA2FEC-F68F-4DC7-9A45-9174AC044427}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{755D0ED0-3996-4ADB-9B1F-AD8F0E9E4738}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{76220F29-1F4D-4A8B-9E32-2D64FF0B41D6}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvReport.kxp
delsubreg|HKEY_CLASSES_ROOT\CLSID\{085C1F40-1C33-4296-A3B3-CC47540B9A12}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{762D618C-E2CB-4217-8275-03302A93073F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{765BA0B5-EBE4-4B1A-AFDA-5683606F626C}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{76757940-7773-4AA5-BB57-F4A0270E165C}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{76B9BA7A-81D0-4979-8598-8471F2AB5186}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{76CBCF38-0583-44C7-A1AE-D463DFE625EC}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{76D44356-B494-443a-BEDC-AA68DE4255E6}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{77064888-B267-464A-AB8A-BC262FB23603}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{77AC4257-6781-430B-80C1-BCA6D20C950F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{77AE086B-ED00-4527-A208-6FFF03D92F4C}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVScan.kxp
delsubreg|HKEY_CLASSES_ROOT\CLSID\{77EDC705-6B15-4ADA-B25E-B791D30569Db}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{086CBBCA-8B04-47E3-B792-5E2C558F810D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{77FD640A-158F-48AC-FD14-1597F14A9777}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{77FEF28E-EB96-44FF-B511-3185DEA48697}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{781B13B8-70FF-446D-90D6-D823FACE394D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{781FBCC1-99C7-4AE0-95F7-66EA49E86DD7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{78B02B63-EAF4-40EE-935D-C86DF4C6970F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{78DAA23D-614E-445E-942D-7E69EDA464DF}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7938BD2F-0143-4C46-991C-71069712D9D9}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{79462C10-DB9A-4CA0-B3DB-24AE72636B75}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVSrvXP.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{79470BDB-086A-4A4C-90B1-66452C36E5B4}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{79921D3F-7537-463E-9E38-CD503A8FA485}
delsubreg|HKEY_CLASSES_ROOT\BDHook.BDSrchHook.1
delsubreg|HKEY_CLASSES_ROOT\CLSID\{086D50B6-D088-41A4-B6C8-5DF3B02FA3C7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{79C12B2D-3792-4FD4-924E-87272BD728A9}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{79FC744E-75CA-49B0-8F02-AEAE4CAACBE0}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7A041F13-A111-12A3-B0CF-F99818AA68A7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7A6DF30E-D0F2-446f-B4F0-BF4232D60E07}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7ADC2AB1-5C6A-4178-82DA-94863354AF7C}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7B473157-ABA4-4222-8505-42F5D34EF824}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KVStub.kxp
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7B8B0E17-B03E-4EDE-BA46-F31692D977BB}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7BACC4F8-0754-4BA0-BB18-9DDB1B8C6C48}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7BD57B5E-3091-4C33-B2E2-A39392F9F1D4}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7C2727B6-5368-4582-BEF7-DB3370C262D7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{08A8DAE3-31B7-4702-AF5B-558D1F84FE35}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7C59DDC1-7792-4027-9D72-9807937E3464}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7C69034A-F45F-D34D-A33A-C33C4D324FC7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7C8D1401-A58D-A81C-CD24-A5915C4517C7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7C954872-1230-6541-9548-6541025884C7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7CC109E5-B2FC-4FEE-AF04-74B2DCBD2540}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvupload.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7CC1DA3B-A5C8-4329-8004-41981BA4BF86}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7D20F028-D3F8-4B18-B42A-6F569EEB77E9}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7D5C8CCD-0111-41B4-9A61-73927EF2F242}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7DA50197-30CB-4559-A42C-9E61F44555F8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7E72C5E4-028B-4C43-AE6A-52FCA04C5CB5}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{08CBFE20-8DC8-4195-B8E2-DD66F860469D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7E853D72-626A-48EC-A868-BA8D5E23E045}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7E94C114-C874-4112-9922-054D8E5546E2}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7E983C60-EBF5-4A36-BE25-EA26ED55052B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7F12CA98-B0BE-4408-ADFD-8B8AE6AF847E}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kvwsc.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7F41BC77-7742-4ABF-9277-1316B43D049A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7F753D7F-3EC8-4467-B2DD-A148F978D29F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7F965200-EE7C-46B3-9A22-B010E2149769}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7F9F521D-41E2-4DB8-936A-F126EB10EBFA}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{7FD45A54-9875-698F-E56E-65102358FDF7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{08E909A4-B236-48DD-8BCC-90A604B93E68}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{80010030-0911-00E3-8467-99ca3230262a}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{80168013-E05A-4A05-88E9-6687C2D17362}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{803E9ADD-8D2B-4D78-AD34-D7FD790A17FB}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvXP.kxp
delsubreg|HKEY_CLASSES_ROOT\CLSID\{80AF1289-F140-A140-D012-C1458759FC08}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{814AC387-61EE-4BAA-963A-55FF92BDDB7B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{81549ADC-2F24-4784-8124-F1075D770539}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{815EDE81-767D-4636-80F5-141578667A98}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8183F477-9E50-46A7-A3FC-35C149891BB6}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{81AF1CF6-D1C9-4C6A-AC01-EDE54E71945B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{81BC0740-6E31-4BA4-81C8-EFF9ECEB3BA2}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{08EB3951-6162-47C4-8EF5-CF51744E2B5B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{822775B8-E45B-4E55-9325-0753A0C1DC00}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{827E2FB4-1047-43DE-848D-E12BB0C97AAB}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{20CFDC59-228C-481F-80B6-404BCFA16B13}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{827E7421-A6BF-4BD7-B3F0-8524FDC2168A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{82DE2804-AF65-4CF2-BD3D-A95D734D6BDA}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{82E044C4-C4CC-4535-B731-F6CB8EB1F6D8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{83108597-9059-F574-5B3D-48FF818F79EC}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{837B45D6-BF85-457D-AABF-6D2E7815F791}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{83B78794-1991-4BE4-A439-D5EF37E8DC97}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{83BA45AF-FAAA-CDDD-BEEE-BCDE1234AB38}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{840AEC38-0194-4BA3-8621-AFC7CFA9F3F8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{09EB15FA-17D8-4D60-8598-3F549A848DF2}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{840E7363-FA0F-4925-9C51-817FA7C2EF32}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1f4de370-d627-11d1-ba4f-00a0c91eedba}\Shell\扽俶(&D)\Command
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KvXP_1.kxp
delsubreg|HKEY_CLASSES_ROOT\CLSID\{84143967-B645-4BFF-B873-DA1DC886E9A7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{841529CB-7F77-4B99-A895-B5441E0D302F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8419DDBB-EF93-4558-9934-9B439EF9CBAE}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{844B57D0-AD06-499F-AC52-15A4E6D14C28}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{844B8558-9E29-4D70-AF91-26319E22F1A8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{845BA58F-711A-48BD-948D-E6024F49909E}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{845C1D27-529C-4EA5-9796-8E71AC5933BA}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{84639C2D-CD75-4081-B515-329AFCECBF19}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{84BD3613-EBAB-4CCA-9E94-00CE6AB956A6}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{0A2D7F10-1153-4061-AA4B-ACB870212B57}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatch.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{84CC1A5C-D480-4E41-AAD2-C72B7A2635C5}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8554F9AB-AEF3-4701-886F-4192F0CC36C0}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8566F82E-03A4-416E-AEAC-66600D8881F1}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8567EDFA-408C-43e9-B929-4C25C04F5003}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{856F6FA5-447F-4FB8-BF6F-FBEDB90A3829}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8614153F-3930-448B-9AD8-E65DF6AC4750}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{861603EA-21EB-487F-87FD-D373009787A2}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8708994F-1758-4C2C-9A3F-FA22D6CCCB41}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{871A54C1-1EB3-48bd-A879-5DBA4EF16BE6}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{875E07B1-0614-43D9-A76E-D76A28AB3D7B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatch9x.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{0B014B81-4E12-46F9-806F-55867AF8FD3C}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{87DE8A1A-96C5-4420-B222-EF998F697CE7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{87FD640A-158F-48AC-FD14-1597F14A9778}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{88A7AF21-3F82-4298-93C9-B7D572C51277}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{892B9CC3-70DB-4E90-B57B-07A8AABB0A86}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{894C0068-46AC-4F59-A140-EDE0DABA776C}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{898E02AB-9372-4a2c-9C4A-FFE1AF61097F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8A041F13-A111-12A3-B0CF-F99818AA68A8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8A2B5714-1F9B-4843-B131-FC191AF30758}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8A6A5B34-D995-4C5D-9338-B5E264B4A87}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatchUI.EXE
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8AD0F1B1-990D-4F52-A33D-2837E43CEF58}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{0B3358D2-410F-4693-9C14-DD01CE1698CF}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8BEE6B12-EDA7-4111-8EE5-0947236AE4AC}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8C41B7F7-3168-400D-A702-0E7EFE0BA304}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8C8DA92A-857A-4B76-9688-BFDADEAAF495}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8C954872-1230-6541-9548-6541025884C8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8CEBFDC0-A57C-429D-8510-0E5E01AD6907}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8CEEE744-30B0-4100-B016-46913B889857}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8D10FD9A-5715-48BE-9835-EA19947D281E}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8D79D9C6-D210-476A-82B7-5D9113A40CE3}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KWatchX.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8E3526E3-F160-437B-9095-46A011877CBE}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8E6D4583-0FA1-41B2-BAAA-63352E6333CA}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{0B43554E-BA93-429B-8531-647CC155B8D3}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8E97DB95-ED1B-408C-9454-02FC9990C148}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8EE9AFC0-F04E-4501-8225-06F107566FE8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8EF8F90E-15AD-4C22-B3B8-74A0BBEF0B77}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8F61586C-5D1B-4c76-BB3A-3B88F96A18B0}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{8F67E146-FB6C-418F-9FE5-37AA2206D92E}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{910A5582-4F7C-42A4-A070-0C91A1E68085}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lamapp.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{912F6837-CCB6-424B-BC9C-8BB5541AFB54}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{91954FAC-1023-154F-895A-1458258AD819}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{91AA45D0-4D9E-4EC4-ABAE-AE30F7FCCD3D}
delsubreg|HKEY_CLASSES_ROOT\BDHook.URLBDHook
delsubreg|HKEY_CLASSES_ROOT\CLSID\{0B83E10B-88B2-4A02-B603-0494C2A87DC7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{91C7DF6D-AEF5-4136-9252-AF030D7A5931}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{91CFF913-BADF-44FC-9C44-5CC06F8696C1}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{91F5C9DB-ACD1-4812-BAB9-6F5AE433930A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{92335157-984B-4692-8405-530335CA9F27}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{92E496B3-2E80-4FE0-B6F8-B3308BB6BFB9}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\licmgr.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{92EB19C4-F0F1-4D18-A3BC-59658F64F8EE}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{93001DB8-F229-43F3-B533-9F546F1AD1EA}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{9319A1F1-9410-9654-3201-345FFA349139}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{93B5C837-F80A-4337-924D-3A96D853C5A8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{93DA1E7D-7C46-4F90-8674-EC90511FCA72}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{0BC82A03-D2E1-42BB-87BB-BDF7692AC2A7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{93DEE065-EC9B-4505-ADD3-19880AD3C38F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{93EC6B33-16B4-4110-BBC1-8B4A20E321C5}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{93EE42EA-B0DD-48A3-98DF-DF1C1E9D8988}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{93F33500-527E-4E33-AECA-69B15243A90E}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\livesrv.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{950D1600-DE4A-448D-93B4-7BAE5A7A8052}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{96F14DB0-A8F3-4334-BC67-89C51B609DF4}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{9726072A-8039-4958-B609-565CF7A16B38}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{9731FA19-8C71-4763-85EA-BB64CDE11D8E}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{97421D0D-E07F-40DF-8F07-99597B9585AD}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{97972049-FB05-4A90-A600-FE5EB197F76B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{0C36AE95-DAB2-480E-A50C-2AD6E59D5CF0}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{97A32646-10D8-4EC8-8248-A27FAB047D79}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{97FD640A-158F-48AC-FD14-1597F14A9779}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{98283B12-E35B-4051-86EA-1EE682FB369E}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\LiveUpdate360.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{984FD966-B303-4CD8-8A6C-8D70E6B1F1E2}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{986488AF-13D5-9DDF-4FEF-9FB88698CFC1}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{9867A72A-B1F0-4AD8-BC4B-1E1065B85E13}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{98B7C13A-E9CD-4959-8B46-FBEAB41E42A8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{98C57570-8CC3-489E-8CF5-3EE644500681}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{997B14DD-E2D1-4FAA-A17E-DC4F64F8EBFC}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{99F71232-CFE3-42BD-BAEE-3E69D233A4C3}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{0CCE6E12-C2EC-56CD-1A62-AE3FD6EF56E6}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{9A4E6730-B97D-43D0-979C-C81F88D78559}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{9AD1DE62-196C-4C01-9A2F-0BEDEF727C59}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\loaddll.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{9B0D4EA5-8A3A-410E-A1A9-FB87FCAACF13}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{9C20D654-5AF8-4DB7-A125-1A17D7065C73}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{9C7A2EA9-A168-4157-A3E6-7E47A248E204}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{9CA963CA-107C-4089-B0AB-31380F90D7E3}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{9D3A3726-0BCB-4474-90C7-522774D42531}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{9E325A3C-2B26-4CDB-9E40-9713C2788F89}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{9E32A24D-BEFC-4BF9-A25D-91C37CEDE61B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{9E8287B0-0F3A-48ae-99C5-A6E0AAC36BC5}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{0CDCBC5F-D4D5-48CC-8B20-3897858D9973}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{9F684DE8-3E87-4174-9033-E02A3DFD8B61}
delsubreg|HKEY_LOCAL_MACHINE\Software\CLASSES\CLSID\{BC207F7D-3E63-4ACA-99B5-FB5F8428200C}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{21BE5FDF-D4CB-4850-AD99-21E68B50BF3F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{9FA4F5A4-CBC6-454a-A170-82D954252EF6}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{9FC3AD52-875C-4FF9-AA4E-5A6D86D4A0B4}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A0113412-4022-4B59-97FE-2DBD8D710394}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A024A926-B807-40B7-A94A-CD62D76DA0D1}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A06E2720-F24E-90B3-D5C6-333C14A3F43D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A0C86020-5935-4B87-B20E-0B656D450264}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A1A6BC2E-C6A1-43C1-8884-A31D772F42B8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A22390A5-4FDD-4366-B9ED-D2AB728E220A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A272F097-E24C-4A6E-8BCD-8C42839CE8DE}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{0D267113-499A-4EEF-998D-C45731C1B313}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\LOCKDOWN2000.EXE
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A2BCFCEE-C939-433F-A32A-7353A6E720DB}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A2C3BA54-DF75-4881-8EB3-E54B26BBBBC9}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A33B53E3-404C-481D-8F9C-33E416E9D865}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A36FF2ED-2F06-4F7F-9A43-F109A8463D86}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A3822D97-2330-4A3F-94C1-381E37D46BED}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A3C95A74-638D-4C6B-A856-4B27664A7F47}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A3D8CA41-41ED-405C-8BC0-65E99BE834CF}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A43BFB0E-BF1B-47E3-8A7A-53FB4E1104FF}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A4A419B3-D0D5-4E1D-AE79-91CF9E920B99}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A5076382-B8B0-4396-A5A7-9F48FFC8549C}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Logo_1.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{0DCB6565-A9F9-41CA-97E1-65F4A6345F3E}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A55F538E-9E65-4706-9458-852BF6592063}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A5B2B651-7819-42d6-800B-E9F7FC2853C9}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A5CA6C70-7185-4466-AB45-B1C34E7A37CA}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A600E212-2A41-41BC-92F1-ED5C96B06185}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A629FF4F-ACDB-5C90-A098-FACB3456A26A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A6B7F435-38B4-4DCC-9EBF-21C968ECF4FD}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A6C1FDD5-04DF-4707-A74B-92BB9D8A8F68}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A761BE8E-C15A-4DDD-A777-2C683E9E96C8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A7CD6B0D-0EB7-4476-BEA7-167E39744C66}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Logo1_.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A7EBD59A-2438-41D6-B8A9-788300588DFF}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{0E55A9F5-EEA3-4334-9906-F2FB3C821153}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A81EBFD7-0FA3-41ec-B60D-6DAE78B4D31A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A85363C1-CAB1-4999-A0D6-4951BBF69BE8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A8FC611B-71F6-4B4D-BD3A-BFBCCDE96F57}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A93061FE-464A-4E95-8E96-A54CD948B0F7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A95083BE-3D1F-4C7E-ACCC-EC11EA9D498A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{a9844b2d-fca2-45e0-9862-be24e19d06c3}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A9895933-6636-4281-BC58-EE6DE2AF96E3}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\logogo.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A9A7AE50-34D8-4726-B32F-7EDA5FDC6079}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{A9BCD26B-9EFB-4718-A9DB-67A61DB76C77}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{0EA12C16-CDEF-6AC1-236E-CD3FE82F5213}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AA0A58A6-5C1A-4CAA-9BCD-C2486C202073}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AA2D2E20-4CBD-4AB2-B2B6-B356214DA8D0}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AA546010-1611-4616-920B-5D2D11965050}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AA59145F-315D-BC23-AC1F-145DF81A34AA}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AA6B979A-796F-452A-94B3-DF1F17B72031}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AAB6C1A0-F3A4-4DAC-A922-F82E601E73A8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AB1912D5-04C9-46C3-9810-C91D388C9534}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\LOOKOUT.EXE
delsubreg|HKEY_CLASSES_ROOT\CLSID\{ab340860-fd81-4a65-b345-82eb77a66b5e}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AB52A9B4-A995-4FA4-A11F-6178F0E61BBA}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AB692F9B-27FE-4511-8885-ED62BB45197B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{0FA24E3E-422C-4D94-A125-104F32352C90}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AB6C5D1A-EF31-49E6-9ACC-BAD329EA8D38}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AB8105BD-1B1B-40F3-8D3D-65FD7FC68CC5}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AB900155-F1F0-4165-9E73-67BC13BBCE89}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{ABD0935D-B35A-47BD-BA9A-81678DDE74DD}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AC2DDC79-9580-4B83-A213-D6C23C4E7BC5}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AC6F3D84-3433-4FCB-B445-3DE0C97D50EB}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\LUALL.EXE
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AC6FC642-201F-4397-B6E6-29276AD0A60E}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{ACADABAE-1101-0010-8001-00AA006D2EA8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AD11A17C-83C2-4121-89C8-D0660555685C}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AD26AC5F-8421-419C-8692-ED1FE74D0FE8}
delsubreg|HKEY_CLASSES_ROOT\BDHook.URLBDHook.1
delsubreg|HKEY_CLASSES_ROOT\CLSID\{0FA40B34-8B9B-44ED-B85C-60A83F2C5D24}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AD2F1493-F26E-4E37-908D-4A33A31FA708}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AD56A0C8-8EDF-406E-AB5C-94498074CEC9}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AD66F7EB-BC9B-40CF-B5D3-3F535BB8D675}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AD862DC6-37FA-4D56-B7EA-59C2522A5FC4}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\LUCOMSERVER.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AE8813B0-61B3-4F6D-8F9A-7AF223E2C46E}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91974}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91975}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AF05A291-7249-4C15-B212-3E8D8C02438D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AF235511-A3CA-4AF6-BA10-C2D229B8A01B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AF5E43F1-9AB6-45AB-93A0-D87CEFF4966B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{0FAD2E16-C8EF-5AC1-1E6A-AE3FD8EF56B3}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{AF976DCD-754F-4ac2-BE49-951DC7AA57D2}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B01DED18-9E26-4F33-B373-F59758747AFF}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B03A4BE6-5E5A-483E-B9B3-C484D4B20B72}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MagicSet.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B051DBDB-8B9E-4FB1-B04A-67FC0A5DF427}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B058B02A-AC93-4FBA-900B-FA44D9B92805}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B05A92B0-F7B0-4E5B-884E-3D5FB2D4552A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B05CB5FE-1E22-43C7-93E2-4CF04C87B3CC}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B0ADE25F-5283-4EB7-84E6-45C6A02995A2}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B10C1202-2D2A-43C3-A230-9D67F927BE18}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B276D18F-E1AB-4674-A559-B267CF550B0D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{0FE2703F-7C86-42BD-8B03-B43C481AD738}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B3721C07-62B3-411A-9DC7-F5F27E3E21FF}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B3776444-0648-41DD-8EDC-92CCB95D74F4}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MAILMON.EXE
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B397CED2-0688-40DA-B136-90D7E8209CDB}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B3A1AAFC-C934-4DB5-86C6-B8C03FCC1C63}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B41816C9-9511-40C3-BAE7-F8208E9677AF}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B4262617-467C-43DB-9B2D-C32739E5AA14}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B490415F-65F8-B5C5-D8BA-9405FB12054B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B523D3D0-AF5C-4A25-9FBA-5243B231BFAA}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B629FF4F-ACDB-5C90-A098-FACB3456A26B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B69F34DD-F0F9-42DC-9EDD-957187DA688D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{100EB1FD-D03E-47FD-81F3-EE91287F9465}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B6C3510F-2666-496B-A46F-6EEFD6328C2B}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C1A8AF25-1257-101B-8FB0-0020AF039CA8}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\makereport.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B6E23E89-C925-4BF7-92EB-77EFDF8C58A6}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B778645D-B2A0-48E5-8E43-04B02CA3EA9D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B7D21764-31A1-4B15-B975-8AAA398CE07F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B7D59563-AD35-4D2B-B174-7A61A0BC829B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B7F1BFDC-4B6C-4E2F-AF7A-638D2D47802C}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B8898C49-7B3A-4306-A9EF-8E186EDEE5EA}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{b89f72ec-3017-856c-4128-3017fa646e12}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B8F4C7B3-74C8-4380-80B6-B66E5486B904}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B955C012-E3E8-4777-86CB-73CC15890D29}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{1055CA44-51F8-486B-8CBD-DC7AD4213F1E}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{227CDDDC-C646-3BAF-CD8E-903D20A4650A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{B9D0F4D7-C809-4C27-9CB4-63201DFB3D05}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BA16C151-EC27-4917-BA64-D9A1E0B74B75}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BA73DD0D-D9F9-420F-B53F-E19115A6C385}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BA7EDF54-8408-4B21-B351-7B447B344BA4}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BAD4551D-9B24-42cb-9BCD-818CA2DA7B63}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BB136BA5-D1A5-4BD4-AC72-CAA9CB8EF992}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BB4C402F-882A-4526-8C08-51278EA437C1}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BB4E3499-0132-4d3f-849A-2BE1B26D84E1}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BBC92FBA-9F43-4938-8716-62D17E1A1617}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BC0F0A98-380F-4399-989E-737AE006CEBF}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Maxthon.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{10618412-C528-C784-C056-C164D1F7C501}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BC207F7D-3E63-4ACA-99B5-FB5F8428200C}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BC2E065D-C5AB-49A7-80E7-A23E45C5CDF1}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BC8975EB-DD3E-406A-8DF9-218848C3B594}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BCDC783F-C3C3-426D-BB84-4F13C8B573D0}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BCEF561D-FD3C-4FDD-859F-F2AC43DD5101}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BD07AE7E-DB9C-4FFB-BD21-99DCC8434610}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BD0DE545-9C56-4A2C-86E7-03DD0EDA6E48}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BD233082-E412-4667-BE66-5C9FEBB719C8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BD344AF4-67AB-4E19-A630-7435587D320B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcafee.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BD75B192-6840-453B-AE28-2B4B548645B6}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{108DA6C0-CFBF-41D4-9A09-C4D06AE6FFD2}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BDEC641B-8B04-4F94-9294-9F589E02CFFB}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BE12C98F-645D-4566-B524-DC32040B7C8A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BE1A344F-9FF5-4024-949B-52205E6DB2D0}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BE6661FD-2DA8-4E8A-B614-7322D4604DC3}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BEA5B04E-545C-4386-89FD-5BB1CC5426C8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BEC8A03E-2E55-445A-97F3-03905BEAB07E}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BEE17DA4-AF94-4D82-8A8D-CF61D73AF94D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BEF08ECF-FE0A-4209-9F7D-D89FAECE046D}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcagent.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BF0E569A-6E3D-4744-9B7D-D9E9946BFB4B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BF576861-D001-4651-9C77-BCA1F6615982}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{109BE732-8F8C-49D4-A3F4-FEDCAC7F0A25}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{BF5AEF56-7C4B-4816-8541-C371182B531C}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C00B4190-B46C-4A97-9E44-4532D12BE1B4}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C01A46D2-5397-4087-90DD-F44F207F7642}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C08DF07A-3E49-4E25-9AB0-D3882835F153}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{c1005aa1-b41b-4057-94ec-cfa8f081d18c}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C10D41C6-4D17-4808-87CE-40612862A1BB}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C1626E66-C26B-C628-E1DF-CDACCFA26EE1}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcconsol.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C1A8AF25-1257-101B-8FB0-0020AF039CA8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C1B34818-3883-4A0A-9665-189A8A39EAB0}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C20C5A13-4DD7-40D9-90B4-700BAB0BBBE9}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{1166350E-BE0A-4242-A816-AF0A9752D2AF}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C225280D-48C9-4CFA-B167-BBD91A534E29}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C2388C06-CA6F-4D08-8428-E32189A99A70}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C250CF20-5F89-4310-9854-4BC261FB14FB}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C277B942-1F68-486b-8F95-6E486A13F148}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C27CCE38-8596-11D1-B16A-00C0F0283688}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C286ECE5-AC84-4B89-A219-38B876C739F2}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcdash.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C28925ED-EBF5-4FEE-B829-B518B4CB2E10}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C34865A9-79AE-4D44-A0AB-E623F3705442}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C34AAB30-15BF-465C-8477-E47850780BFB}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C362D1C3-313C-41C8-A0C7-45458CD8D9A9}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{11B10F7F-FB23-466D-BDC3-9591CF02EC17}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C3919446-AF54-44AE-9CFB-CEF0AB35A3C1}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C3E75763-F9C7-4868-8502-81F11B41D943}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C3F79FB7-475D-4A84-9E00-8F3570B7C26B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C4560D12-CE25-4A2E-A5D4-B5070FCBE282}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C490415F-65F8-B5C5-D8BA-9405FB12054C}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcdetect.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C4D2CCF4-F674-48C7-9F89-F150DF63CCAE}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C4E6B319-8C65-4016-8689-39ED0537D0CC}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C517FCA8-7040-472F-9DE5-90B990387AD7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C52678A5-AC8A-4327-BCB3-6DA940945747}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C53C1999-1B56-41BD-8F76-520D618F112C}
delsubreg|HKEY_CLASSES_ROOT\BDPlugins.Interceptor
delsubreg|HKEY_CLASSES_ROOT\CLSID\{11F09AFD-75AD-4E51-AB43-E09E9351CE16}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C5470A7F-BDF2-4D97-847B-6AA97ADCF91A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C5CB6C70-7185-4466-AB45-B1C34E7A37CA}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C5F43BEF-CE2F-46D8-AFE6-A647BACD1F09}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcmscsvc.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C5FC2AAE-C21F-4CDF-8E3C-3FE421118A1B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C60BC4DF-4CAB-4F66-ABED-D3FCCE7910AD}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C68250B5-364B-43B4-B62D-E95B9E52CD44}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C704DA21-F1A7-46B8-9BDC-50E506198AE3}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C713CB8A-F650-4A42-8342-12FFCDAD7020}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C722AD57-35DA-4460-8353-328372F32AB2}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C73C94FF-8E84-45BB-A81E-D47833D9B302}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{11FDB6D4-166A-47BF-A0F8-A09DABA75FC1}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C74B750A-3C70-4AB5-8749-2B864A9116DE}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C74EB933-C198-4F49-A63B-17DCCD4E36BB}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\McNASvc.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C7AF807A-C1C5-436C-AB05-4E45B837007D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C85CB78B-8D31-4C27-8533-149683423BF7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C86488AF-13D5-4FEF-9DDF-9FB88698CFC1}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C89E2A42-268E-4BEC-8EAB-EAC55D58EAF6}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C8EB51BC-82D8-4018-8678-5A0580DBA04A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C9EACC3E-25D3-41D9-8575-410FD86DD685}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{C9EC9A56-C939-4B5A-A12E-FCFF02579770}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{c9f1240b-7e43-1a8b-96a8-c32114593fd0}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{122B901E-493F-4AD9-BC69-7DE8C3E52FCC}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{CA92B524-BC8A-4610-BD2C-6BD3E28155D0}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{FCC4B6C0-5959-4664-B1C6-2B86F5136B63}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C27CCE38-8596-11D1-B16A-00C0F0283688}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Mcods.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{CAB2E13E-848E-4DA0-A97D-53245C25449A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{CABA599D-5089-4865-9420-E41FA3C1F55F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{CADB02D0-5722-4BE6-9CB6-5CE88E31E165}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{CB661471-055A-4C5B-9ED0-497B9908FEF5}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{CB6E79AE-29CC-4082-A190-525D3C4A5233}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{CBD9FCD6-0F8C-4596-9B3F-2F6974FFE672}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{CBF4E071-9785-4507-A09C-652C2862E3B9}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{CBF8A83B-543B-485C-8D43-4B2529A326F1}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{CC0EC2C9-432D-4DCC-91E7-A7C5CEA748D8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{12316E69-4CE5-4CD7-A174-C0BD57529D5A}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\McProxy.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{CC48391C-3696-49B9-9293-9F69C28AB3C7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{CC80F0B4-04D7-44D0-8DB9-9109B5B72141}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{CCACAB8C-9218-4E37-ACF6-FF84BEBEF60A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{CCCA2FB9-2D5D-4481-8BFE-1CDDC458A3F4}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{CD1779C2-CFD3-46FD-8139-A454565E447D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{cd36797a-70f3-4acd-8825-623d3b896881}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{CD478099-014D-4B3A-A4BB-B518F1019BC7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{CD8D6EBD-22BB-4ACF-8AF2-737305B879A2}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{CD95107F-52A5-42A4-9914-18949993E798}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{CDBFB47B-58A8-4111-BF95-06178DCE326D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{22A11E32-1FCB-4F54-A511-34253CB09A1A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{129067F2-E20A-4D14-8F30-FC3968B9C028}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{CE38B9E6-AF0C-4B93-AFAB-A20C2311FFD0}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{CE6C2B2F-B590-4EA1-9A44-5100596D7EAF}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{CE7C3CF0-25FC-11D1-ABED-784B7D6BE0B3}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{CEBB8F8A-308B-43E9-9789-B6FD6BE1BD97}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{CF2C613A-A0D9-4E5C-B1BB-6B03B269B054}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{CF526160-CAC2-4560-AD0C-20C8D88CA4FA}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D047C24E-876B-43BC-8373-5E7BE9BA9C35}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D0B5AB50-711B-495A-B804-C86D9AE3D9A6}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D0B7E0F1-4A38-4ACC-B3ED-5C552BDBE512}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\McSACore.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D157330A-9EF3-49F8-9A67-4141AC41ADD4}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{12B02216-AC3F-42A7-8313-449771237061}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D1CC9DC6-F0BC-40fc-9552-E497B05E05B8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D23B0004-30E2-4BDB-B53A-7E9041308C36}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D251FE2F-DD5C-4828-85F7-9E7EABB6DD6F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D2DF094F-19E5-4096-9E6E-CDE173909227}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D3112B69-A745-4805-874E-ABD480EA1299}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D3626E66-B13B-C628-ACDF-BDABCFA265E1}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D36A1DF7-6582-4160-B925-59A34E39FE30}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D3CD6983-551F-4CD8-B48F-FABEB7DE8F3D}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\McShield.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D468BE53-03E2-4294-8967-CB67C9990F1B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D495FADF-2A7C-4A62-A50E-D6FD9DF6FD9D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{12C00240-1B5A-4CC9-9DB8-F97EFD4EF36B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D4FEDE82-C500-4AA4-BB99-A4DAE5A65A46}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D5141C2D-A732-4627-AC14-D5B54121A941}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D59D2B84-7851-4B10-BA14-4125D8EB86BF}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D6129F8A-6F6E-41D7-BBC9-AC7426759CED}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D64374E8-8B1D-49AB-9284-5072687B6BD3}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D7019B3B-ABF8-4D55-AB50-95A110373D54}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D72860C5-2C7E-4C8C-B1C9-F6803BEB09E4}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcsysmon.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D7515C61-A66C-4319-A0E0-D416CB8059E3}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D7C79813-9233-4AE0-832C-99B2E8019673}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D7FFD784-5276-42D1-887B-00267870A4C7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{133AEAC9-9C88-4905-864C-38BBA312D9B0}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D806ABA9-CFCF-4100-B914-B8A067EDB967}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D82C0336-583E-468B-B46A-0897FAB9D5A2}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D889BF1A-EDD5-4C1D-A3B7-434F4918E7C9}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D8CC4845-441C-44F8-9053-28F2EF67655B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D90E7FF1-3BA4-469D-9345-86888D174D79}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D91BC61E-7D78-4A2A-A336-7B97E8E52F0B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mctskshd.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D9735121-5627-4697-A2B0-DAB75D6595FF}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D9AD332C-F0BD-FB6D-8A8F-393E0F10C0CE}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D9C002DD-EA51-43A2-9009-54EAAAF031A4}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D9D0D8CF-0C6F-403B-8D57-DFB685C55B6A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{136F4843-F6B1-459F-83B5-7B0F982FDDA5}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{D9EA901D-EE31-419C-8DD0-7E4B804C8CF3}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{DA112397-5376-4E52-A333-A85284658DEA}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{DA191DE0-AA86-4ED0-4B87-293D48B2AE99}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{DA1DE019-A6A8-ED40-4B87-248B2A93DE99}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{DA63E650-537C-4042-87BB-9D19D844680B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsescn.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{DAA9A840-0BB3-4706-9160-C5BF58D79C31}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{DAF11377-E995-4BDE-9561-FE28E14734B9}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{DB1D3240-C22E-434D-9D34-D1FC6C68D93F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{DC7596CB-D6CC-DCA3-DE52-DEEA63F6C61D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{DCBC4DF7-09A8-42D0-BCF4-299F72F40EAD}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{13DED518-ACC3-4FA7-AF26-4E67A43B016E}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{DD1F3EAC-D200-4D70-B846-7A272C0A7867}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{DD247050-3EA7-43D1-88DB-8C79E8E3F04F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{DD3129DE-81B7-48D7-AC9F-819A3FBBF2E8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{DD696DC3-7803-4750-8EFC-C10F6D900D2A}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcvsshld.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{DD8B4357-BF3A-469A-BFBF-16EB6A591799}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{DDFDCED2-075A-4910-986E-B2BDA2B0E916}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{DE02F764-C51A-4788-9597-D78ECC2AC08F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{DE43F05E-1CE8-4B5D-A8C3-982437642A1C}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{DE64EA3B-53E5-461D-96B1-38A8BBD36ED2}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{DF12F8AB-9A00-469C-B9D4-425C1BE3E1E6}
delsubreg|HKEY_CLASSES_ROOT\BDPlugins.Interceptor.1
delsubreg|HKEY_CLASSES_ROOT\CLSID\{13F7717D-A7AD-4DBA-92E2-083A4F1B1B1A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{DFB3DAC5-B0B5-4B05-BFCF-FB42737778FA}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{dfcdbba7-9ed7-4500-aade-c42ff96e3f9c}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mghtml.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{DFEAF1AB-1B26-4ACF-A97A-BEF452ACBB4F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{DFEC5CB7-E2AA-4B0A-BEB3-D140E59ED53A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E035AC3D-B5A8-43A7-9944-8BB333A90D2A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E03C23BD-35B7-49C2-BBCA-6D8CEC2507E3}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E0528BDA-C850-4F23-93E4-7F907C1EF30E}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E0D39066-96D7-4891-8527-488ADAFCD60F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E0F3526A-4165-4589-80CD-50B6FBAC3BDA}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E11FB24A-F766-4D0F-ADF5-237958FFA262}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{14A0A05F-E7C4-449E-8A35-088F68B56CA4}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E1384213-0948-4A60-A9E3-875B191CC2E7}
delsubreg|HKEY_LOCAL_MACHINE\Software\CLASSES\CLSID\{CA92B524-BC8A-4610-BD2C-6BD3E28155D0}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\microsoft.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E14DEE75-D635-47E6-9963-D907AA030ED9}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E16EA4C8-040B-4A12-A0F5-783963AD665D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E3019869-0038-49F8-B8CF-4170728210F1}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E30AFD4A-110D-4FD6-A698-EE9D2BD98C7A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E3367679-4775-4244-A62E-4CFE58FC850B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E3531A16-FFEA-416F-82DF-32FEDE02EABF}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E3616E66-C13B-2628-2CDF-EDABCFA235E1}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E3789A02-334D-43C9-AA31-6152094BA26B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E44343AD-3605-4282-AC8F-2E41C2F5F398}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{14C0A9F9-5512-43BA-87FA-ED4860306453}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmqczj.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E45C0FF6-B170-43B2-B897-6D02C43A2E18}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{e45eea58-eb26-48a1-abd2-661f5556dc33}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E46276C8-FA5E-489E-A78E-5182B652E5C7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E4814792-EFA3-4C20-93D0-8B130A59F9A8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E4CC0B6B-93B1-4766-AE5E-3FE89FD6DD6F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E53443AE-A4E2-4218-A938-3EB1032FCE20}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E58B05EE-6CA5-42E1-A0CE-82169DDEE42C}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E59C8BDA-489C-47EC-8967-A33C6A730B10}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E75B29ED-F3D2-46D8-9EF3-B088068CB58C}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E762D574-B60E-4160-B417-4788469ECB3E}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmsk.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{14F7F80A-0FE7-4A24-83CC-639D42BE410C}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E7ABF01D-9B5C-40C1-85BB-3EAEDEAB46A5}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E85C18E7-C293-4424-9DD0-B31D8DB27013}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E8908346-8B0A-4EE3-8AEE-84502544688F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E8A3B193-77E3-4FB3-986D-F4FA4828BAFC}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E912513C-22DA-4200-BB9D-4D36BB294B22}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E918A05E-0FC7-4077-8ED4-ED1D6CEC0E8A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E952B8F8-D91A-4EDD-851C-EE1A0F944469}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E996F10E-FCAF-41CC-94C8-B8BF7D6F80AC}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{E9C84B05-22D2-4820-99B0-4AAAA7CD6A5D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{22D75360-199D-4F79-880D-82E766675F06}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{EA25F4E7-8B67-452A-B9DD-B38C526250D3}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{151EAB12-CDA2-4CE4-88E2-000ECD557A40}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{EA3AB1EA-AF0A-42A9-BB49-B0386462A036}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{EA44A26D-DDC8-46C0-AFE1-A529FE014E3F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{EA4D8F95-8F2E-4658-A234-E8F4C9AC21C5}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{EA5D4B0E-B8CE-4761-8C7E-5D26369F0EC6}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{EA5FB64B-1CA5-4939-A93A-9E76234B0A67}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{EB0691E5-E6F5-4FAC-BAEC-FE6C960FFC56}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{EB5D4E06-B487-4150-A19B-08B6F50F7BA5}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{EB6650FB-DAF5-4EEE-BBF7-19006A5B99A3}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mon.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{EB6736EA-D66C-49A8-81A8-FBF9FECB62B1}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{EB71E0B3-E97D-4D30-8733-E28266467617}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{15882A2F-A06D-486E-8958-E84C86CBF273}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{EB965722-E1B1-4098-9DE5-D9CE34110DCE}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{EBD2EAD0-88A7-477C-9664-BC42F1CDC312}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{EBE50EA1-89C8-463A-998A-69A05ECD2D26}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{EC1E8459-B93E-4D9E-9D58-A2263C95E9F7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{ECC8E4BF-44DE-4B8D-A591-80845E6A7863}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{ECD35E39-F399-40DF-8B88-005C7A4B0ABF}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\moniker.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{EDC8293B-C0AE-4247-9A50-7D75FEEB1AAB}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{EDFF29C1-5A70-4460-AC1D-16DCB4B672F0}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{EE1CCAC2-F78B-4CB6-80F8-58DB08F87F8E}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{16368135-64FA-BC34-DA32-DCF4FD431C91}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{EE1E1B0D-3689-402A-82DC-9689A71DBE46}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{EE4CEE03-3174-43FC-99D6-A435EF5A9D64}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{EE9EBB5C-5B4C-48d3-8BDD-0EDBF4F720B4}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{EF20A659-32BA-4A38-BECD-4CC2F3089C0A}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{EF4A79B4-070E-4645-B732-8A4A26E18A11}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{F01CD512-AE66-45BD-B182-EED2D68E9FA2}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MOOLIVE.EXE
delsubreg|HKEY_CLASSES_ROOT\CLSID\{F03905AC-469B-4617-A984-44F245F29981}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{F0930A2F-D971-4828-8209-B7DFD266ED44}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{F0C9FBC2-6FA2-479d-B65D-F9D65C613ECC}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{F1455861-8C40-4095-ABD8-7BEAE5ADF92E}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{1655D6CC-5FAD-4A03-9EE2-49D91A386E6D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{f14ef0e2-c39e-4589-93e8-52e89cb5ddb2}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{F171A450-7AF5-43E1-AFED-EDC826A1B0F5}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{F181F067-7046-4DCB-993F-200990736305}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{F2319AD4-D519-45AC-86A7-02FE9B851F37}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{F49C475D-5651-4A94-B289-9953F9248EF9}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MpfSrv.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{F4AEB826-71B5-4496-B79E-146897B8064F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{F51EE66E-8F35-41EB-AC93-9A0B973F7C04}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{F543B043-E9F5-4438-B89A-94E2BDF40B7D}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{F65BDEC7-4BF3-4512-840F-68B166B6D7AC}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{F6A454AE-156A-415E-9F89-3795677A8A91}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{16886058-6A31-4D53-B4AC-4CC7D2248D69}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{F6ECA821-B4FE-41BF-85FA-7BA54ED88176}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{F718AEF5-84CF-46AC-951D-3915D838897E}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{F71A67D5-5BBB-47A3-9534-4150FC739257}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{F7776F24-A299-492D-8E5D-409140455376}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MPFTRAY.EXE
delsubreg|HKEY_CLASSES_ROOT\CLSID\{F7B7E354-C12F-4C4A-AAAF-A21C61ED8561}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{F8C6B7B5-DAE0-4B78-BF2A-101C9A9CCA27}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{F8E45003-3AAB-4F7C-AF06-725A2559E55B}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{F93CB274-12A2-489E-9DB6-BAAF492448D0}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{fa19bd7e-50bc-4203-80ac-c4edc81ca9a3}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{FA281E7B-905D-4565-964B-1F3A61F39873}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{16AF66EB-93C8-49F9-BB09-B4F87CEDCE46}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{FA50E57C-6924-4C03-B325-9A0172C9E8BA}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{FA9B58AA-6759-4C02-B37F-572FC2F1A231}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{FB628720-6493-4AD5-AD46-AEF90A005475}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MPMon.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{FB62C72B-F6A0-44DE-8332-4C18AEB26CF7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{FB7247A4-5F09-472F-961B-68F7645EBE9E}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{FBA9B4CB-D3B1-44C8-8555-AF65C7929222}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{FBF3B337-FEB6-403B-BBE2-2B67CB6563E3}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{FC769E66-3862-4F80-A24D-E2F1EA7260D8}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{FC8F4603-4AB2-4A0D-B17F-886CC8AAAFD2}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{FCA4D3BE-C6C7-4F4D-9CBD-CB2666647ACA}
delsubreg|HKEY_LOCAL_MACHINE\Software\CLASSES\TypeLib\{CE7C3CE2-4B15-11D1-ABED-709549C10000}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MPSVC.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MPSVC1.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MPSVC2.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ms.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{23784612-5FEC-4E07-97FD-D5B5954A4236}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msksrver.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\N32ACAN.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\N32SCANW.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\naPrdMgr.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Navapsvc.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\kingsoft
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Navapw32.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navigator.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NAVLU32.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NAVNT.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navrunr.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{23DA65D2-C696-4EE4-BEE8-B4841DEC3E30}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NAVSCHED.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NAVSetup.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NAVSTUB.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NAVW.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{265E4762-90CB-4E07-0606-070406010206}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\navw32.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NAVWNT.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nisserv.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NISUM.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\niu.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NMain.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{0086DD39-EB8E-4504-A085-AC8A433E34D0}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{23E6662B-FA39-4042-A240-990A5E4827AB}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nmapapp.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{28ABC5C0-4FCB-11CF-AAX5-81CX1C635612}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32krn.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nod32kui.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NORMIST.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\norton.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NPFMntor.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NUPGRADE.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NVC95.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Nvcc.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{24144CB8-10ED-4BFC-843F-68A9F3369947}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\oasclnt.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{A8844B0B-CA06-CB5E-D0E5-7B08749934CC}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OCSCtl.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\office.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OllyDBG.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OllyICE.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\opera.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OUTPOST.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PADMIN.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pagefile.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pagefile.pif
delsubreg|HKEY_CLASSES_ROOT\CLSID\{244AE512-A46A-4BEF-AAB7-1D9FFD31C2F5}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{17276F09-EF0A-430B-9C3E-72CDD59449E3}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PAVCL.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PAVSCHED.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pavsrv51.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PAVW.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcc.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCCClient.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pccguide.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pcciomon.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pccmain.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCCWIN98.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{EF066BED-BD94-4D3B-9BF7-31E4FB514549}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{244AE512-A46A-4BEF-AAB7-1D9FFD3AC1F5}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCFWALLICON.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PERSFW.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFW.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFWLiveUpdate.ex
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PFWLiveUpdate.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pop3trap.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PpPpWallRun.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\preupd.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ProcessSafe.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{F44820FA-D641-0741-12F8-59193E89AE4D}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexp.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{244AE512-A46A-4BEF-AAB7-1D9FFD3AC2F4}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\program.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\prot.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\psctrls.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\psimreal.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\psimsvc.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pskdr.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\pview95.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QHSET.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{FD301436-732E-4F47-8DA0-FBD8720C1E0B}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{F5C1B2F7-82CF-4F7A-8039-A0DC62D31B49}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQDoctor.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQDoctorMain.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{244AE512-A46A-4BEF-AAB7-1D9FFD3AC2F5}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQKav.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\QQSC.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qutmserv.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ras
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ras.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rav.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RAV7.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\Intel Physical Routine 1.2A
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RAV7WIN.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavCopy.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMon.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{244AE512-A46A-4BEF-AAB7-1D9FFD3AC611}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavMonD.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavStore.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavStub.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ravt08.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RavTask.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RAVtimer.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database\Distribution Units\{BC207F7D-3E63-4ACA-99B5-FB5F8428200C}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ravtool.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RawCopy.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\reg.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RegClean.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{244AE512-A46A-4BEF-AAB7-1D9FFD3AC6F1}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.Exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit32.Exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RegEx.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regmon.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RegTool.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database\Distribution Units\{CA92B524-BC8A-4610-BD2C-6BD3E28155D0}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rescue32.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rfw.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwcfg.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RfwMain.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwolusr.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{244AE512-A46A-4BEF-AAB7-2D9FFD3AC2F5}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwProxy.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwproxy.exeFYFireWall.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwsrv.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rfwstub.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions\!CNS
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rising.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rn.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RsAgent.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rsaupd.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rsmain.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rsnetsvr.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{245C05BC-9441-46AD-8897-1680DAF88898}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rssafe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rssafety.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RSTray.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rtvscan.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runiep
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\runiep.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safebank.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeboxTray
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeboxTray.
delsubreg|HKEY_CLASSES_ROOT\CLSID\{0088C75C-6361-4dfb-B2CF-576CACFA3C55}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{24EDEA54-9E75-4559-8818-F124CADF6DF8}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safeboxTray.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_AVP32.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\safelive.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SAFEWEB.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scam32.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scan32.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SCAN95.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scanfrm.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SCANPM.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ScanU3.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{24F05563-C144-46E4-ADF3-516F4E0AA91D}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_AVPCC.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sched.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scon.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SCRSCAN.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SDGames.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\seccenter.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\secnotifier.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\secu.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SelfUpdate.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SERV95.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\servet.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{1798BEA6-E891-46B7-A1F8-C15780D0A023}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{24F8B41C-5AE1-4CC3-833A-17619A05D0BA}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sethc.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SetupLD.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sfctlcom.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sffnup.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shcfg32.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shstat.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ShuiNiu.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sirc32.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smartassistant.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_AVPM.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SmartUp.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{25B8D58C-B0CB-46b0-BA64-05B3804E4E86}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SMC.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\smtpsvc.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sndsrvc.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sos.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spbbcsvc.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SPHINX.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spy.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SREng.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{FD428244-8EE5-4155-95DF-B07E8C304A39}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\~.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SREngPS.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\srgui.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{25FD6584-698F-BCD2-602C-698745210352}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sriecli.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\start.bat
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SuperKiller.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svch0st.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SWEEP95.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcsvc.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symproxysvc.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\~OllyDBG.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\syscheck.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Syscheck2.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SysSafe.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{267709FD-A691-43B0-BF38-0DF6887A9B44}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Systom.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Tbmon.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TBSCAN.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TCA.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TDS2-98.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\~OllyICE.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TDS2-NT.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\theworld.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\THGUARD.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Thunder5.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{26F0E2C9-F853-42D4-866E-86AA4C8EF58F}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TMBMSRV.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Tmntsrv.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TMOAgent.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tmp6.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tmproxy.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360deepscan.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tmupdito.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TNT.Exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ToolsUp.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tqat.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojanDetector.e
delsubreg|HKEY_CLASSES_ROOT\CLSID\{26F58495-C4E4-4E64-97E2-FBD9A6080F93}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojanDetector.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojanHunter.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Trojanwall.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojDie.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360down.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TrojDie.kxp
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TSC.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TTraveler.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TxoMoU.Exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UFO.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ufseagnt.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{27AC9E17-125D-4EE5-9617-502A90E7F709}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ufupdui.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UIHost.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UIHost.kxp
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360hotfix.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\uiStub.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UlibCfg.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxAgent.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxAttachment.ex
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxAttachment.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxCfg.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxFwHlp.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{27E1C1B0-7117-4582-8565-682E569810D2}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UmxPol.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UpdaterUI.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360Loader.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\upiea.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\UpLive.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\USBCleaner.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\userinit.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vavrunr.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Vba32arkit.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vba32ldr.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vcr32.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{009BBA18-D7A2-456A-AE04-EB9ABF822FE4}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{27E96DE0-8211-42CF-9A1E-FA6246A95B77}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rp.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vcrmon.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VET95.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VETTRAY.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vir.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VPC32.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vptray.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VSCAN40.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VSECOMR.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VSHWIN32.EXE
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VSSCAN40
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360rpt.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{286C2802-481C-4324-8D20-8E1738548D39}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsserv.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vsstat.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Vstskmgr.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vstskmgr.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\webproxy.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WEBSCAN.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\webscanx.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\webtrap.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WFINDV32.EXE
delsubreg|HKEY_CLASSES_ROOT\CLSID\{17a0438f-579d-46e7-aed0-297316da8fdf}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WinDbg.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{2876D76C-CAAA-4313-AF97-8D1D9A2A1087}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\windows蚥趙湮呇.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wink.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wmain.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WoptiClean.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WowUSBManager.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WSCStub.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wsctool.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Wsyscheck.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{FDE7B169-1290-4543-AF4E-0583CFE8367E}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360Safe.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xcommsvr.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\XDelBox.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{2882C70A-AD5B-45BC-A8EC-D17AA8FE54FD}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xnlscn.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\XP.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\XXX.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Zanda.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapro.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zhudongfangyu.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360Safe.xe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zjb.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Zlh.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ZONEALARM.EXE
delsubreg|HKEY_CLASSES_ROOT\CLSID\{28907901-1416-3389-9981-372178569982}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zoneband.dll
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zxsweep.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\修复工具.
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\党葩馱撿
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\党葩馱撿.
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\党葩馱撿.exe
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safebox.
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\党葩馱撿.exe>碧w?
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\党葩馱撿.exeF碧wJ
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c00C05F0
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c00E6667
delsubreg|HKEY_CLASSES_ROOT\CLSID\{2895B086-90F7-459C-BB2E-E3AEB77A1BD6}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\axwcgkvc
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbXPhIAR
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptHigx
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safebox.e
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptmsh
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ddcbAPfG
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\efcDSMEw
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\f8bd0107654
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\fsmgmt
delsubreg|HKEY_CLASSES_ROOT\CLSID\{289C5E9E-D431-436A-895B-74F321F3EF11}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\geBuRIAS
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkkJdBuR
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mlJCSjkk
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mlJDttqQ
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360safebox.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\opnmmkj
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\plnjfw
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnno
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\qoMdDwTj
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\querdgne
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sfcfdmsc
delsubreg|HKEY_CLASSES_ROOT\CLSID\{289F69CA-F9BC-4186-818F-3F9F3B6F3B50}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqQiGwV
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssttr
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tscerf
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360sd.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvUKdBq
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\usbmon
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\uwvzyz
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\vtUmlLDW
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wexmat
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winctrl32
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winexplorer
delsubreg|HKEY_CLASSES_ROOT\CLSID\{28EB3777-3E23-4E72-8449-A992D09D24C3}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winhab32
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Winhmg32
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360se.
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winhoq32
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Winlnx32
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WinNt32
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Winnxm32
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Winudr32
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Winxxs32
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xpohgtls
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\yayXppOF
delsubreg|HKEY_CLASSES_ROOT\CLSID\{291FABA8-CB00-488C-AC9E-B457FFC4A117}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360se.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00000000-12C9-4305-82F9-43058F20E8D2}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0005A87D-D626-4B3A-84F9-1D9571695F55}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0088C75C-6361-4dfb-B2CF-576CACFA3C55}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44cf-8957-5838F569A31D}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02EFB688-A21E-42d1-A830-2D67143FF0C3}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{030A0F33-5B99-482E-83F5-2EEB8457878B}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{037C7B8A-151A-49E6-BAED-CC05FCB50328}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{038AEFD0-22F5-407F-9C49-8CC52462356D}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{03968992-38D3-4053-BA15-F128078BF260}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360SoftMgrSvc.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{2960356A-458E-DE24-BD50-268F589A56A2}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{05FADA96-DDAF-4CCC-AC9C-41D3551945D5}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06647158-359E-4D10-A8DE-E6145DA90BE9}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{083A5F21-BCB9-4B21-A121-2584BEEFBFEF}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{085C1F40-1C33-4296-A3B3-CC47540B9A12}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{08CBFE20-8DC8-4195-B8E2-DD66F860469D}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{09EB15FA-17D8-4D60-8598-3F549A848DF2}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{09FE7311-3589-4EE1-A7A9-15B5312F0D04}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0B014B81-4E12-46F9-806F-55867AF8FD3C}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360speedld.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FE2703F-7C86-42BD-8B03-B43C481AD738}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{296AB1B8-FB22-4D17-8834-064E2BA0A6F0}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{100EB1FD-D03E-47FD-81F3-EE91287F9465}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10618412-C528-C784-C056-C164D1F7C501}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{109BE732-8F8C-49D4-A3F4-FEDCAC7F0A25}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1166350E-BE0A-4242-A816-AF0A9752D2AF}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11F09AFD-75AD-4E51-AB43-E09E9351CE16}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{14C0A9F9-5512-43BA-87FA-ED4860306453}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1655D6CC-5FAD-4A03-9EE2-49D91A386E6D}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{16FF142F-BEBD-47CE-A3A6-D52A1A2ECB54}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{FE8B267E-D504-4FA8-AC3C-3214C27C5A5F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1798BEA6-E891-46B7-A1F8-C15780D0A023}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{17a0438f-579d-46e7-aed0-297316da8fdf}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{2A30458A-4460-426C-8D2E-189F8A42C708}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18093456-9012-4568-9076-908765467181}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18EDD7A0-87EF-45B7-85CF-6A7E1341E2BB}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1A698452-C5D8-C584-C256-C264C987C5A1}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1B0E7716-898E-48cc-9690-4E338E8DE1D3}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1DBD6574-D6D0-4782-94C3-69619E719765}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1F2E3A6B-94A7-4355-B58D-74DF486E6C97}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{202AEF39-2BFA-4A5F-B526-390FDE0BC675}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.e
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{20618412-C528-C784-C056-C164D1F7C502}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{20876DE5-9AB5-4050-B7F1-99E4DC5BA989}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{20909876-4567-3908-4056-909834565102}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{2A698452-C5D8-C584-C256-C264C987C5A2}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{21BE5FDF-D4CB-4850-AD99-21E68B50BF3F}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{244AE512-A46A-4BEF-AAB7-1D9FFD31C2F5}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{244AE512-A46A-4BEF-AAB7-1D9FFD3AC1F5}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{244AE512-A46A-4BEF-AAB7-1D9FFD3AC2F4}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{244AE512-A46A-4BEF-AAB7-1D9FFD3AC2F5}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{244AE512-A46A-4BEF-AAB7-1D9FFD3AC611}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360tray.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{244AE512-A46A-4BEF-AAB7-1D9FFD3AC6F1}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{244AE512-A46A-4BEF-AAB7-2D9FFD3AC2F5}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{259F616C-A300-44F5-B04A-ED001A26C85C}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25B8D58C-B0CB-46b0-BA64-05B3804E4E86}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{2B394226-862F-4aa4-AA53-988E24F50841}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25FD6584-698F-BCD2-602C-698745210352}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{26F0E2C9-F853-42D4-866E-86AA4C8EF58F}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27E1C1B0-7117-4582-8565-682E569810D2}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27E96DE0-8211-42CF-9A1E-FA6246A95B77}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{28907901-1416-3389-9981-372178569982}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\360upp.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{291FABA8-CB00-488C-AC9E-B457FFC4A117}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{296AB1B8-FB22-4D17-8834-064E2BA0A6F0}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{296AB8C6-FB22-4D17-8834-064E2BA0A6F0}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A698452-C5D8-C584-C256-C264C987C5A2}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2B394226-862F-4aa4-AA53-988E24F50841}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{2B660F50-0FD6-4D96-9ABA-48B731C7ABAB}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2B69874A-C58C-458D-69F0-698F874E41B2}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2CB77746-8ECC-40ca-8217-10CA8BE5EFC8}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2CEFF6F0-3DE9-4B2B-B2B4-1B1A6F69A795}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2D11BCB9-F67D-4C25-91BD-9B78DE29E8A3}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\a2service.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3152ACEA-61D6-4DDA-A11E-55E69C933906}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{319675CC-4129-497f-8C7F-E2F48251019E}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{32596546-2036-9451-6058-658402589723}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{33200C76-F883-4C5C-B1EB-F3C070DB12C6}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34ecc7cb-0587-4420-8cca-fc441eaff885}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35671234-7890-ABCD-CDEF-567801237653}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{2B69874A-C58C-458D-69F0-698F874E41B2}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35B8D58C-B0CB-46b0-BA64-05B3804E4E86}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35C98014-DBB7-40E9-908E-0A970E82A549}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{361A1C46-F062-47FF-8E98-53F50E214691}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ACKWIN32.EXE
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{36EAFED6-FE52-42E5-8FEC-703424BAA9CF}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{37A924AF-1A5F-CF21-AB1D-1D5CF82A8A73}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{37AC9076-C898-B098-D098-A18319080973}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{38093456-9012-4568-9076-908765467183}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{385AB8C6-FB22-4D17-8834-064E2BA0A6F0}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3876F52A-C07E-A452-285A-C6EA15724E68}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39109876-7619-9101-7012-901938475193}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{2B94FD3C-E6C7-4E33-8966-D216D6B05ED2}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3A908760-8000-4000-A000-9000322145A3}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3AA0903B-1E13-4865-B114-15792D413C41}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adam.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3B7AAEB1-9F3D-4491-9C06-C7165CA8D058}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3C954872-1230-6541-9548-6541025884C3}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3D698451-2015-6358-9871-2015987452D3}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3e301889-882f-4abb-a2d8-4e75db3f3020}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3E7C9687-C865-4797-A540-0B3D4FD0FAB6}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3EA18648-FAF6-490D-9C92-8FD729028A58}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3f4dffdc-1bd0-4368-87b4-c97ae21fde40}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{2BDC2363-6468-4A18-A082-1782BE1B4B0B}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{42C50607-D944-41A9-9B67-720AFBE8C22C}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adffg7h785v.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4306D2B4-1D20-4E23-AE74-3CE99776DBC6}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{43512378-9874-5641-1025-985420368734}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4486FE99-9018-4E49-A6E7-28CBCAC846FE}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4629FF4F-ACDB-5C90-A098-FACB3456A264}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{47544506-3C22-BBB6-9E9F-489B4B645F24}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{478932A2-862F-4A34-A264-54A6EB998FDE}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{47994C89-1857-4D33-B196-263ED6FA4CFF}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{487C9905-26A8-42C8-8033-C58AD3D2AEC3}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{489873CE-F3E1-44A3-8E89-04BE26BE4446}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{2C268BA0-2884-436B-9ABE-AD95BDDC6376}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adffgh785v.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{49E0E0F0-5C30-11D4-945D-000000007667}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4A698102-5904-AFD0-20DF-CD1A65829CA4}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4B00FA79-7C1A-41F1-AF62-C7FF0D3B96A7}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4B00FA80-7C1A-41F1-AF62-C7FF0D3B96A7}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4B00FA89-7C1A-41F1-AF62-C7FF0D3B96A7}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4C648541-1025-9650-9057-6541258720C4}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4CAFE568-1C3A-4edd-856D-2B14249777CF}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E3FBFA4-F1CC-4B66-B333-B9F0FF4B4748}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4FA955E8-C73C-4D72-BDCC-EA12227B45D9}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{500BCA15-57A7-4eaf-8143-8C619470B13D}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AgentSvr.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{00B0B983-9D74-49BF-9C14-46788179446F}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{2C56D8DB-5D4B-4EA2-8B68-18F5C513E50C}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50940F85-F015-14F1-A05F-F69858AC6D05}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{512EABF9-6550-4B48-B46F-C6CE65F9D2C6}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{51B15F5A-E98B-4658-B9CB-9307B74773A7}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{52023698-6984-8541-9654-698745012525}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{528DF602-9541-A985-210A-984A698C6F25}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5419706F-9AD1-49BB-A91F-EE6B62E2881E}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{54F6A1F0-18CD-4A8E-B08B-6A5203AADE30}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{54FAE856-AD58-20CB-A025-CD4895FA6E45}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{FEF08182-D075-403A-8117-C894067EC79D}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aluschedulersvc.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{55694105-5108-9405-3695-954187462155}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{557217a4-234c-bafe-f52a-595f0a4aeb50}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{2C846F45-2FB7-488A-A0AE-038EDEAF7E55}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{55D0FADF-CACC-495D-8400-7E7FA75CA4E1}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{56CF31C1-A46F-4B57-886C-6638DA412087}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{57AC9076-C898-B098-D098-A18319080975}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{589E405E-6C09-4341-862A-FFFEBD5C3C8C}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59DA0F12-24E3-4616-83FC-7925675F2A30}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5A041F13-A111-12A5-B0CF-F99818AA68A5}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5A041F13-A111-12A8-B0CF-F99818AA68A5}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{18093456-9012-4568-9076-908765467181}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5A041F13-A111-12B0-B0CF-F99818AA68A5}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5A041F13-A111-12B3-B0CF-F99818AA68A5}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5A041F13-A111-12B6-B0CF-F99818AA68A5}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{2CB77746-8ECC-40ca-8217-10CA8BE5EFC8}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5A069845-2036-6084-9054-6087502480A5}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5B1AEF69-DDAE-FDAD-DCAB-698F026ABDB5}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CEA2D14-E3C1-4EA7-BCFD-C79FC6EF28A7}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5D52083D-E1FC-42A4-802A-CA40106ECB2E}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5D7ED61B-DB3E-44EC-BED5-40307384FF81}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5DA743EA-6725-4ADE-BF17-C328743011FD}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\anti.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5DDFF6E6-7FC1-4101-9B08-A9BD30446790}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5FB8C5D4-929F-4870-89E2-7E3EE26EE701}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{60A345CD-ABCD-EFAB-CDEF-ABCD01020306}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6212B202-7BBF-4B40-9AFC-A88133B84018}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{2CEFF6F0-3DE9-4B2B-B2B4-1B1A6F69A795}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{65056902-6E7B-4bd7-95BA-688DB5FA5BEB}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{65C5C134-DB66-43EB-829E-C973D5F9CEEE}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{65F7F9CD-DAC0-45D2-9404-F0B2352536F3}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{66E62803-BC8B-448A-A880-96322FA7E23D}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{670D0417-CD55-4C33-94A6-BA5CDA0876A3}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiArp.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6A041F13-A111-12A3-B0CF-F99818AA68A6}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6A8D34D7-08D7-421F-AFF6-956A0BD6F0BF}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6B1AEF69-DDAE-FDAD-DCAB-698F026ABDB6}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C5DFBB6-9D4C-4C97-8073-DAA1CF156168}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C648541-1025-9650-9057-6541258720C6}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{2D11BCB9-F67D-4C25-91BD-9B78DE29E8A3}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C8D1401-A58D-A81C-CD24-A5915C4517C6}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6CDC431B-5481-43EB-93DC-901CD4DB2F1E}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D4C8213-9FF7-7C76-29A2-083C0C7BB02F}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ANTI-TROJAN.EXE
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E28339B-7A2A-47B6-AEB2-46BA53782379}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E753CA1-7CED-11d8-A178-000BCDB8C679}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6E7ADF53-1A96-42E8-BB07-53A8EA8BAAA4}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6FD45A54-9875-698F-E56E-65102358FDF6}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{70C09FA4-3B41-4E53-B195-F547FE88FF73}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{711D85FB-681D-4F4E-A214-41A615900A20}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{2D1A65D7-16CA-42EB-9C05-018291234B5B}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{720A87A2-9E33-41DE-8F42-CB514BFF1F6F}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7242A763-6114-4045-9970-07C545D72C45}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7319A1F1-9410-9654-3201-345FFA349137}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AntiU.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{734447EB-69B4-418B-8CCF-F92047108F51}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7359CB42-AC3B-489C-89BF-7699B597B779}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{736D2B41-7BD0-45BD-BF7C-E73AACC8356B}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{740D3283-A18C-4F48-8D65-2745215026AE}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{748EFE3C-3192-7C2B-AD61-BA112A31CFBF}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{749E4FEF-6AFF-41A6-AED8-364222D455A7}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{74C557B4-3E0B-4289-87E4-6AC8CB4FF099}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{2DB6D5D0-6850-4B03-A14C-B98D48CBE3F0}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77EDC705-6B15-4ADA-B25E-B791D30569Db}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\antivir.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77FD640A-158F-48AC-FD14-1597F14A9777}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77FEF28E-EB96-44FF-B511-3185DEA48697}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{781B13B8-70FF-446D-90D6-D823FACE394D}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{79921D3F-7537-463E-9E38-CD503A8FA485}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{79C12B2D-3792-4FD4-924E-87272BD728A9}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{79FC744E-75CA-49B0-8F02-AEAE4CAACBE0}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7A041F13-A111-12A3-B0CF-F99818AA68A7}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7A6DF30E-D0F2-446f-B4F0-BF4232D60E07}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{2DF5DA5E-22B9-4936-A652-2C84340181D4}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7BD57B5E-3091-4C33-B2E2-A39392F9F1D4}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AoYun.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C2727B6-5368-4582-BEF7-DB3370C262D7}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C69034A-F45F-D34D-A33A-C33C4D324FC7}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C8D1401-A58D-A81C-CD24-A5915C4517C7}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C954872-1230-6541-9548-6541025884C7}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7D182ECE-BFD3-4482-902F-035F4CE9A3C4}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F12CA98-B0BE-4408-ADFD-8B8AE6AF847E}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F23592B-8F2C-4C08-83A8-BBE01BF9CC64}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7FD45A54-9875-698F-E56E-65102358FDF7}
delsubreg|HKEY_CLASSES_ROOT\CLSID\{2EF0D734-21FD-4225-A1A2-BCD296182AAF}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AoYunzv.exe
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{80010030-0911-00E3-8467-99ca3230262a}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{80168013-E05A-4A05-88E9-6687C2D17362}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{80AF1289-F140-A140-D012-C1458759FC08}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{827E7421-A6BF-4BD7-B3F0-8524FDC2168A}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83108597-9059-F574-5B3D-48FF818F79EC}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83BA45AF-FAAA-CDDD-BEEE-BCDE1234AB38}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8419DDBB-EF93-4558-9934-9B439EF9CBAE}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{845BA58F-711A-48BD-948D-E6024F49909E}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8567EDFA-408C-43e9-B929-4C25C04F5003}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{871A54C1-1EB3-48bd-A879-5DBA4EF16BE6}
delsubreg|HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\appdllman.exe
delsubreg|HKEY_CLASSES_ROOT\CLSID\{2FED201F-5325-4EF9-8522-DB4E231EDEFA}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{87FD640A-158F-48AC-FD14-1597F14A9778}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{892B9CC3-70DB-4E90-B57B-07A8AABB0A86}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{894C0068-46AC-4F59-A140-EDE0DABA776C}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8A2B5714-1F9B-4843-B131-FC191AF30758}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8AD0F1B1-990D-4F52-A33D-2837E43CEF58}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E3526E3-F160-437B-9095-46A011877CBE}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8F67E146-FB6C-418F-9FE5-37AA2206D92E}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B}
delsubreg|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{912F6837-CCB6-424B-BC9C-8BB5541AFB54}

Delete specific registry values
HKEY_CURRENT_USER \Software\Microsoft\Internet Explorer\Main|CNSEnable
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{F6ECA821-B4FE-41BF-85FA-7BA54ED88176}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|postie
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce|BaiduInstallbdgdins.dll
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|95292102717235109971295992935442
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{073B937F-266D-4FF4-B73A-41A0236DD0AA}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce|bPYW
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce|cvhnykzx
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce|f13h
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce|GGan
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce|jgHS
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce|MessengerPlusLiveUninstall
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce|ORuI
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|put120
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce|PivotSoftware
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce|qsNt
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce|Regsister WScript
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{074616A6-5ADC-4A3F-B252-E1D605228B5C}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce|svchost.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce|Symantec Event Manager Service
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx|deryheruxc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx|Microsoft Update
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|A5C32D50
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|ACQV1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|rissos
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|AVP-SE
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|bogekum
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|Configuration Loader
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|Copic Tilevb
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{076FB645-17A5-4DE6-B23E-C90FAB741CB0}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|GBNP2
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|Generic Host Process for Win32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|GKQN1
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|gyfypu
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|hgkytwe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|qq
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|IXUV0
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|JGPF2
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|JREA1
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|KFWU0
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|LWWR1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{08223B03-1B38-4A33-A83A-A4D3CC1D6E4E}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|MCWR0
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|Microsoft Update
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|MPGR2
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|Newsvalue
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|qq10000
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|PK Services
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|QLFQ2
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|RWVB0
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|SmcSVR
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|System Service Manager Device
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|TileFree
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{083A5F21-BCB9-4B21-A121-2584BEEFBFEF}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|UpdateWin
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|Win Updater
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|Win32DLL
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|Services Control
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|Windows SP2 Update Manager
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|wizowa
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices|woocob
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad|glnjfzpj.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad|ieModule
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad|ikqzluvt.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad|iurgzdjy.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{085C1F40-1C33-4296-A3B3-CC47540B9A12}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad|meqeypec.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad|nxggjwny.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|servises
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad|oledll
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad|qurymlae.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad|RealCodec
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad|ubhwsmoo.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad|vjzfvxiu.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad|ywyrgnql.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad|zqcksyte.dll
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\.Net CLR\Parameters|ServiceDll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{086CBBCA-8B04-47E3-B792-5E2C558F810D}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{08223B03-1B38-4A33-A83A-A4D3CC1D6E4E}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|SessMgr
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{1055CA44-51F8-486B-8CBD-DC7AD4213F1E}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{108DA6C0-CFBF-41D4-9A09-C4D06AE6FFD2}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{122B901E-493F-4AD9-BC69-7DE8C3E52FCC}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{1719B301-B494-4185-9379-242461F9CF02}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{23DA65D2-C696-4EE4-BEE8-B4841DEC3E30}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{2EF0D734-21FD-4225-A1A2-BCD296182AAF}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{36AC68E6-0C26-4D39-B98E-54B49DAB6BAA}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{38FEFE05-702C-440D-AD5C-B796209A1CC5}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{41D2953A-CB90-485A-8673-6975088309F7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{086D50B6-D088-41A4-B6C8-5DF3B02FA3C7}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|smile
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{51716C09-6B08-4CCF-B526-718E912C0573}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{51AA0D89-E9A9-4284-93E8-40C0FDD59304}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{53915AE3-2660-4870-B092-C9E5A292D327}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{5405A7B2-F3F5-446F-8715-2A4EF674E079}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{610B6886-2A1A-475A-A842-65A613C70460}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{704C3595-DB85-40F6-A601-8D6F346907BD}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{737858A9-9AEA-4838-9B49-54DA731F7F37}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{765BA0B5-EBE4-4B1A-AFDA-5683606F626C}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{7F41BC77-7742-4ABF-9277-1316B43D049A}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{822775B8-E45B-4E55-9325-0753A0C1DC00}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|start
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{08A8DAE3-31B7-4702-AF5B-558D1F84FE35}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{8708994F-1758-4C2C-9A3F-FA22D6CCCB41}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{87DE8A1A-96C5-4420-B222-EF998F697CE7}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{93DA1E7D-7C46-4F90-8674-EC90511FCA72}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{93F33500-527E-4E33-AECA-69B15243A90E}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{A5CA6C70-7185-4466-AB45-B1C34E7A37CA}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{A600E212-2A41-41BC-92F1-ED5C96B06185}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{A6B7F435-38B4-4DCC-9EBF-21C968ECF4FD}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{AB8105BD-1B1B-40F3-8D3D-65FD7FC68CC5}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{BE12C98F-645D-4566-B524-DC32040B7C8A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{F718AEF5-84CF-46AC-951D-3915D838897E}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|stup
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{CD478099-014D-4B3A-A4BB-B518F1019BC7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{08CBFE20-8DC8-4195-B8E2-DD66F860469D}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{CE38B9E6-AF0C-4B93-AFAB-A20C2311FFD0}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{CF2C613A-A0D9-4E5C-B1BB-6B03B269B054}
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks|{E3531A16-FFEA-416F-82DF-32FEDE02EABF}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|43a5a334-80c5-4815-bc0d-590e9356b558
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|Taskman
HKEY_CURRENT_USER \Software\Microsoft\Internet Explorer\Main|CNSHint
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{08E909A4-B236-48DD-8BCC-90A604B93E68}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|svchstt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{08EB3951-6162-47C4-8EF5-CF51744E2B5B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{09FE7311-3589-4EE1-A7A9-15B5312F0D04}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{0A2D7F10-1153-4061-AA4B-ACB870212B57}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{0B3358D2-410F-4693-9C14-DD01CE1698CF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{0B43554E-BA93-429B-8531-647CC155B8D3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{0B83E10B-88B2-4A02-B603-0494C2A87DC7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{0BC82A03-D2E1-42BB-87BB-BDF7692AC2A7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{0CCE6E12-C2EC-56CD-1A62-AE3FD6EF56E6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{0D267113-499A-4EEF-998D-C45731C1B313}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|Aim6
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|SysAnti
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{0DCB6565-A9F9-41CA-97E1-65F4A6345F3E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{0E55A9F5-EEA3-4334-9906-F2FB3C821153}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{0EA12C16-CDEF-6AC1-236E-CD3FE82F5213}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{0FA40B34-8B9B-44ED-B85C-60A83F2C5D24}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{0FAD2E16-C8EF-5AC1-1E6A-AE3FD8EF56B3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{0FE2703F-7C86-42BD-8B03-B43C481AD738}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{1055CA44-51F8-486B-8CBD-DC7AD4213F1E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{10618412-C528-C784-C056-C164D1F7C501}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{108DA6C0-CFBF-41D4-9A09-C4D06AE6FFD2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{1166350E-BE0A-4242-A816-AF0A9752D2AF}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|388g2x8b12c
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|amva
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{11B10F7F-FB23-466D-BDC3-9591CF02EC17}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{11FDB6D4-166A-47BF-A0F8-A09DABA75FC1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{11FFC1C5-0887-4E11-9330-18EBB026D4F3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{122B901E-493F-4AD9-BC69-7DE8C3E52FCC}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{12316E69-4CE5-4CD7-A174-C0BD57529D5A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{129067F2-E20A-4D14-8F30-FC3968B9C028}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{12B02216-AC3F-42A7-8313-449771237061}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{12BA6240-AA6C-4F33-9048-F2168F219E42}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{12C00240-1B5A-4CC9-9DB8-F97EFD4EF36B}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|rs32net
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{133AEAC9-9C88-4905-864C-38BBA312D9B0}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|anhtaaa
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{136F4843-F6B1-459F-83B5-7B0F982FDDA5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{13DED518-ACC3-4FA7-AF26-4E67A43B016E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{13F7717D-A7AD-4DBA-92E2-083A4F1B1B1A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{14698742-2059-3025-9058-954023874141}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{14A0A05F-E7C4-449E-8A35-088F68B56CA4}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{14C0A9F9-5512-43BA-87FA-ED4860306453}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{14F7F80A-0FE7-4A24-83CC-639D42BE410C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{15882A2F-A06D-486E-8958-E84C86CBF273}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|SysLive
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{16368135-64FA-BC34-DA32-DCF4FD431C91}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{1655D6CC-5FAD-4A03-9EE2-49D91A386E6D}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|anhtaas
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{16886058-6A31-4D53-B4AC-4CC7D2248D69}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{16AF66EB-93C8-49F9-BB09-B4F87CEDCE46}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{16BC0F81-410C-41DF-A902-1B04368BA8AE}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{16FF142F-BEBD-47CE-A3A6-D52A1A2ECB54}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{171565E3-F0BB-4FF0-9A42-C9406C79DB78}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{1719B301-B494-4185-9379-242461F9CF02}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{17276F09-EF0A-430B-9C3E-72CDD59449E3}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|SystemTool
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{17DFD111-BF3A-4CB4-ADB0-88FCBFE69821}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{18093456-9012-4568-9076-908765467181}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{18e64250-19a8-4d10-828f-30e101a22291}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|AntiMalware
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{18EDD7A0-87EF-45B7-85CF-6A7E1341E2BB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{18EDD7As0-87EF-45B7-85CF-6A7E1341E2BB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{1957817A-94B2-4CAC-B113-A331809B5730}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{1962C281-E515-4D4B-A449-7E7B4B88D638}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{198FF3D8-56F1-466B-A36F-F9C28B43E440}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{1A698452-C5D8-C584-C256-C264C987C5A1}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|TXMouie
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{1A86369A-3629-46BA-A666-D1811761D146}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{1B1D8534-8B2E-4DF0-B92B-C878E4DB0F0B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{1BA683A0-8EE6-4C60-9BF2-907C2CB6B680}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{1C0D6505-4198-4783-82F4-C6683FF6C4EF}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|av_md
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{1C1BB1A6-8167-4C20-AB35-03B97A1389C8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{1DBD6574-D6D0-4782-94C3-69619E719765}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{1E322963-355E-422F-BE2E-8C4667E31D10}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{1E51C0FD-EE36-434B-AD2A-FD1FF3731C38}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{1EBA4EB0-24EE-4310-8F6C-7F5D6EDC19F4}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|user
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{1EEF419D-2264-4522-858A-5C2C31EDF2AA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{1F2E3A6B-94A7-4355-B58D-74DF486E6C97}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{1F71CA42-7E7B-4A47-A923-B5F4231617E2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{1FB3B422-7793-455A-8802-660853A9D102}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{201476D0-2B18-462E-AB9F-3E2B0CC8732B}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|axisremote
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{202AEF39-2BFA-4A5F-B526-390FDE0BC675}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{20618412-C528-C784-C056-C164D1F7C502}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{20909876-4567-3908-4056-909834565102}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{20CFDC59-228C-481F-80B6-404BCFA16B13}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|userini
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{21BE5FDF-D4CB-4850-AD99-21E68B50BF3F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{22A11E32-1FCB-4F54-A511-34253CB09A1A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{22D75360-199D-4F79-880D-82E766675F06}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{23784612-5FEC-4E07-97FD-D5B5954A4236}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{23DA65D2-C696-4EE4-BEE8-B4841DEC3E30}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{23E6662B-FA39-4042-A240-990A5E4827AB}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|bgswitch
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{24144CB8-10ED-4BFC-843F-68A9F3369947}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{245C05BC-9441-46AD-8897-1680DAF88898}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{24EDEA54-9E75-4559-8818-F124CADF6DF8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{F71A67D5-5BBB-47A3-9534-4150FC739257}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|waults
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{24F05563-C144-46E4-ADF3-516F4E0AA91D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{24F8B41C-5AE1-4CC3-833A-17619A05D0BA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{25FD6584-698F-BCD2-602C-698745210352}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{26F0E2C9-F853-42D4-866E-86AA4C8EF58F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{26F58495-C4E4-4E64-97E2-FBD9A6080F93}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{27AC9E17-125D-4EE5-9617-502A90E7F709}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{27E1C1B0-7117-4582-8565-682E569810D2}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|book ante
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{286C2802-481C-4324-8D20-8E1738548D39}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{2876D76C-CAAA-4313-AF97-8D1D9A2A1087}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|XMouie
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{2882C70A-AD5B-45BC-A8EC-D17AA8FE54FD}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{28907901-1416-3389-9981-372178569982}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{2895B086-90F7-459C-BB2E-E3AEB77A1BD6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{289C5E9E-D431-436A-895B-74F321F3EF11}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{289F69CA-F9BC-4186-818F-3F9F3B6F3B50}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{28CD9D00-836E-4E0A-A9AA-8F4F5ECF3958}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{28EB3777-3E23-4E72-8449-A992D09D24C3}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{291FABA8-CB00-488C-AC9E-B457FFC4A117}
HKEY_CURRENT_USER \Software\Microsoft\Internet Explorer\Main|CNSList
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|brastk
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|xzad
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{2960356A-458E-DE24-BD50-268F589A56A2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{2A30458A-4460-426C-8D2E-189F8A42C708}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{2A698452-C5D8-C584-C256-C264C987C5A2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{2B660F50-0FD6-4D96-9ABA-48B731C7ABAB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{2B69874A-C58C-458D-69F0-698F874E41B2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{2B94FD3C-E6C7-4E33-8966-D216D6B05ED2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{2BD6354D-8A68-4F9A-B8D7-88A5E09BD16F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{2BDC2363-6468-4A18-A082-1782BE1B4B0B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{2C268BA0-2884-436B-9ABE-AD95BDDC6376}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{2C56D8DB-5D4B-4EA2-8B68-18F5C513E50C}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run| ?瓥#??i'??DｇC:\Program Files\ISTsvc\istsvc.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|braviax
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{2C846F45-2FB7-488A-A0AE-038EDEAF7E55}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{2CB77746-8ECC-40ca-8217-10CA8BE5EFC8}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{2CEFF6F0-3DE9-4B2B-B2B4-1B1A6F69A795}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{2D11BCB9-F67D-4C25-91BD-9B78DE29E8A3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{2D1A65D7-16CA-42EB-9C05-018291234B5B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{2DB6D5D0-6850-4B03-A14C-B98D48CBE3F0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{2DF5DA5E-22B9-4936-A652-2C84340181D4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{2E6ED9F9-D2F1-4B33-B505-478C63E3B53B}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{2EF0D734-21FD-4225-A1A2-BCD296182AAF}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run| Java developer Script Browse
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{2F281C60-0A58-4E54-9369-57216CC1611A}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|BSserver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{2FED201F-5325-4EF9-8522-DB4E231EDEFA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{304B9531-94D9-4F69-81A3-99B7B172220F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{30618412-C528-C784-C056-C164D1F7C503}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{319675CC-4129-497f-8C7F-E2F48251019E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{31E59C8C-20C9-4B7C-A160-6983B2AAAAA1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{322302FE-90F2-41B9-95BF-FA3F4AD60B48}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{32596546-2036-9451-6058-658402589723}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{325A1A2D-CBE3-4411-9F41-0FFA22ACDA52}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|rwasds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{32DC6FB6-AD66-43A4-B231-151B57A7B3F0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{332F8DF8-AE56-48C6-B8A2-17F82403FEC0}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|cdoosoft
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{334345F1-DACF-3452-CB7D-4620F34A1533}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{335A9BAE-19FA-42F2-AFD2-20C3275EF392}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3422FB0F-95EB-458A-8B56-39552017A4EF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3474A8C2-BEF9-46C8-983A-A26A0030EC30}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{349F9B06-D92F-4AF9-AE96-6730A16821F9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{34A25F04-008D-403E-8EE6-2307BC02FA2E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{35671234-7890-ABCD-CDEF-567801237653}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|%windir%\system32\kdddv.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{358F3DF7-2CA6-4D98-B35E-08F02D2694DB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{35D95784-1EB0-4494-BCBF-1F37C2AD3BF3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{369774CA-7CB4-4A3F-A9A9-77D6BC53CB3B}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|clidoc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{36AC68E6-0C26-4D39-B98E-54B49DAB6BAA}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{36EAFED6-FE52-42E5-8FEC-703424BAA9CF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{37A924AF-1A5F-CF21-AB1D-1D5CF82A8A73}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{37AC9076-C898-B098-D098-A18319080973}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{37BEAC91-ED58-4F24-A924-8BD1E46F9A2C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{37C5D66A-8B1B-4545-8112-3751194F6A4A}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|%windir%\system32\kdsxr.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{38093456-9012-4568-9076-908765467183}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3816D07B-D6F9-403B-B7D7-EDE52959341B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{38EEF43B-3B2E-4619-8EBE-36CFDFD13A0B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{38FEFE05-702C-440D-AD5C-B796209A1CC5}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|Clip
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{39109876-7619-9101-7012-901938475193}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{39349BEE-BE43-47E4-8670-8B34570E112D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{399A4CC9-2020-43ED-8888-C3F1B536D675}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3A5700C3-2847-4CBE-A3E5-F0C394690C9A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3A908760-8000-4000-A000-9000322145A3}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|0123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3B2DC1F1-E030-4C51-AE8F-39929185CC21}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3BAFECEF-0CE3-45C7-819D-57ABE5163BD8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3C954872-1230-6541-9548-6541025884C3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3CA7A137-35F8-46CD-B83B-534CD13D5A67}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3CBB135A-485D-4B93-AFB6-4EA39CC40864}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|cmds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3CC177E7-3E8D-4F5B-AF46-308380C3F6C1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3D144530-43DA-47CC-B7C7-A3A9F3B9A6B2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3D490B56-425C-4B8F-889E-0E391AD54DE8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3DCB9005-ABA0-47F8-8C40-49ABC04AE5EE}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|03863121
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3E090A14-E55E-4BA3-97C2-505907EAC7A7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3E1B07B7-6519-4BD7-9896-385B0B713525}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3E52FA6E-D83E-4811-8FB5-1D54C0687227}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3E7C9687-C865-4797-A540-0B3D4FD0FAB6}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3E8C8B7C-369D-47D6-B53F-E1880DC3DA17}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3EA18648-FAF6-490D-9C92-8FD729028A58}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|Cognac
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3EA5D055-B989-4F08-80A2-79DE32243973}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3EFEAF36-B081-4454-9DE0-9023F21B2263}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3F74CB3A-F095-45D7-AE11-F4535A990B83}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{F7776F24-A299-492D-8E5D-409140455376}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|04174051500
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3FA3CAD1-C5D8-48B9-800A-A7B2D2A23044}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3FDEB171-8F86-0003-0001-69B8DB553683}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{3FDEB171-8F86-0004-0001-69B8DB553683}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{40618412-C528-C784-C056-C164D1F7C504}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{407C7A80-4656-4C4A-81C6-DFFB8009B80F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{40B75357-A4C0-4C28-9DF9-50F288D1AC49}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{412441C4-07A6-4C62-85F1-823946775569}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|coolsos
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{41912A21-4337-4E99-8C30-80A8434B0793}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{41AE6BB6-3815-4F48-8FA4-920B586BA193}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|04D668
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{41D2953A-CB90-485A-8673-6975088309F7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{42752A70-C149-4995-AE4A-AB81F12E9BC3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{427E02E6-39DB-4424-A49C-7553CD1331F5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{42B244BB-E8F8-4878-B4BC-BFC602FC1D3A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{42C50607-D944-41A9-9B67-720AFBE8C22C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4306D2B4-1D20-4E23-AE74-3CE99776DBC6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{434FA69C-5F0A-42e1-82B8-10AF2C8E53C6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{43ACDCC5-9009-4AF4-B80A-93BC656EF298}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|couquar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4486FE99-9018-4E49-A6E7-28CBCAC846FE}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|0c4fd606
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4540B243-1CA5-41F5-8C80-A799B22CDB77}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{45671234-7890-ABCD-CDEF-567801237654}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4582BCF1-1C39-4058-88B0-CDB8BB57EA61}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{45AADFAA-DD36-42AB-83AD-0521BBF58C24}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{461D2AB4-29A5-45C2-9134-D52272D3DE38}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4642593F-4159-4C7B-9036-33D6CD7F1750}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4679E74B-E5EE-458F-B613-2324AA1C817E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{470165F1-9F65-569F-F895-F14F58F41074}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{47018D3A-8682-4D30-AC5E-F74B84189AB3}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|07687952239537979582643710732095
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|0CBEA3
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|Creative program
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{478932A2-862F-4A34-A264-54A6EB998FDE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{47958181-270d-4547-a2c8-d73002b9a922}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{47994C89-1857-4D33-B196-263ED6FA4CFF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{484DEC01-A8CA-49DC-8DA9-35FE53BA36A9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{487C9905-26A8-42C8-8033-C58AD3D2AEC3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4894F5C2-169D-4DAC-A982-444B9BDB3AC4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{49109876-7619-9101-7012-901938475194}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{495271CA-D0C6-4052-ABE6-5B01C73CDFB0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{49762F37-EF1F-447D-A27A-967C9520A3F8}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|0DBC50
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4A1F8C99-7A43-451A-8EF7-5EA11770A33E}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|ctfmon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4A26AA9C-E583-4338-9BE2-17717E8E15DA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4A698102-5904-AFD0-20DF-CD1A65829CA4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4B00FA79-7C1A-41F1-AF62-C7FF0D3B96A7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4B00FA80-7C1A-41F1-AF62-C7FF0D3B96A7}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4B00FA89-7C1A-41F1-AF62-C7FF0D3B96A7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4B3DA347-ACBB-497B-B62F-957C4D2B46D3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4BF9CBA3-8DEE-41A1-8BDB-FC28D30E949F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4C31B312-1A26-4D0F-A31D-5F18F937AF50}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|0ntoikb2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4D023DE9-F4B5-4BE0-99C6-7C7AD0CF5426}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4D165A2A-4BC1-4CA8-8299-08E05AAAB5A4}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|dc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4D698451-2015-6358-9871-2015987452D4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4E3FBFA4-F1CC-4B66-B333-B9F0FF4B4748}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4E5CFE74-700B-4A8B-B0BF-A6B47D896C18}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4E7B7BCC-D111-49B2-A61D-26CAE048F844}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4EFDDEBE-303C-4D1A-8C9E-E4F215C43651}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4F34C688-FD49-42FC-97F7-87D2F5791612}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4F5EEDE5-1687-49D2-8A17-FF0B454FB37B}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|rwasds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4F72F83A-1C16-444C-8821-D01FF4759555}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4F81668D-833C-4739-ACDD-267B6E3A1FDD}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{4FBFD5A4-5FE8-4444-8BD9-FD0FAFA64F96}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|dc2k5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5007ED72-6A0A-4D7A-8C2F-B3D9CB85186A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{501A388B-6FBF-4150-9248-6D1E1BCF2B40}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{50632D5C-B71B-4ba0-B012-3DC6F15C011B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5086CD29-ED02-41A0-B571-ACDA0C33BA94}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{50940F85-F015-14F1-A05F-F69858AC6D05}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{50EBD6A5-0CF6-4E59-AE08-CCD991AA0596}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|1067A8
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5123A024-BAB1-4DFD-A6F9-CE92A4DE8ED1}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{512EABF9-6550-4B48-B46F-C6CE65F9D2C6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{51716C09-6B08-4CCF-B526-718E912C0573}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{51AA0D89-E9A9-4284-93E8-40C0FDD59304}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|Desktop Security 2010
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{51F88A10-09E6-4763-948F-1C8861003255}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{51FC2309-B81E-4542-A0F1-E9A51297F2F4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{52023698-6984-8541-9654-698745012525}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{52635CBE-B590-458E-86DF-E4F82348511A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{526403AC-FEDD-4350-946A-BC0B8114C65A}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|11977387950
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{526EB425-7F56-4773-8D70-B8E45AA8E2B6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{528DF602-9541-A985-210A-984A698C6F25}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5350D2D5-0874-40ED-8D73-E3D0489215E0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{53915AE3-2660-4870-B092-C9E5A292D327}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{53D44DB6-E22B-4B17-97D3-572C96CCA6E1}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|disnisa
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5405A7B2-F3F5-446F-8715-2A4EF674E079}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5419706F-9AD1-49BB-A91F-EE6B62E2881E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5471D4CA-DADD-43B0-9FAD-009FB2D65726}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{54DA5754-2475-4B55-8DFA-D0327C8F4A9E}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|14D5FC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{54DE8BF2-906A-445A-8575-CCB08E809495}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{54FAE856-AD58-20CB-A025-CD4895FA6E45}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5528694E-30EC-46E6-98F4-C413B5AC4DD4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{55694105-5108-9405-3695-954187462155}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{556BA12D-13FE-41F4-9740-B6F1B8E1A8C3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{556F0F4D-9CD8-4C91-A95B-0F88D638406A}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{55BD6687-15F6-41B3-959B-B69C032E7795}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{55D0FADF-CACC-495D-8400-7E7FA75CA4E1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{56BC86C7-0692-4F94-A2C1-6CF1DBF8096C}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|q550cpwp
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|16220144
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{56CF31C1-A46F-4B57-886C-6638DA412087}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{56E800F9-8E27-451B-B960-53EC724C3A87}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5731EA1D-6AAF-4DE9-BDDA-7B390A75B286}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{574D626F-263B-4B1B-9F38-D858CF9135FE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5768264D-0CED-4643-A907-581545843629}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{57AC9076-C898-B098-D098-A18319080975}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{589E405E-6C09-4341-862A-FFFEBD5C3C8C}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|dorfgwe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{58FF3024-8A83-4B1A-88E9-302F47646EEE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5934EA2B-B2C4-4BE7-BF7A-FBA781A12E40}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|16345784
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{59703ED2-799E-4F3F-9EBB-41B2F1F65C07}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5A041F13-A111-12A5-B0CF-F99818AA68A5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5A041F13-A111-12A8-B0CF-F99818AA68A5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5A041F13-A111-12B0-B0CF-F99818AA68A5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5A041F13-A111-12B3-B0CF-F99818AA68A5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5A041F13-A111-12B6-B0CF-F99818AA68A5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5A069845-2036-6084-9054-6087502480A5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5A0B8C1F-115F-48AE-B52F-DDA144375324}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|doscp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5A5B354D-E845-487A-8544-F111366B59E1}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|165896
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5ADD154A-2990-49F7-99D8-922E7D292E61}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5AF04671-190D-4D5C-97AF-D8054F831E27}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5B0C7E2C-3257-4619-8282-A173017B16E2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5B77087D-AB76-4C22-B0A6-C34D1F438E55}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5B953C72-A6FF-11E0-9A84-00C04FD8DBD8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5BBEB45A-1387-4FEA-AE57-74273B8C33C2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5BBFBD79-78AC-42EF-B80E-1EFD555C0675}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5C7596CB-C3CC-6BA3-BE52-8EEA63F9C61D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5C901F36-6395-4667-AF85-B1B64AD3693F}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|dsdibmktvt
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|1685932861400
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5CEA2D14-E3C1-4EA7-BCFD-C79FC6EF28A7}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5D7ED61B-DB3E-44EC-BED5-40307384FF81}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5DDFF6E6-7FC1-4101-9B08-A9BD30446790}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5E7B90C2-75FE-4B5D-A3BE-68ABB8785400}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5E907A48-400E-4EA8-9792-FFAE052D59E9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{5EEEA400-799B-4A55-8F17-E03795052FD0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{6049BC02-7EDA-4C41-B4AB-D5398607C39E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{60940F85-F015-14F1-A05F-F69858AC6D06}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{60A345CD-ABCD-EFAB-CDEF-ABCD01020306}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{6101B532-3E30-49FB-8594-F9B22338FF4A}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|1696752819875
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|0F073E85A930ED81EA37A6ACACC660FB
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|dsfghjgj
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{610B6886-2A1A-475A-A842-65A613C70460}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{610C01BA-76E0-463C-B906-73061D855AF5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{6212B202-7BBF-4B40-9AFC-A88133B84018}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{622E84AF-AB3B-419E-AB5C-67DA236E91AE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{62C2B451-2F5B-4A7F-84DD-F2FBC3735E4F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{6302B4AC-43E3-46D2-9969-629A0E175FB1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{6345F11D-722C-4B9B-B99E-0E9F58F30522}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{63C8062F-BA71-44A1-8322-1C9A84783778}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|18303594
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{648B6B95-9B30-47F2-AA08-AA0E665128ED}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{65056902-6E7B-4bd7-95BA-688DB5FA5BEB}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|ertyuop
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{653BC427-1413-4CFA-B41F-3F0294E7640F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{65D89E28-6877-480F-85EE-B67147796C82}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{663FCF67-330C-47E9-973C-2260DE48283B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{66A11D22-9C6D-4D4D-9EA8-D8C7F69194A6}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{66AFCB56-FAA9-42D2-8C72-2767A46C7FA8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{66D2E7CF-582B-4146-85B3-93224CB76DC9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{66E62803-BC8B-448A-A880-96322FA7E23D}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|18712304
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{67A4A417-26DB-4FA5-922C-3F036D95647A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{6826A3DB-EA8E-4E67-880D-53D04C7C0BD8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{68F7767A-090C-4BBF-A015-720ACC6706E2}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|esetsos
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{68FC11DF-A032-4429-995C-730586B6114F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{695C5A80-18A5-4CD2-A911-4DBEBE92F18D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{69828DCD-20B6-4588-BDC0-8A8D0656FEDC}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{69B265A2-A172-4D27-BDF1-917E6D8B1DCC}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{6A069845-2036-6084-9054-6087502480A6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{6A2F86CD-BA9B-49A1-B708-9C550BEF6DA7}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|SCMTool
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{6A903CE9-E762-46BB-AFA6-2DB46482B743}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{6A908760-8000-4000-A000-9000322145A6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{6AA221D9-0DDD-4A03-B4EA-5360359D0AE6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{6AF45C53-676C-451F-A4A9-DC8D61D9D46A}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|EventLog
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{6B1AEF69-DDAE-FDAD-DCAB-698F026ABDB6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{6B9FEAD7-4319-4312-AB05-D8C9CD255BFE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{6BB80F57-0262-4FE0-841B-5EAAB5609BF6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{6C5DFBB6-9D4C-4C97-8073-DAA1CF156168}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{6C648541-1025-9650-9057-6541258720C6}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|18784278313
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{6CC3BA8B-1594-4607-BC83-E4AB6B6AF176}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{6CDC431B-5481-43EB-93DC-901CD4DB2F1E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{6E3FCC92-4080-4619-86AA-D2AF43A478EE}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{6E7ADF53-1A96-42E8-BB07-53A8EA8BAAA4}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{6EB6B154-5D10-4505-A998-E71419B05BE1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{6FD45A54-9875-698F-E56E-65102358FDF6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{704C3595-DB85-40F6-A601-8D6F346907BD}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{71046DD5-E136-4C4B-A6B5-91C30CB15291}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|18874064
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{711D85FB-681D-4F4E-A214-41A615900A20}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{71463F9C-9BA4-46A4-9AA9-61AB4D65409E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7152C68A-D93C-49BF-AFEF-6B4576849A7E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{71A78CD4-E470-4a18-8457-E0E0283DD507}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{71C4F360-FF1E-413E-B17A-0CA267A78E97}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{720A87A2-9E33-41DE-8F42-CB514BFF1F6F}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|EXPLORER.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{72236771-3891-46BF-B185-1D816A09333F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7242A763-6114-4045-9970-07C545D72C45}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{726B4F5C-36C9-4D42-AD3A-48F768A1DF3F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{F7B7E354-C12F-4C4A-AAAF-A21C61ED8561}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|19121874
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{72B29486-39B6-4241-B234-B57DEF78302F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7319A1F1-9410-9654-3201-345FFA349137}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{732AD45D-A875-4019-970D-B32DA96C3EBD}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{734447EB-69B4-418B-8CCF-F92047108F51}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7345AD03-BF1E-4B23-8ABA-646A8E085BA1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7359CB42-AC3B-489C-89BF-7699B597B779}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{736D2B41-7BD0-45BD-BF7C-E73AACC8356B}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|Firewall Administrating
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{737858A9-9AEA-4838-9B49-54DA731F7F37}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{739A09B9-3DF2-484F-89A1-0C417E598ECD}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|19335464
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{73AE86E6-7F03-4C3B-8980-FB1DA157D3C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{73F1DAAB-0DBA-4804-81C9-BCA409393AAE}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{740D3283-A18C-4F48-8D65-2745215026AE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{741D962D-B1DF-4BE4-8C92-FAF45661D30D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7488E47D-E8F3-41C0-B2DA-9B2BD8803A80}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{749E4FEF-6AFF-41A6-AED8-364222D455A7}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{74C557B4-3E0B-4289-87E4-6AC8CB4FF099}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{74DA2FEC-F68F-4DC7-9A45-9174AC044427}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|Fun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{74E84D48-3ED3-4DBE-A174-3997B06C56F0}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|1E0967
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{755D0ED0-3996-4ADB-9B1F-AD8F0E9E4738}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{76220F29-1F4D-4A8B-9E32-2D64FF0B41D6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{762D618C-E2CB-4217-8275-03302A93073F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{765BA0B5-EBE4-4B1A-AFDA-5683606F626C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{76757940-7773-4AA5-BB57-F4A0270E165C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{76B9BA7A-81D0-4979-8598-8471F2AB5186}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{76CBCF38-0583-44C7-A1AE-D463DFE625EC}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{76D44356-B494-443a-BEDC-AA68DE4255E6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{77064888-B267-464A-AB8A-BC262FB23603}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|german.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|1F48C3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{77AC4257-6781-430B-80C1-BCA6D20C950F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{77AE086B-ED00-4527-A208-6FFF03D92F4C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{77FD640A-158F-48AC-FD14-1597F14A9777}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{77FEF28E-EB96-44FF-B511-3185DEA48697}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{781FBCC1-99C7-4AE0-95F7-66EA49E86DD7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{78B02B63-EAF4-40EE-935D-C86DF4C6970F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{78DAA23D-614E-445E-942D-7E69EDA464DF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7938BD2F-0143-4C46-991C-71069712D9D9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{79462C10-DB9A-4CA0-B3DB-24AE72636B75}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{79470BDB-086A-4A4C-90B1-66452C36E5B4}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|1puninst
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|gridclock
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{79921D3F-7537-463E-9E38-CD503A8FA485}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{79B6D0EF-EA55-478A-AE4F-5E582D19D046}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{79C12B2D-3792-4FD4-924E-87272BD728A9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{79FC744E-75CA-49B0-8F02-AEAE4CAACBE0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7A041F13-A111-12A3-B0CF-F99818AA68A7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7A6DF30E-D0F2-446f-B4F0-BF4232D60E07}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7ADC2AB1-5C6A-4178-82DA-94863354AF7C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7B473157-ABA4-4222-8505-42F5D34EF824}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7B8B0E17-B03E-4EDE-BA46-F31692D977BB}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|20.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7BACC4F8-0754-4BA0-BB18-9DDB1B8C6C48}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|13581420797231458393188814511016
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|ieupdate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7BD57B5E-3091-4C33-B2E2-A39392F9F1D4}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7C2727B6-5368-4582-BEF7-DB3370C262D7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7C59DDC1-7792-4027-9D72-9807937E3464}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7C69034A-F45F-D34D-A33A-C33C4D324FC7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7C8D1401-A58D-A81C-CD24-A5915C4517C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7C954872-1230-6541-9548-6541025884C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7CA8D7D3-56A1-49A8-B167-103FCB917B1F}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|2008xoceanclick
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7CC109E5-B2FC-4FEE-AF04-74B2DCBD2540}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7CC1DA3B-A5C8-4329-8004-41981BA4BF86}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7D20F028-D3F8-4B18-B42A-6F569EEB77E9}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|IgfxSys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7D5C8CCD-0111-41B4-9A61-73927EF2F242}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7E72C5E4-028B-4C43-AE6A-52FCA04C5CB5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7E94C114-C874-4112-9922-054D8E5546E2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7E983C60-EBF5-4A36-BE25-EA26ED55052B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7F41BC77-7742-4ABF-9277-1316B43D049A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7F753D7F-3EC8-4467-B2DD-A148F978D29F}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|24021215
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7F9F521D-41E2-4DB8-936A-F126EB10EBFA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{7FD45A54-9875-698F-E56E-65102358FDF7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{80168013-E05A-4A05-88E9-6687C2D17362}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{803E9ADD-8D2B-4D78-AD34-D7FD790A17FB}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|Init
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{80AF1289-F140-A140-D012-C1458759FC08}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{814AC387-61EE-4BAA-963A-55FF92BDDB7B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{81549ADC-2F24-4784-8124-F1075D770539}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{815EDE81-767D-4636-80F5-141578667A98}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{8183F477-9E50-46A7-A3FC-35C149891BB6}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|servises
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{81AF1CF6-D1C9-4C6A-AC01-EDE54E71945B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{822775B8-E45B-4E55-9325-0753A0C1DC00}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{827E2FB4-1047-43DE-848D-E12BB0C97AAB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{82DE2804-AF65-4CF2-BD3D-A95D734D6BDA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{82E044C4-C4CC-4535-B731-F6CB8EB1F6D8}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|Intel Physical Routine 1.2A
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{837B45D6-BF85-457D-AABF-6D2E7815F791}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{83B78794-1991-4BE4-A439-D5EF37E8DC97}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{83BA45AF-FAAA-CDDD-BEEE-BCDE1234AB38}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{840AEC38-0194-4BA3-8621-AFC7CFA9F3F8}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|27C7FD
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{84143967-B645-4BFF-B873-DA1DC886E9A7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{841529CB-7F77-4B99-A895-B5441E0D302F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{844B57D0-AD06-499F-AC52-15A4E6D14C28}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{844B8558-9E29-4D70-AF91-26319E22F1A8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{845C1D27-529C-4EA5-9796-8E71AC5933BA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{84639C2D-CD75-4081-B515-329AFCECBF19}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|Internet Security 2010
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{84BD3613-EBAB-4CCA-9E94-00CE6AB956A6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{84CC1A5C-D480-4E41-AAD2-C72B7A2635C5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{8554F9AB-AEF3-4701-886F-4192F0CC36C0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{F8C6B7B5-DAE0-4B78-BF2A-101C9A9CCA27}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|2899A9
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{8566F82E-03A4-416E-AEAC-66600D8881F1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{856F6FA5-447F-4FB8-BF6F-FBEDB90A3829}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{8614153F-3930-448B-9AD8-E65DF6AC4750}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{861603EA-21EB-487F-87FD-D373009787A2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{8708994F-1758-4C2C-9A3F-FA22D6CCCB41}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{875E07B1-0614-43D9-A76E-D76A28AB3D7B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{87D2404F-32A3-46C1-A90A-A96D6265A122}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|Java micro kernel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{87DE8A1A-96C5-4420-B222-EF998F697CE7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{87FD640A-158F-48AC-FD14-1597F14A9778}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|3443734
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{892B9CC3-70DB-4E90-B57B-07A8AABB0A86}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{894C0068-46AC-4F59-A140-EDE0DABA776C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{898E02AB-9372-4a2c-9C4A-FFE1AF61097F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{8A041F13-A111-12A3-B0CF-F99818AA68A8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{8A2B5714-1F9B-4843-B131-FC191AF30758}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{8A6A5B34-D995-4C5D-9338-B5E264B4A87}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{8AD0F1B1-990D-4F52-A33D-2837E43CEF58}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{8BEE6B12-EDA7-4111-8EE5-0947236AE4AC}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|jvsoft
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{8C41B7F7-3168-400D-A702-0E7EFE0BA304}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|360rptt
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{8C8D1401-A58D-A81C-CD24-A5915C4517C8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{8C8DA92A-857A-4B76-9688-BFDADEAAF495}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{8C954872-1230-6541-9548-6541025884C8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{8CEBFDC0-A57C-429D-8510-0E5E01AD6907}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{8CEEE744-30B0-4100-B016-46913B889857}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{8D10FD9A-5715-48BE-9835-EA19947D281E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{8D79D9C6-D210-476A-82B7-5D9113A40CE3}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{8E3526E3-F160-437B-9095-46A011877CBE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{8E6D4583-0FA1-41B2-BAAA-63352E6333CA}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|kasa
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|360Safebox
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{8E772993-0DF1-44B8-AAC9-1FF4ABAF8AD0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{8E97DB95-ED1B-408C-9454-02FC9990C148}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{8EE9AFC0-F04E-4501-8225-06F107566FE8}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{8EF8F90E-15AD-4C22-B3B8-74A0BBEF0B77}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{8F67E146-FB6C-418F-9FE5-37AA2206D92E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{90872CA9-A763-43B9-A6BA-A8B5B17CEBC2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{910A5582-4F7C-42A4-A070-0C91A1E68085}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{912F6837-CCB6-424B-BC9C-8BB5541AFB54}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{91954FAC-1023-154F-895A-1458258AD819}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{91AA45D0-4D9E-4EC4-ABAE-AE30F7FCCD3D}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|360safelr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|kaso
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{91C7DF6D-AEF5-4136-9252-AF030D7A5931}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{91CFF913-BADF-44FC-9C44-5CC06F8696C1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{91F5C9DB-ACD1-4812-BAB9-6F5AE433930A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{92E496B3-2E80-4FE0-B6F8-B3308BB6BFB9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{92EB19C4-F0F1-4D18-A3BC-59658F64F8EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{93001DB8-F229-43F3-B533-9F546F1AD1EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{9319A1F1-9410-9654-3201-345FFA349139}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{93B5C837-F80A-4337-924D-3A96D853C5A8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{93DA1E7D-7C46-4F90-8674-EC90511FCA72}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|361kary
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{93DEE065-EC9B-4505-ADD3-19880AD3C38F}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|kava
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{93EC6B33-16B4-4110-BBC1-8B4A20E321C5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{93EE42EA-B0DD-48A3-98DF-DF1C1E9D8988}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{93F33500-527E-4E33-AECA-69B15243A90E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{945550DE-6D41-4182-854F-34C64F648131}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{950D1600-DE4A-448D-93B4-7BAE5A7A8052}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{96F14DB0-A8F3-4334-BC67-89C51B609DF4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{9726072A-8039-4958-B609-565CF7A16B38}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{9731FA19-8C71-4763-85EA-BB64CDE11D8E}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|36Osafe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{97972049-FB05-4A90-A600-FE5EB197F76B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{97A32646-10D8-4EC8-8248-A27FAB047D79}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|23126487630441956625169149732448
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|kavo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{97FD640A-158F-48AC-FD14-1597F14A9779}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{98283B12-E35B-4051-86EA-1EE682FB369E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{984FD966-B303-4CD8-8A6C-8D70E6B1F1E2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{9867A72A-B1F0-4AD8-BC4B-1E1065B85E13}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{98C57570-8CC3-489E-8CF5-3EE644500681}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{997B14DD-E2D1-4FAA-A17E-DC4F64F8EBFC}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|3config
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{99F71232-CFE3-42BD-BAEE-3E69D233A4C3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{9AD1DE62-196C-4C01-9A2F-0BEDEF727C59}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{9B0D4EA5-8A3A-410E-A1A9-FB87FCAACF13}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{9C20D654-5AF8-4DB7-A125-1A17D7065C73}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|keep remote
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{9C7A2EA9-A168-4157-A3E6-7E47A248E204}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{9CA963CA-107C-4089-B0AB-31380F90D7E3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{9E325A3C-2B26-4CDB-9E40-9713C2788F89}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{9E8287B0-0F3A-48ae-99C5-A6E0AAC36BC5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{9F41E4F0-DCA2-4D4E-A51C-0CC593B5CF03}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|3PMmUpdate
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{9F684DE8-3E87-4174-9033-E02A3DFD8B61}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{9FC3AD52-875C-4FF9-AA4E-5A6D86D4A0B4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A0113412-4022-4B59-97FE-2DBD8D710394}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A024A926-B807-40B7-A94A-CD62D76DA0D1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A0C86020-5935-4B87-B20E-0B656D450264}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|kerne11
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A1954FAC-1023-154F-895A-1458258AD81A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A1A6BC2E-C6A1-43C1-8884-A31D772F42B8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A22390A5-4FDD-4366-B9ED-D2AB728E220A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A23CA53C-731F-4033-92E8-C1DFB4E71D34}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|smss32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A272F097-E24C-4A6E-8BCD-8C42839CE8DE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A2BCFCEE-C939-433F-A32A-7353A6E720DB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A2C3BA54-DF75-4881-8EB3-E54B26BBBBC9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A33B53E3-404C-481D-8F9C-33E416E9D865}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A3822D97-2330-4A3F-94C1-381E37D46BED}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A3C95A74-638D-4C6B-A856-4B27664A7F47}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|King_pg
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A3D8CA41-41ED-405C-8BC0-65E99BE834CF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A43BFB0E-BF1B-47E3-8A7A-53FB4E1104FF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A4A419B3-D0D5-4E1D-AE79-91CF9E920B99}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{F8E45003-3AAB-4F7C-AF06-725A2559E55B}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|46C61D
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A5076382-B8B0-4396-A5A7-9F48FFC8549C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A55F538E-9E65-4706-9458-852BF6592063}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A5CA6C70-7185-4466-AB45-B1C34E7A37CA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A600E212-2A41-41BC-92F1-ED5C96B06185}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A629FF4F-ACDB-5C90-A098-FACB3456A26A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A6B7F435-38B4-4DCC-9EBF-21C968ECF4FD}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A6C1FDD5-04DF-4707-A74B-92BB9D8A8F68}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|king_tw
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A761BE8E-C15A-4DDD-A777-2C683E9E96C8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A7CD6B0D-0EB7-4476-BEA7-167E39744C66}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|4916624932413
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A7EBD59A-2438-41D6-B8A9-788300588DFF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A81EBFD7-0FA3-41ec-B60D-6DAE78B4D31A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A85363C1-CAB1-4999-A0D6-4951BBF69BE8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A8FC611B-71F6-4B4D-BD3A-BFBCCDE96F57}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A93061FE-464A-4E95-8E96-A54CD948B0F7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A95083BE-3D1F-4C7E-ACCC-EC11EA9D498A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A9895933-6636-4281-BC58-EE6DE2AF96E3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A9A7AE50-34D8-4726-B32F-7EDA5FDC6079}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|king_za
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{A9BCD26B-9EFB-4718-A9DB-67A61DB76C77}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|4creator
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{AA0A58A6-5C1A-4CAA-9BCD-C2486C202073}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{AA2D2E20-4CBD-4AB2-B2B6-B356214DA8D0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{AA546010-1611-4616-920B-5D2D11965050}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{AA59145F-315D-BC23-AC1F-145DF81A34AA}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{AA6B979A-796F-452A-94B3-DF1F17B72031}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{AB1912D5-04C9-46C3-9810-C91D388C9534}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{AB52A9B4-A995-4FA4-A11F-6178F0E61BBA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{AB6C5D1A-EF31-49E6-9ACC-BAD329EA8D38}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{AB8105BD-1B1B-40F3-8D3D-65FD7FC68CC5}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|kmmsoft
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|4FDA54
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{AB900155-F1F0-4165-9E73-67BC13BBCE89}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{ABD0935D-B35A-47BD-BA9A-81678DDE74DD}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{AC6F3D84-3433-4FCB-B445-3DE0C97D50EB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{AC6FC642-201F-4397-B6E6-29276AD0A60E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{ACADABAE-1101-0010-8001-00AA006D2EA8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{AD11A17C-83C2-4121-89C8-D0660555685C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{AD2F1493-F26E-4E37-908D-4A33A31FA708}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{AD56A0C8-8EDF-406E-AB5C-94498074CEC9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{AD66F7EB-BC9B-40CF-B5D3-3F535BB8D675}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{AD862DC6-37FA-4D56-B7EA-59C2522A5FC4}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|625B57
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|KrMS5wpauYa
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{AE8813B0-61B3-4F6D-8F9A-7AF223E2C46E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{AEB6717E-7E19-11d0-97EE-00C04FD91974}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{AEB6717E-7E19-11d0-97EE-00C04FD91975}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{AF05A291-7249-4C15-B212-3E8D8C02438D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{AF235511-A3CA-4AF6-BA10-C2D229B8A01B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{AF976DCD-754F-4ac2-BE49-951DC7AA57D2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B01DED18-9E26-4F33-B373-F59758747AFF}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B03A4BE6-5E5A-483E-B9B3-C484D4B20B72}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B051DBDB-8B9E-4FB1-B04A-67FC0A5DF427}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|66012139987
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B058B02A-AC93-4FBA-900B-FA44D9B92805}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|kxswsoft
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B05A92B0-F7B0-4E5B-884E-3D5FB2D4552A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B0ADE25F-5283-4EB7-84E6-45C6A02995A2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B10C1202-2D2A-43C3-A230-9D67F927BE18}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B1998CE2-AAF2-4225-8D03-19F68509ACFD}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B276D18F-E1AB-4674-A559-B267CF550B0D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B3721C07-62B3-411A-9DC7-F5F27E3E21FF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B397CED2-0688-40DA-B136-90D7E8209CDB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B3A1AAFC-C934-4DB5-86C6-B8C03FCC1C63}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|670113362038
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B41816C9-9511-40C3-BAE7-F8208E9677AF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B4262617-467C-43DB-9B2D-C32739E5AA14}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|lhwqld
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B490415F-65F8-B5C5-D8BA-9405FB12054B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B523D3D0-AF5C-4A25-9FBA-5243B231BFAA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B629FF4F-ACDB-5C90-A098-FACB3456A26B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B6C3510F-2666-496B-A46F-6EEFD6328C2B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B6E23E89-C925-4BF7-92EB-77EFDF8C58A6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B778645D-B2A0-48E5-8E43-04B02CA3EA9D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B7D21764-31A1-4B15-B975-8AAA398CE07F}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|682435872112
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B7D59563-AD35-4D2B-B174-7A61A0BC829B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B7F1BFDC-4B6C-4E2F-AF7A-638D2D47802C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B82E7FC1-A1BC-48ED-A977-53BAD6207AA5}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|24yO5072
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|libor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B8898C49-7B3A-4306-A9EF-8E186EDEE5EA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B955C012-E3E8-4777-86CB-73CC15890D29}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{B9D0F4D7-C809-4C27-9CB4-63201DFB3D05}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{BA16C151-EC27-4917-BA64-D9A1E0B74B75}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{BA73DD0D-D9F9-420F-B53F-E19115A6C385}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|685932861400
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{BA7EDF54-8408-4B21-B351-7B447B344BA4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{BB136BA5-D1A5-4BD4-AC72-CAA9CB8EF992}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{BB4C402F-882A-4526-8C08-51278EA437C1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{BB4E3499-0132-4d3f-849A-2BE1B26D84E1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{BBC92FBA-9F43-4938-8716-62D17E1A1617}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|LowRiskFileTypes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{BC0F0A98-380F-4399-989E-737AE006CEBF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{BC2E065D-C5AB-49A7-80E7-A23E45C5CDF1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{BC8975EB-DD3E-406A-8DF9-218848C3B594}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{BCDC783F-C3C3-426D-BB84-4F13C8B573D0}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|691518911700
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{BD07AE7E-DB9C-4FFB-BD21-99DCC8434610}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{BD0DE545-9C56-4A2C-86E7-03DD0EDA6E48}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{BD233082-E412-4667-BE66-5C9FEBB719C8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{BD344AF4-67AB-4E19-A630-7435587D320B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{BD75B192-6840-453B-AE28-2B4B548645B6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{BDEC641B-8B04-4F94-9294-9F589E02CFFB}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|m02w2mop
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{BE12C98F-645D-4566-B524-DC32040B7C8A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{BE6661FD-2DA8-4E8A-B614-7322D4604DC3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{BEA5B04E-545C-4386-89FD-5BB1CC5426C8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{F93CB274-12A2-489E-9DB6-BAAF492448D0}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|Sound
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{BEC8A03E-2E55-445A-97F3-03905BEAB07E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{BEE17DA4-AF94-4D82-8A8D-CF61D73AF94D}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{BF0E569A-6E3D-4744-9B7D-D9E9946BFB4B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{BF576861-D001-4651-9C77-BCA1F6615982}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{BF5AEF56-7C4B-4816-8541-C371182B531C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C00B4190-B46C-4A97-9E44-4532D12BE1B4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C01A46D2-5397-4087-90DD-F44F207F7642}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|MalwareRemovalBot
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C10D41C6-4D17-4808-87CE-40612862A1BB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C1B34818-3883-4A0A-9665-189A8A39EAB0}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|699047678387
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C1CB394D-CECE-440B-9381-838D36862DE2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C20C5A13-4DD7-40D9-90B4-700BAB0BBBE9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C225280D-48C9-4CFA-B167-BBD91A534E29}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C250CF20-5F89-4310-9854-4BC261FB14FB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C286ECE5-AC84-4B89-A219-38B876C739F2}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C28925ED-EBF5-4FEE-B829-B518B4CB2E10}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C34865A9-79AE-4D44-A0AB-E623F3705442}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C34AAB30-15BF-465C-8477-E47850780BFB}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|mmva
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C362D1C3-313C-41C8-A0C7-45458CD8D9A9}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|6AFDCC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C3919446-AF54-44AE-9CFB-CEF0AB35A3C1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C3E75763-F9C7-4868-8502-81F11B41D943}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C3F79FB7-475D-4A84-9E00-8F3570B7C26B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C490415F-65F8-B5C5-D8BA-9405FB12054C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C4D2CCF4-F674-48C7-9F89-F150DF63CCAE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C4E6B319-8C65-4016-8689-39ED0537D0CC}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C52678A5-AC8A-4327-BCB3-6DA940945747}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C53C1999-1B56-41BD-8F76-520D618F112C}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C5470A7F-BDF2-4D97-847B-6AA97ADCF91A}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|Mon
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|6F7365
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C5CB6C70-7185-4466-AB45-B1C34E7A37CA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C5F43BEF-CE2F-46D8-AFE6-A647BACD1F09}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C5FC2AAE-C21F-4CDF-8E3C-3FE421118A1B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C60BC4DF-4CAB-4F66-ABED-D3FCCE7910AD}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C68250B5-364B-43B4-B62D-E95B9E52CD44}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C704DA21-F1A7-46B8-9BDC-50E506198AE3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C722AD57-35DA-4460-8353-328372F32AB2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C73C94FF-8E84-45BB-A81E-D47833D9B302}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C74B750A-3C70-4AB5-8749-2B864A9116DE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C74EB933-C198-4F49-A63B-17DCCD4E36BB}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|727496
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|Monopod
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C7AF807A-C1C5-436C-AB05-4E45B837007D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C85CB78B-8D31-4C27-8533-149683423BF7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C89E2A42-268E-4BEC-8EAB-EAC55D58EAF6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C8EB51BC-82D8-4018-8678-5A0580DBA04A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C9EACC3E-25D3-41D9-8575-410FD86DD685}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{C9EC9A56-C939-4B5A-A12E-FCFF02579770}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{CABA599D-5089-4865-9420-E41FA3C1F55F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{CADB02D0-5722-4BE6-9CB6-5CE88E31E165}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{CB661471-055A-4C5B-9ED0-497B9908FEF5}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|74BE16
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{CB6E79AE-29CC-4082-A190-525D3C4A5233}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|mserv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{CBF4E071-9785-4507-A09C-652C2862E3B9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{CBF8A83B-543B-485C-8D43-4B2529A326F1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{CC0EC2C9-432D-4DCC-91E7-A7C5CEA748D8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{CC48391C-3696-49B9-9293-9F69C28AB3C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{CC80F0B4-04D7-44D0-8DB9-9109B5B72141}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{CCCA2FB9-2D5D-4481-8BFE-1CDDC458A3F4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{CD1779C2-CFD3-46FD-8139-A454565E447D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{CD478099-014D-4B3A-A4BB-B518F1019BC7}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|76470-OEM-0011903-00288KA
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{CD8D6EBD-22BB-4ACF-8AF2-737305B879A2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{CD95107F-52A5-42A4-9914-18949993E798}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|MSFox
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{CE38B9E6-AF0C-4B93-AFAB-A20C2311FFD0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{CE6C2B2F-B590-4EA1-9A44-5100596D7EAF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{CEBB8F8A-308B-43E9-9789-B6FD6BE1BD97}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{CF2C613A-A0D9-4E5C-B1BB-6B03B269B054}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{CF526160-CAC2-4560-AD0C-20C8D88CA4FA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D047C24E-876B-43BC-8373-5E7BE9BA9C35}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D0B7E0F1-4A38-4ACC-B3ED-5C552BDBE512}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|78A16F
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D1C8CCFB-D10B-45A6-B9E4-1D717B0D4FC2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D1CC9DC6-F0BC-40fc-9552-E497B05E05B8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D23B0004-30E2-4BDB-B53A-7E9041308C36}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|msiexecs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D251FE2F-DD5C-4828-85F7-9E7EABB6DD6F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D2CCC364-CA20-4581-B6E3-7EBE086DCF27}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D3112B69-A745-4805-874E-ABD480EA1299}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D36A1DF7-6582-4160-B925-59A34E39FE30}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D3CD6983-551F-4CD8-B48F-FABEB7DE8F3D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D468BE53-03E2-4294-8967-CB67C9990F1B}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|842F0D
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D495FADF-2A7C-4A62-A50E-D6FD9DF6FD9D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D50D4C49-4140-4E22-8EE7-821D2EF0E4EE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D5141C2D-A732-4627-AC14-D5B54121A941}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D59D2B84-7851-4B10-BA14-4125D8EB86BF}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|2u3zc6vv
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|MSServer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D6129F8A-6F6E-41D7-BBC9-AC7426759CED}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D64374E8-8B1D-49AB-9284-5072687B6BD3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D7019B3B-ABF8-4D55-AB50-95A110373D54}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D72860C5-2C7E-4C8C-B1C9-F6803BEB09E4}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|84352E
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D7C79813-9233-4AE0-832C-99B2E8019673}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D806ABA9-CFCF-4100-B914-B8A067EDB967}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D82C0336-583E-468B-B46A-0897FAB9D5A2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D889BF1A-EDD5-4C1D-A3B7-434F4918E7C9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D8CC4845-441C-44F8-9053-28F2EF67655B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D90E7FF1-3BA4-469D-9345-86888D174D79}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|msword98
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D91BC61E-7D78-4A2A-A336-7B97E8E52F0B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D9735121-5627-4697-A2B0-DAB75D6595FF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D9C002DD-EA51-43A2-9009-54EAAAF031A4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{FA281E7B-905D-4565-964B-1F3A61F39873}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|8B8BA3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D9D0D8CF-0C6F-403B-8D57-DFB685C55B6A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{D9EA901D-EE31-419C-8DD0-7E4B804C8CF3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{DA112397-5376-4E52-A333-A85284658DEA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{DA63E650-537C-4042-87BB-9D19D844680B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{DAA9A840-0BB3-4706-9160-C5BF58D79C31}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{DAF11377-E995-4BDE-9561-FE28E14734B9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{DB1D3240-C22E-434D-9D34-D1FC6C68D93F}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|MyWebSearch Email Plugin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{DC7596CB-D6CC-DCA3-DE52-DEEA63F6C61D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{DCBC4DF7-09A8-42D0-BCF4-299F72F40EAD}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|SpyEmergency
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{DD1F3EAC-D200-4D70-B846-7A272C0A7867}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{DD247050-3EA7-43D1-88DB-8C79E8E3F04F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{DD696DC3-7803-4750-8EFC-C10F6D900D2A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{DD8B4357-BF3A-469A-BFBF-16EB6A591799}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{DDFDCED2-075A-4910-986E-B2BDA2B0E916}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{DE02F764-C51A-4788-9597-D78ECC2AC08F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{DE43F05E-1CE8-4B5D-A8C3-982437642A1C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{DE64EA3B-53E5-461D-96B1-38A8BBD36ED2}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|Net
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{DF12F8AB-9A00-469C-B9D4-425C1BE3E1E6}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|904174051500
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{DFB3DAC5-B0B5-4B05-BFCF-FB42737778FA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{DFEAF1AB-1B26-4ACF-A97A-BEF452ACBB4F}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{DFEC5CB7-E2AA-4B0A-BEB3-D140E59ED53A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E035AC3D-B5A8-43A7-9944-8BB333A90D2A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E03C23BD-35B7-49C2-BBCA-6D8CEC2507E3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E0528BDA-C850-4F23-93E4-7F907C1EF30E}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E0D39066-96D7-4891-8527-488ADAFCD60F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E0F3526A-4165-4589-80CD-50B6FBAC3BDA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E11FB24A-F766-4D0F-ADF5-237958FFA262}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|netview
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|93555D
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E1384213-0948-4A60-A9E3-875B191CC2E7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E14DEE75-D635-47E6-9963-D907AA030ED9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E16EA4C8-040B-4A12-A0F5-783963AD665D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E3019869-0038-49F8-B8CF-4170728210F1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E30AFD4A-110D-4FD6-A698-EE9D2BD98C7A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E3367679-4775-4244-A62E-4CFE58FC850B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E3531A16-FFEA-416F-82DF-32FEDE02EABF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E3789A02-334D-43C9-AA31-6152094BA26B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E3BE119A-F7B9-4E82-9D41-C4B8C8166190}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E44343AD-3605-4282-AC8F-2E41C2F5F398}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|96355776
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|PersonSecurity
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E45C0FF6-B170-43B2-B897-6D02C43A2E18}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E46276C8-FA5E-489E-A78E-5182B652E5C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E4814792-EFA3-4C20-93D0-8B130A59F9A8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E4CC0B6B-93B1-4766-AE5E-3FE89FD6DD6F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E53443AE-A4E2-4218-A938-3EB1032FCE20}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E5608703-D625-410D-B97E-6AB2D40D1A9F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E58B05EE-6CA5-42E1-A0CE-82169DDEE42C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E59C8BDA-489C-47EC-8967-A33C6A730B10}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E6243EB4-6253-4F95-866C-C3F58B3D2BEB}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|97A03D
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E75B29ED-F3D2-46D8-9EF3-B088068CB58C}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|PHIME2006ASyn
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E762D574-B60E-4160-B417-4788469ECB3E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E7ABF01D-9B5C-40C1-85BB-3EAEDEAB46A5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E88AE11C-26DF-4F4D-8726-C043F513990E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E8908346-8B0A-4EE3-8AEE-84502544688F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E8A3B193-77E3-4FB3-986D-F4FA4828BAFC}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E912513C-22DA-4200-BB9D-4D36BB294B22}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E918A05E-0FC7-4077-8ED4-ED1D6CEC0E8A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E952B8F8-D91A-4EDD-851C-EE1A0F944469}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|98313586
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{E996F10E-FCAF-41CC-94C8-B8BF7D6F80AC}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{EA25F4E7-8B67-452A-B9DD-B38C526250D3}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|pikachu
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{EA3AB1EA-AF0A-42A9-BB49-B0386462A036}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{EA44A26D-DDC8-46C0-AFE1-A529FE014E3F}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{EA4D8F95-8F2E-4658-A234-E8F4C9AC21C5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{EA5D4B0E-B8CE-4761-8C7E-5D26369F0EC6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{ea5fb64b-1ca5-4939-a93a-9e76234b0a67}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{EB0691E5-E6F5-4FAC-BAEC-FE6C960FFC56}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{EB34007A-BD36-43DD-89FF-7A8C8538FFBB}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|A025A3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{EB5D4E06-B487-4150-A19B-08B6F50F7BA5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{EB6650FB-DAF5-4EEE-BBF7-19006A5B99A3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{EB71E0B3-E97D-4D30-8733-E28266467617}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|PK Services
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{EB965722-E1B1-4098-9DE5-D9CE34110DCE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{EB9660D8-E1CD-4ff0-B4A9-00CD907F928A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{EBD2EAD0-88A7-477C-9664-BC42F1CDC312}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{EBE50EA1-89C8-463A-998A-69A05ECD2D26}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{EC1E8459-B93E-4D9E-9D58-A2263C95E9F7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{ECC00636-8C3B-4D8D-B271-AAA6DF9505CD}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ACD5BDE5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{ECC8E4BF-44DE-4B8D-A591-80845E6A7863}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{ECD35E39-F399-40DF-8B88-005C7A4B0ABF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{EDFF29C1-5A70-4460-AC1D-16DCB4B672F0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{EE1CCAC2-F78B-4CB6-80F8-58DB08F87F8E}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|postsos
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{EE4CEE03-3174-43FC-99D6-A435EF5A9D64}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{EE9EBB5C-5B4C-48d3-8BDD-0EDBF4F720B4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{EF20A659-32BA-4A38-BECD-4CC2F3089C0A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{EFBF72E3-4A08-40B1-8B93-44171A960791}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{F01CD512-AE66-45BD-B182-EED2D68E9FA2}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ActiveSMART
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{F03905AC-469B-4617-A984-44F245F29981}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{F0930A2F-D971-4828-8209-B7DFD266ED44}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{F1455861-8C40-4095-ABD8-7BEAE5ADF92E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{F181F067-7046-4DCB-993F-200990736305}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{F2319AD4-D519-45AC-86A7-02FE9B851F37}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|360Safetask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{FA50E57C-6924-4C03-B325-9A0172C9E8BA}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ader_sl
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|adsnds32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|SpywareRemover
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Advanced DHTML Enable
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|AE31E6
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|aewordpad
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|afksdfks1
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|agiexplore
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|akgkagaksad9
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ALG
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{FA9B58AA-6759-4C02-B37F-572FC2F1A231}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|alsched
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|alupgrade
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Anti Trojan Elite
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|sunny
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Antivirus Pro 2009
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Antivirus Pro 2010
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Antivirus System PRO
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|apadslasla13
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|aplerestarter
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|arextloader
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{FB628720-6493-4AD5-AD46-AEF90A005475}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Artcrl
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|asdsaxcxz13
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|asfkafsk4
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|asgfdjs2
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|54dfsger
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|supervisor.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|askasdkcl3
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|aslgflsdakgsl1
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|aslkgadlkgsl1
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ASocksrv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{FB62C72B-F6A0-44DE-8332-4C18AEB26CF7}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|auncher
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|aunchgtaiv
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|aurealjbox
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|autochk
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|av_md
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ave2pc_light
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|svc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|avgnt
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|avwordpad
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|axwinword
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{FB7247A4-5F09-472F-961B-68F7645EBE9E}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|azinetwiz
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|bagfwlive
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|bcf84c06
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|BeatTrojan
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|beupdaterinstallmgr
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|bgmonitor
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|bhmigrate
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|SVC Service
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|bisetup
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|bmfloppyme
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|qoqtx
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|bnwavpack
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|bogekum
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|brastk
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|braviax
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|brmsaccess
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|brwdiag
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|bugreport
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|buscanpst
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|svchost
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|buwmpnscfg
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{FBA9B4CB-D3B1-44C8-8555-AF65C7929222}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|bwp
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|bypxhpinst
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|C:\WINDOWS\system32\kdxor.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|C:\WINDOWS\system32\realplayerupdate.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|c052e8a5
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|c3config
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|C85880
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|C9395B
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Camera Detector
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|SVCHOST.EXE
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{FBF3B337-FEB6-403B-BBE2-2B67CB6563E3}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|cao
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|caoni
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|casarestore
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ccc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ceasplnchr
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|cfaubroker
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ckidriver2
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|cktmbmsrv
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ckupgrdhlp
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ckupnp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{FBFAD3A6-0B1E-4122-9C2B-92A4623875EC}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|syncman
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|clauncher
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|close surf mail dupe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|cnpartin
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|CnsM.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|CnsMin
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|coinetwiz
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|config
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Configuration Loader
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Copic Tilevb
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{FC769E66-3862-4F80-A24D-E2F1EA7260D8}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|couquar
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|syssafe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Cpl32ver
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|CPMbfcb7f9a
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|cqbx
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|crplxvb07b8hst89fwjo
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ctfmon.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|D70895
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|dasa
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|daskaskfsak6
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|Programadmin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{FC8F4603-4AB2-4A0D-B17F-886CC8AAAFD2}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|daskgfkkcx15
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|dateisetup
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|system tool
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|dbghelp
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|DC6_check
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|debug2
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Defy Inside Proc Heart
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|desetup
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|devenv
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|dfprevhndlrshim
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{FCA4D3BE-C6C7-4F4D-9CBD-CB2666647ACA}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|displaycmd
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|djoemig50
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|dllhost
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|t2jDx9PgC
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|dlregform
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|dlscanost
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|dnb89fhh62nd8fj62
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|dnb89fhh63nd8fj63
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|dnb89fhh64nd8fj64
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|dnetnwp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{FCC4B6C0-5959-4664-B1C6-2B86F5136B63}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|dnwmpnscfg
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|dobeupdatecheck
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|dowsxp-kb918997-v6-x86-cht
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|dsadlsa14
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|tasa
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|dsevos
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|dsfg45fj
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|dsjjowsadm
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|duexcel
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|dwgrun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{FD301436-732E-4F47-8DA0-FBD8720C1E0B}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|dyunrar
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ealsched
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ealtrimmer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|eamoc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ebhrtzzm
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|60140468987395858545925099031990
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|taso
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|EC43F6
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ecmplayerc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ED0BA5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{FD428244-8EE5-4155-95DF-B07E8C304A39}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ediainfo
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|edsetlang
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|eeditor
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|eewordpad
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|egui
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|encoder
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|eomso7ftps
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|tasoft
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ep2k_certd_bc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|epsmon2k_8AFE14174D4B473F91405AB5D95D27B3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{FDE7B169-1290-4543-AF4E-0583CFE8367E}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|erimepadsv
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|eropatentactivation
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|erovision
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ERS_check
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|etection
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|evnerolive
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Ex
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|export
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|tava
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Eyazevipej
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|Quickbar
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|faslkakj11
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|faubroker
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|fbmstordb
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|fc5fd0d1
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|fcompinstaller
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|fdggd
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|fgBatchDL
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|fhsuimain
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|filelink
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|tavo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{FE8B267E-D504-4FA8-AC3C-3214C27C5A5F}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|filelinkconfig
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|fimepadsv
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Firevall Administrating
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Firewall Administrating
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|fjsetup
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|forupdate
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|fplatformcomsvr
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|fpmsinfo32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|fprevhndlrshim
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|fqfrontpg
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{FEF08182-D075-403A-8117-C894067EC79D}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|tprncqict
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Framework Windows
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ftbckgzm
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ftpqlaunch
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|fysa
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|fzg
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|gadkgak12
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|gajklgasjlkga
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|gbatchdl
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|gbhpfxicm
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{FEF265AC-5A25-4A5C-8736-CBB14AEC3BE7}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|gdrecode
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|update
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Generic Host Process for Win32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|gfptedit32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|giwssqpcsvmzhyguv
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|gkaossvc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|glecrashhandler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|gleupdate
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|gnchkrzm
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|gqscanpst
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{F49C475D-5651-4A94-B289-9953F9248EF9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{FF3E3C08-0ACE-4730-AD5D-E07370B62CB3}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|grmcdlc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|gsmimo
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|UpdateWin
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Gtwatch
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|gvpqboot32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|gxowsrmadm
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|gyfypu
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|gzoemig50
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|HBService
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|HBService32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{FFAE967F-D0FC-4D2B-A0F5-D1BF27F46418}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|helper.dll
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|hesrutil
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|hgsetup
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|urlspace
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|hhinetwiz
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|hhmdllhost
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|hiimccphr
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|hmhqfgftjp
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Home Antivirus 2010
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|hp32_nword
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{FFBA5A4F-CDD2-439E-902B-81AAAFDAD3EC}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|hqdqe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|hqmiccal
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|hunderfw
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|hunderservice
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|userini
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|hvcplutl64
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|hy
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|hyimecfmui
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|hyppstream
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ibpqpe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|}1DBD6574-D6D0-4782-94C3-69619E719765}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ictureviewer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ihnbsftp
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|iiunrar
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ijdialer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ilelocksetup
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|userinit
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ilicwconn1
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ilortgdg
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|iluqcwr
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|IME
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|38093456-9012-4568-9076-908765467183}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|IME_JPUpdate1.1
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|indowslivesync
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|inetsrv
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|info sect setup online
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|infsykum
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|install
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|6444da34
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|VirRL2009
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|instasp
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Internat
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|_1
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Internet Connection Wizard Setup Tool
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ioautoup
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ionlinesetup_111111
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|iounins
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|iqsuimain
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|isture
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ivcoverdes
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|J?e?VnR?吭?+:\Program Files\ISTsvc\istsvc.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|ViRsLab
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|j0jnw3iri9s76qq
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|9
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Java
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|jbgonline
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|jbjrjrjb
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|jfmsqry32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|jhidriver
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|jiahus
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|jmnvrtnv
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|jojj99jwq62nf8feh62
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|jojj99jwq63nf8feh63
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|VirTrigger
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|qyfyatii
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|jojj99jwq64nf8feh64
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|jqlssrvc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|jts3
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|jtsa
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|jtwmencagt
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Jugs Surf Inter Media
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|JVM0.14
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|kasa
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|kaso
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|kava
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|Alcmtr
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|waults
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|kavo
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|kbsetlang
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|kcpatch
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|kd25tray
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|kdwordconv
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|kqnero
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|krdw15
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ksgonline
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|kterne
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|b97b
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|KVMON
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|wblogon
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|kvunrar
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|kvwinzip32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|kwicwtutor
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|l.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ladxsetup
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|lasassf
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|lasuassf
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|lbmso7ftps
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{F4AEB826-71B5-4496-B79E-146897B8064F}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|Beanfun
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|lbugreport
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ldmsacnv30
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|Windows Management
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ldmsimport
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|lerestarter
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Lexmark_X79-55
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|lgameboot
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|LicenseMan
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ljahv
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|llhost
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|ccsnahh
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|lnoniesvr
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|load
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Love default global mess
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|Windows SP2 Update Manager
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|lphcc5vj0en7c
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|lphcv1cj0el40
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|lsass
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|LTT2
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|lvmsoicons
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|lvofflb
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|Cisvc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|lymstore
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|lypeer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|m02w2mop
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|madonemivo
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|WindowsUpdater
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|mar
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|mbcwriter
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|mdllhost
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|mHotmon
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|mhsa
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|ClipSrv
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Microsoft Update
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Microsoft WinCheck
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Microsoft Winsock
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Microsoft WinUpdate
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Microsoft(R) System Manager
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|winexecs
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|MicrosoftMail
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|MifS
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|mkrgsc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ml
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|CmSTP
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|mldtpro
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|mmchcfg
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|mnmsaccess
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|mnsa
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|mobiswing
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|mosetup
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|winlegon.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|mpdssm
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|MPKrnl
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|mpproflwiz
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|compmgmt
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|mrghykh
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|msexe.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|MSN Host
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|MsnLiveMessenger
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|MSServer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|mssrv32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|mstranscoder
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|74982737623934399585426522712816
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|wow64main.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|msword98
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|ComRepl
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|mtvwizard
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|mvdw20
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|mx
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|mxtintlphr
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|My Web Search Bar
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|My Web Search Bar Search Scope Monitor
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|MyRuna
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|MySQL
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|MyWebSearch Email Plugin
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|wowsos
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|config.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|MyWebSearch Plugin
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|mzptedit
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ncpeer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|nderliveud
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ndexstoresvr
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ndowsxp-kb918997-v6-x86-cht
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ndpinball
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Net
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|net64
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|netc
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|reader_s
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|wsctf.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|netfx35setup
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|netinstaller
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|netsv32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|netw
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Network Translation Service
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|netx
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|netzip
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|New Value #2
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Newsvalue
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|ctfmon
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ninstall
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|www.adult-collection09.net
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|njuqrtau
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|nkmsoxmled
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|nmoffprov
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|nntimidity
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|noniesvr
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|nrfinder
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|nrmsimport
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|nstall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{F51EE66E-8F35-41EB-AC93-9A0B973F7C04}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|ctfn
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ntaossvc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ntdll.dll
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|XP Antivirus
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|NVIDIA driver monitor
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|nvikernel
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|nvscsvs32s
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|nvsucvs32s
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|nypqlaunch
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|nzpqlaunch
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|nzscanpst
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|DF
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|obsubstrip
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|odb
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|odby
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|ytyvmi
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|odectweaktool
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|oeicwtutor
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ogleupdaterservice
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ok
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|okclview
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|oklssrvc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|DllHst
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|oogdsmux
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|oogleupdate
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|opatentactivation
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|osidrivert
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|YVIBBBHA8C
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|otfixdownloader
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|oticwconn2
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|otnetinstaller
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ototypef
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|otypuqsjfwaylg
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|dlmcjjcefc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ouuninst
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ovision
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|oypatcher
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|oypeerconf
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|pdate_taiwan
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|zoorfat
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|pdateisetup
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|pdater
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|photfixdownloader
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|pjhypertrm
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|dlnajjbdfa
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|PK Services
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|pkmstordb
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|plbckgzm
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ploice
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|plxmpboot
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|pmiw4sp
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|zzjmnjdl.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|pp
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|PPHIDPAD
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|pps
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|DXDLG32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|pqolreg
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|prevhndlrshim
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|PromoReg
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|proxy
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|psgame_silent
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|pstreamsetup-update1204
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|puninst
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce|vcbbjf
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|puuleadweb
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|pvuimetool
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|Esent Utl
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|pwicwtutor
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|pxexcelcnv
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|pygfwlive
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|q550cpwp
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|q7j67jpn64gtrh65hj64
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|qdunzip
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|qedw15
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|qjsa
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|78242387273157472208786549514510
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce|Winsock2 driver
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|IEudinit
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|qlunzip
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|qm
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|qpose
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|qQ
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|qqs3
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|qrdialer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|qrmsaccess
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|qsclview
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|qumigrate
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|qvwmccds
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|kcodu
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices|hfdtubvnx
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|qwuphclean
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|qyasplnchr
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ragonica
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Rainmeter
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|rashreporter
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|RavTray
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ravuusee
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|razclientm
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|rbmcdlc
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|RealAV.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|rbsetup
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices|UpdateWin
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|rcunwise
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|rdassist
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|reader_s
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Regedit32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|RegistryMonitor1
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|RegistryWm
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|restorer32_a
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|restorer64_a
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{F543B043-E9F5-4438-B89A-94E2BDF40B7D}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|kcomc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|rintingdialog
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|rioemig50
HKEY_CURRENT_USER\Software\Microsoft\W不好易indows\CurrentVersion\Run|msword98
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Rising
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|rit
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|rlicwtutor
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|rmhpfiui
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|rocheck
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|rogadgetcmserver
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ropatentactivation
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|kcomd
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|rorescueagent
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|rosearchadvanced
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|rotoolbarcomm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|Taskman
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|rotoolbarupdate
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|rs32net
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|RsTray
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|rudwtrig20
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|run31
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|run40
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|kvtrwkcc.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|runonce
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|runrestart
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|runsql
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|rvertool
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects|{296AB1B8-FB22-4D17-8834-064E2BA0A6F0}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|rxsa
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|rynbdraef
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|rysoundman
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ryy
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|s3_1.7.9.002003_from_1.6.6.002003
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|leng5
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|s3_update1.6.6
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Safe32Test
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|SafeSys
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|SafeTest
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|sakdasj6ksd5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects|{6E28339B-7A2A-47B6-AEB2-46BA53782379}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|sakdasksd5
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|sassinscreed_launcher
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|SCMTool
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|sdebugconfig
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|llajyn_df
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Seagull Drivers
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|SeekmoOE
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|SeekmoSA
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Services
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|servises
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Setwallpaper
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler|{C4560D12-CE25-4A2E-A5D4-B5070FCBE282}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|sfsetup
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|shell
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|siounins
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|lljyn_df
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|SiZhu
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|slive.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|SmartToolBar
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|smeviewer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|smss32.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|snp2uvc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|snuvcdsm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{00180018-0018-0018-0018-00180018BB15}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|somkvmerge
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|SoundMIN
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|Logman
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|SoundsMan
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|SP00.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Spooler SubSystem App
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|SpySpotter System Defender
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|spywareguard
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|sremove
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ssassinscreed_dx10
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|SSER
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{0086DD39-EB8E-4504-A085-AC8A433E34D0}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Startwd
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|maineyucst
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|sticwrmind
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|stoolbarinstaller
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Stupid Data Dart Wave
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|svchost
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|svchost.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|svchosts
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|swdtpro
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|syncman
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|sys32_nov.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|87lhgq83t
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|ming9bstart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{009BBA18-D7A2-456A-AE04-EB9ABF822FE4}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|sysgif32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|sysldtray
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|system
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|System Service Manager Device
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|system.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|systemk
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|SystemMgr
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|SystemSafer.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ta_ep32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|Mousie
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|taacecnflt
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{00A18A60-D7A2-456A-AE04-EB9ABF822FE4}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|TabletWizard
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|tasa
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|taskman
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|taso
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|tava
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|tavo
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|TBMExe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|tcppsap
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{F65BDEC7-4BF3-4512-840F-68B166B6D7AC}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|restorer32_a
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|tdeviewer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|TE_RegProtect
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{00B0B983-9D74-49BF-9C14-46788179446F}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|teemm386
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|temsmsgs
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|temtunermain
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|test.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|tewmplayer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|tfasplnchr
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|tfffmpeg
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|Mousiexp
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|tfimepadsv
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|tgfloppyme
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|tgnwcdex
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{00F22189-C504-46BB-983A-E6FD66609F0A}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|TileFree
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Tinue
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|tlgspot
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|tlsa
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|tmiedw
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|tmnero
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|Mousiexp1
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|tosnapviewer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|totypef
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|tpdrvmap
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|tprncqict
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{00F5A942-E883-4899-BD2E-1B6F926757E7}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|tqmsohelp
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|TrialReset
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|TrojanScanner
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|trsetup
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ttwavtoasf
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|MPMKrnl
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|tunbcore
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|tureviewer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|tvgogobox
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|tvwizard
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|two city internet heck
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{0189BBFC-930D-49A2-A268-CEDBB4A0A3A0}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|txgtaiv
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ufvtidb
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ugreport
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|uihrtzzm
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|MSDCG32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|UIUCU
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ukregform
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ulcdqsp
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|underliveud
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|uoltgmckoxnhejm
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|uosetup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{01AFE3DC-2242-436E-9B44-6DD1C664E828}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|update.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|updateisetup
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|updater
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|MSDEG32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|UpdateWin
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|uqautoup
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|userini
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Utayedul
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|utcfgwiz
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|UTD
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|utsetup_wm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{01C52313-FF03-413E-A148-665C199D3279}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|uydw20
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|uzsetup
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|MSDHG32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|vaahv
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|vapqpe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|vbicwrmind
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|vbiw4sp
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|vbpqboot32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|vdicwconn2
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Vistadrv
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|viunpack
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{021F087F-4378-545F-74FA-37D345AD7A8C}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|vlc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|MSDMG32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|vlhsupdate
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|vlshvlzm
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|vmdetdhc.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|vmhpfsched
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|vmoffdiag
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|vnwmccfg
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|vqrswwr
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|vtmsaccess
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|vusetup
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{0220FBE7-F757-4C74-B246-D6703DCF1087}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|MSDOG32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|vvmstore
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|vwizard
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|vxnwcdex
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|vyicwconn2
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|waults
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|wawabmig
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|wcbtinint
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|wcsetup
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|wdmon
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|wdsa
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|MSDQG32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|88921812731037105478170770096398
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{02845FCC-2BF4-4191-888D-18030FAA2074}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|wdwmpshare
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|websx
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|weicwconn2
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|wesetup
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|wgsa
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Windows DLL Loader
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Windows Image Viewer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Windows Rundll  Center
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{F6A454AE-156A-415E-9F89-3795677A8A91}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|MSDSG32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Windows Rundll Center
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Windows Services
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{028A997C-4262-4107-BD46-2ABBC6143E8C}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Windows SP2 Update Manager
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Windows System Configuration
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Windows Tasks Manager
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Windows UDP Control Center
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Windows Update
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Windows Update Manager
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|WindowsHive
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|restorer64_a
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|winhost
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|WinHosts
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Winsock2 driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{02D83959-FAB9-4FCA-9A14-B71E4C1753F1}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|WinSysW
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|WinUpdate
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|WinWZSys
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|wizowa
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|WL
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|wlsa
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|MSDWG32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|WMedia32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|wmivmipse
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|wmivmipsrv
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|wmsa
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{0306438F-7E67-4DDA-8EF2-C0AD040FEBE0}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|wnloader
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|woocob
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|wos3
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|wosa
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|wotisspwiz
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|MstInit
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|WowUSBSecurity
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|wrmonitor
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|wsconfg
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|WService
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|WSVCHO
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{038AEFD0-22F5-407F-9C49-8CC52462356D}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|wubrandsn
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|www.lady-impact.com.html
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|x3
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|xamplayer2
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|Mstsc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|xcxdsaa7
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|xecnfnot32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|xhupgrdhlp
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|xkufadvlog
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|XP Antispyware 2009
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|XP-1F108B00
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{03F8FE45-1FE0-4C6E-8E6F-D210867F5446}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|XP-282641C7
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|XP-2966CE79
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|XP-3FF170B6
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|mydoc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|XP-6FC6613F
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|XP-9F4C18E8
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|XP-9F4C18E8.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|XP-BCF77097
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|XP-D41D8CD9
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|XP-D8F9930F
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|xportcontroller
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{04A76FFF-1AEF-456D-8E42-2862DF3CB62A}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|xpzclientm
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|xruninst
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|mysys
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|xrwordconv
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|xswzsepe32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|xtanigen
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|xtdrvmap
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|xvsfxfe32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|xwatmaf
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|xwnbcore
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|Xyodovonegifopan
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{05AD2E16-C6EF-6AC1-136A-CE3FD8EF5613}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|xzkadsfk10
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|nmzy_df
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ygpqboot
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|yitidopugu
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|yjpqmagic
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ylauncher
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|YNTUMS_A.EXE
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|yosetup
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|yoshvlzm
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|yrrwnkb
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ysoutlook
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{06EA0A93-F850-4155-B819-BD0D9B5F25EE}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|nwiz
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|yt8a
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ytclview
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|znconvert
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|zndpbpim
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|znsetup
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|zopqbw
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|zpasplnchr
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|zqmsohtmed
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|zts3
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|ztsa
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|pksetexd.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{072DC5A3-0EF5-42C8-AF3A-52D74BC3CBE6}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|zumspub
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|zxexe.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|zzGBK
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|耛AaAA?浴a
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|瑞厒荌弝
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run|電子流氓兔
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce|a0hj3z6emk
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce|Adobe Reader Speed Launcher
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce|BaiduInstall

Modify specific registry values
HKEY_CLASSES_ROOT\Drive\shell||none
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN|CheckedValue|2|REG_DWORD
HKEY_LOCAL_MACHINE\Software\Microsoft\windows\CurrentVersion\explorer\Advanced\Folder\Hidden\SHOWALL|CheckedValue|1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL|CheckedValue|1|REG_DWORD
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks|{AEB6717E-7E19-11d0-97EE-00C04FD91972}|
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows|AppInit_DLLs|
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|Shell|Explorer.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Hidden|1|REG_DWORD

Disable specific device
ROOT\LEGACY_19B5406\0000
ROOT\LEGACY_9CQ81OAO\0000
ROOT\LEGACY_OSOGV\0000
ROOT\LEGACY_00018855\0000
ROOT\LEGACY_OVSSA\0000
ROOT\LEGACY_PCICTRL\0000
ROOT\LEGACY_pcidump\0000
ROOT\LEGACY_PCSCFW2\0000
ROOT\LEGACY_PCXAB\0000
ROOT\LEGACY_PCXYQ\0000
ROOT\LEGACY_PRESAFE\0000
ROOT\LEGACY_PROSAFE\0000
ROOT\LEGACY_9FD8DB\0000
ROOT\LEGACY_PWUAISEAKXAZTTQ\0000
ROOT\LEGACY_PXYZQ\0000
ROOT\LEGACY_00015BB7\0000
ROOT\LEGACY_000189BC\0000
ROOT\LEGACY_QABOP\0000
ROOT\LEGACY_QQQQQRRR\0000
ROOT\LEGACY_QTFRO\0000
ROOT\LEGACY_QUTMDSERV\0000
ROOT\LEGACY_qutmipc\0000
ROOT\LEGACY_QWESXCFVGBY\0000
ROOT\LEGACY_ABOPX\0000
ROOT\LEGACY_RABPCX\0000
ROOT\LEGACY_RAPSYS\0000
ROOT\LEGACY_RAPZQ\0000
ROOT\LEGACY_REGSAFE\0000
ROOT\LEGACY_000189CC\0000
ROOT\LEGACY_RESSDT\0000
ROOT\LEGACY_RFCLT\0000
ROOT\LEGACY_RUNTIME\0000
ROOT\LEGACY_RUNTIME2\0000
ROOT\LEGACY_S3CHIPID\0000
ROOT\LEGACY_0001849C\0000
ROOT\LEGACY_SCHSYS\0000
ROOT\LEGACY_SDRFGTYH\0000
ROOT\LEGACY_SK9OU0S\0000
ROOT\LEGACY_smrkbdd\0000
ROOT\LEGACY_SPYEMRG\0000
ROOT\LEGACY_00018A2A\0000
ROOT\LEGACY_SYS_COM001\0000
ROOT\LEGACY_TCPZ\0000
ROOT\LEGACY_TDDI\0000
ROOT\LEGACY_TSEBN\0000
ROOT\LEGACY_ABP470N5\0000
ROOT\LEGACY_TSP\0000
ROOT\LEGACY_TSRIDE\0000
ROOT\LEGACY_TZDAELY\0000
ROOT\LEGACY_UDHWGXXS\0000
ROOT\LEGACY_UKQHN\0000
ROOT\LEGACY_UPDATEDATA\0000
ROOT\LEGACY_00018A97\0000
ROOT\LEGACY_UQHQ\0000
ROOT\LEGACY_USBMOUSEB\0000
ROOT\LEGACY_UYHGVFDC\0000
ROOT\LEGACY_ABPBP\0000
ROOT\LEGACY_VDUDB\0000
ROOT\LEGACY_vgadrv.sys\0000
ROOT\LEGACY_VVGOP\0000
ROOT\LEGACY_WAODJ\0000
ROOT\LEGACY_WEEBE\0000
ROOT\LEGACY_WMISVC\0000
ROOT\LEGACY_WMPOBJ\0000
ROOT\LEGACY_00018AF5\0000
ROOT\LEGACY_WYDDQLM\0000
ROOT\LEGACY_XAYZPQA\0000
ROOT\LEGACY_ABPCX\0000
ROOT\LEGACY_XCDFVBGT\0000
ROOT\LEGACY_XFNIR\0000
ROOT\LEGACY_XHHCSVHWWFNDU\0000
ROOT\LEGACY_XPUXVJTK\0000
ROOT\LEGACY_XRYQA\0000
ROOT\LEGACY_XTRAPD12\0000
ROOT\LEGACY_XTRLJ\0000
ROOT\LEGACY_XX\0000
ROOT\LEGACY_00018C7C\0000
ROOT\LEGACY_XYQRA\0000
ROOT\LEGACY_ACERNBM\0000
ROOT\LEGACY_XYQRAP\0000
ROOT\LEGACY_XYQXY\0000
ROOT\LEGACY_XYZQA\0000
ROOT\LEGACY_XYZQO\0000
ROOT\LEGACY_YCVIBFVF\0000
ROOT\LEGACY_YOKKBE\0000
ROOT\LEGACY_YOKLVJDP\0000
ROOT\LEGACY_YQFPRHQR\0000
ROOT\LEGACY_YQRAB\0000
ROOT\LEGACY_00018C9B\0000
ROOT\LEGACY_ACPI24DRV\0000
ROOT\LEGACY_YQRABP\0000
ROOT\LEGACY_YYDRBGPV\0000
ROOT\LEGACY_YZQABO\0000
ROOT\LEGACY_ZLOGUWZP\0000
ROOT\LEGACY_ZQBNYVY\0000
ROOT\LEGACY_MPKSL5D04B853\0000
ROOT\LEGACY_MPKSL75CB81FE\0000
ROOT\LEGACY_MPKSL834FA970\0000
ROOT\LEGACY_MPKSLC81D2729\0000
ROOT\LEGACY_00018CF9\0000
ROOT\LEGACY_ACPI32DRV\0000
ROOT\LEGACY_00018D66\0000
ROOT\LEGACY_00018E41\0000
ROOT\LEGACY_000175F6\0000
ROOT\LEGACY_00018E7F\0000
ROOT\LEGACY_00019006\0000
ROOT\LEGACY_0001914E\0000
ROOT\LEGACY_00019258\0000
ROOT\LEGACY_00019332\0000
ROOT\LEGACY_000193CF\0000
ROOT\LEGACY_0001941D\0000
ROOT\LEGACY_000182E6\0000
ROOT\LEGACY_ACPI64DRV\0000
ROOT\LEGACY_00019517\0000
ROOT\LEGACY_000195B3\0000
ROOT\LEGACY_0001967E\0000
ROOT\LEGACY_000179EE\0000
ROOT\LEGACY_0001969D\0000
ROOT\LEGACY_0001971A\0000
ROOT\LEGACY_00019862\0000
ROOT\LEGACY_000198B1\0000
ROOT\LEGACY_0001997C\0000
ROOT\LEGACY_00019DB2\0000
ROOT\LEGACY_ACPIDISK\0000
ROOT\LEGACY_00019EBB\0000
ROOT\LEGACY_00019ECB\0000
ROOT\LEGACY_00019F58\0000
ROOT\LEGACY_0001A2A3\0000
ROOT\LEGACY_00018085\0000
ROOT\LEGACY_0001A35F\0000
ROOT\LEGACY_0001A3CC\0000
ROOT\LEGACY_0001A514\0000
ROOT\LEGACY_0001A69B\0000
ROOT\LEGACY_0001AED8\0000
ROOT\LEGACY_ALCWDRV\0000
ROOT\LEGACY_0001AF55\0000
ROOT\LEGACY_0001B5BE\0000
ROOT\LEGACY_0001B5CE\0000
ROOT\LEGACY_0001B8CB\0000
ROOT\LEGACY_0001BDDC\0000
ROOT\LEGACY_00018121\0000
ROOT\LEGACY_0001C04D\0000
ROOT\LEGACY_0001C1E3\0000
ROOT\LEGACY_0001C60A\0000
ROOT\LEGACY_0001C752\0000
ROOT\LEGACY_ALIIMZ\0000
ROOT\LEGACY_0001C7CF\0000
ROOT\LEGACY_0001C83C\0000
ROOT\LEGACY_0001C86B\0000
ROOT\LEGACY_0001C8AA\0000
ROOT\LEGACY_0001CADC\0000
ROOT\LEGACY_0001CCF0\0000
ROOT\LEGACY_0001816F\0000
ROOT\LEGACY_0001CCFF\0000
ROOT\LEGACY_0001CD5D\0000
ROOT\LEGACY_0001CDF9\0000
ROOT\LEGACY_000184DA\0000
ROOT\LEGACY_0001CE18\0000
ROOT\LEGACY_0001CEA5\0000
ROOT\LEGACY_0001D126\0000
ROOT\LEGACY_0001D183\0000
ROOT\LEGACY_0001D1B2\0000
ROOT\LEGACY_0001D25E\0000
ROOT\LEGACY_0001D2FA\0000
ROOT\LEGACY_000181FC\0000
ROOT\LEGACY_0001D387\0000
ROOT\LEGACY_0001D404\0000
ROOT\LEGACY_ANOKO\0000
ROOT\LEGACY_0001D4C0\0000
ROOT\LEGACY_0001D53D\0000
ROOT\LEGACY_0001D7EC\0000
ROOT\LEGACY_0001DA2E\0000
ROOT\LEGACY_0001DD5B\0000
ROOT\LEGACY_0001DE84\0000
ROOT\LEGACY_0001EAE7\0000
ROOT\LEGACY_0001F085\0000
ROOT\LEGACY_00018269\0000
ROOT\LEGACY_0001F1CD\0000
ROOT\LEGACY_ASDCFVGTYUAM\0000
ROOT\LEGACY_0001FA0A\0000
ROOT\LEGACY_000223E9\0000
ROOT\LEGACY_00022E59\0000
ROOT\LEGACY_000238D9\0000
ROOT\LEGACY_00023E86\0000
ROOT\LEGACY_0002400C\0000
ROOT\LEGACY_00024154\0000
ROOT\LEGACY_00025A0D\0000
ROOT\LEGACY_09ACBF9B\0000
ROOT\LEGACY_ASKDTW\0000
ROOT\LEGACY_AXYOQ\0000
ROOT\LEGACY_b06bdrv\0000
ROOT\LEGACY_111111S1RO1S1A\0000
ROOT\LEGACY_B770CA2\0000
ROOT\LEGACY_BAPIDRV\0000
ROOT\LEGACY_BDLAL\0000
ROOT\LEGACY_BEATTROJANHELPERONE\0000
ROOT\LEGACY_BFSDRV\0000
ROOT\LEGACY_00018529\0000
ROOT\LEGACY_BOPXY\0000
ROOT\LEGACY_BPCXY\0000
ROOT\LEGACY_BUCMLSGQ\0000
ROOT\LEGACY_C362051765\0000
ROOT\LEGACY_360SelfProtection\0000
ROOT\LEGACY_C6424110\0000
ROOT\LEGACY_CA99D57\0000
ROOT\LEGACY_CAUKV\0000
ROOT\LEGACY_CFSJP\0000
ROOT\LEGACY_CITY\0000
ROOT\LEGACY_CO_MON\0000
ROOT\LEGACY_000185C5\0000
ROOT\LEGACY_CVCBHYJHGBVGFREDFRTGFVBGTYHGBHG\0000
ROOT\LEGACY_CVMVB\0000
ROOT\LEGACY_CXOPX\0000
ROOT\LEGACY_3dd78e68\0000
ROOT\LEGACY_CXYQR\0000
ROOT\LEGACY_D7B49FA\0000
ROOT\LEGACY_FGHCYUAQU\0000
ROOT\LEGACY_FILAR\0000
ROOT\LEGACY_FILPP\0000
ROOT\LEGACY_FRJNVCZ\0000
ROOT\LEGACY_FTVFK\0000
ROOT\LEGACY_00018603\0000
ROOT\LEGACY_FVGTYHJ\0000
ROOT\LEGACY_GAGP440P\0000
ROOT\LEGACY_5102a80\0000
ROOT\LEGACY_GENERIC\0000
ROOT\LEGACY_GLUX\0000
ROOT\LEGACY_GTGFESCW\0000
ROOT\LEGACY_GUARDIAN\0000
ROOT\LEGACY_GVGFP\0000
ROOT\LEGACY_HBKERNEL\0000
ROOT\LEGACY_HCPIDESK\0000
ROOT\LEGACY_IG2GX\0000
ROOT\LEGACY_00018642\0000
ROOT\LEGACY_IRANCH\0000
ROOT\LEGACY_6457AED\0000
ROOT\LEGACY_IRENUMQ\0000
ROOT\LEGACY_IUUNK\0000
ROOT\LEGACY_JATMLANO\0000
ROOT\LEGACY_JGAMEENP\0000
ROOT\LEGACY_JGRNQ\0000
ROOT\LEGACY_JMLQHKTSTQIVC\0000
ROOT\LEGACY_JVQJJ\0000
ROOT\LEGACY_KAVSAFE\0000
ROOT\LEGACY_KLAN\0000
ROOT\LEGACY_000186EE\0000
ROOT\LEGACY_8CNVNI4FRX\0000
ROOT\LEGACY_KOON\0000
ROOT\LEGACY_LSOWX\0000
ROOT\LEGACY_LONGRADRV\0000
ROOT\LEGACY_LXKVN\0000
ROOT\LEGACY_MMQPI\0000
ROOT\LEGACY_MSFPFIS64\0000
ROOT\LEGACY_MSIFFEI\0000
ROOT\LEGACY_MSP2P32\0000
ROOT\LEGACY_MYPROT\0000
ROOT\LEGACY_NSDLRK250\0000
ROOT\LEGACY_8J89L\0000
ROOT\LEGACY_00018836\0000
ROOT\LEGACY_NSPSDK00\0000
ROOT\LEGACY_NSPSDK01\0000
ROOT\LEGACY_NSPSDK02\0000
ROOT\LEGACY_NSPSDK03\0000
ROOT\LEGACY_NSPSDK04\0000
ROOT\LEGACY_NSRK1\0000
ROOT\LEGACY_OPXYZ\0000
ROOT\LEGACY_OPYZQ\0000
ROOT\LEGACY_OREANS32\0000

Remove specific device
ROOT\LEGACY_19B5406\0000
ROOT\LEGACY_9CQ81OAO\0000
ROOT\LEGACY_OSOGV\0000
ROOT\LEGACY_00018855\0000
ROOT\LEGACY_OVSSA\0000
ROOT\LEGACY_PCICTRL\0000
ROOT\LEGACY_pcidump\0000
ROOT\LEGACY_PCSCFW2\0000
ROOT\LEGACY_PCXAB\0000
ROOT\LEGACY_PCXYQ\0000
ROOT\LEGACY_PRESAFE\0000
ROOT\LEGACY_PROSAFE\0000
ROOT\LEGACY_9FD8DB\0000
ROOT\LEGACY_PWUAISEAKXAZTTQ\0000
ROOT\LEGACY_PXYZQ\0000
ROOT\LEGACY_00015BB7\0000
ROOT\LEGACY_000189BC\0000
ROOT\LEGACY_QABOP\0000
ROOT\LEGACY_QQQQQRRR\0000
ROOT\LEGACY_QTFRO\0000
ROOT\LEGACY_QUTMDSERV\0000
ROOT\LEGACY_qutmipc\0000
ROOT\LEGACY_QWESXCFVGBY\0000
ROOT\LEGACY_ABOPX\0000
ROOT\LEGACY_RABPCX\0000
ROOT\LEGACY_RAPSYS\0000
ROOT\LEGACY_RAPZQ\0000
ROOT\LEGACY_REGSAFE\0000
ROOT\LEGACY_000189CC\0000
ROOT\LEGACY_RESSDT\0000
ROOT\LEGACY_RFCLT\0000
ROOT\LEGACY_RUNTIME\0000
ROOT\LEGACY_RUNTIME2\0000
ROOT\LEGACY_S3CHIPID\0000
ROOT\LEGACY_0001849C\0000
ROOT\LEGACY_SCHSYS\0000
ROOT\LEGACY_SDRFGTYH\0000
ROOT\LEGACY_SK9OU0S\0000
ROOT\LEGACY_smrkbdd\0000
ROOT\LEGACY_SPYEMRG\0000
ROOT\LEGACY_00018A2A\0000
ROOT\LEGACY_SYS_COM001\0000
ROOT\LEGACY_TCPZ\0000
ROOT\LEGACY_TDDI\0000
ROOT\LEGACY_TSEBN\0000
ROOT\LEGACY_ABP470N5\0000
ROOT\LEGACY_TSP\0000
ROOT\LEGACY_TSRIDE\0000
ROOT\LEGACY_TZDAELY\0000
ROOT\LEGACY_UDHWGXXS\0000
ROOT\LEGACY_UKQHN\0000
ROOT\LEGACY_UPDATEDATA\0000
ROOT\LEGACY_00018A97\0000
ROOT\LEGACY_UQHQ\0000
ROOT\LEGACY_USBMOUSEB\0000
ROOT\LEGACY_UYHGVFDC\0000
ROOT\LEGACY_ABPBP\0000
ROOT\LEGACY_VDUDB\0000
ROOT\LEGACY_vgadrv.sys\0000
ROOT\LEGACY_VVGOP\0000
ROOT\LEGACY_WAODJ\0000
ROOT\LEGACY_WEEBE\0000
ROOT\LEGACY_WMISVC\0000
ROOT\LEGACY_WMPOBJ\0000
ROOT\LEGACY_00018AF5\0000
ROOT\LEGACY_WYDDQLM\0000
ROOT\LEGACY_XAYZPQA\0000
ROOT\LEGACY_ABPCX\0000
ROOT\LEGACY_XCDFVBGT\0000
ROOT\LEGACY_XFNIR\0000
ROOT\LEGACY_XHHCSVHWWFNDU\0000
ROOT\LEGACY_XPUXVJTK\0000
ROOT\LEGACY_XRYQA\0000
ROOT\LEGACY_XTRAPD12\0000
ROOT\LEGACY_XTRLJ\0000
ROOT\LEGACY_XX\0000
ROOT\LEGACY_00018C7C\0000
ROOT\LEGACY_XYQRA\0000
ROOT\LEGACY_ACERNBM\0000
ROOT\LEGACY_XYQRAP\0000
ROOT\LEGACY_XYQXY\0000
ROOT\LEGACY_XYZQA\0000
ROOT\LEGACY_XYZQO\0000
ROOT\LEGACY_YCVIBFVF\0000
ROOT\LEGACY_YOKKBE\0000
ROOT\LEGACY_YOKLVJDP\0000
ROOT\LEGACY_YQFPRHQR\0000
ROOT\LEGACY_YQRAB\0000
ROOT\LEGACY_00018C9B\0000
ROOT\LEGACY_ACPI24DRV\0000
ROOT\LEGACY_YQRABP\0000
ROOT\LEGACY_YYDRBGPV\0000
ROOT\LEGACY_YZQABO\0000
ROOT\LEGACY_ZLOGUWZP\0000
ROOT\LEGACY_ZQBNYVY\0000
ROOT\LEGACY_MPKSL5D04B853\0000
ROOT\LEGACY_MPKSL75CB81FE\0000
ROOT\LEGACY_MPKSL834FA970\0000
ROOT\LEGACY_MPKSLC81D2729\0000
ROOT\LEGACY_00018CF9\0000
ROOT\LEGACY_ACPI32DRV\0000
ROOT\LEGACY_00018D66\0000
ROOT\LEGACY_00018E41\0000
ROOT\LEGACY_000175F6\0000
ROOT\LEGACY_00018E7F\0000
ROOT\LEGACY_00019006\0000
ROOT\LEGACY_0001914E\0000
ROOT\LEGACY_00019258\0000
ROOT\LEGACY_00019332\0000
ROOT\LEGACY_000193CF\0000
ROOT\LEGACY_0001941D\0000
ROOT\LEGACY_000182E6\0000
ROOT\LEGACY_ACPI64DRV\0000
ROOT\LEGACY_00019517\0000
ROOT\LEGACY_000195B3\0000
ROOT\LEGACY_0001967E\0000
ROOT\LEGACY_000179EE\0000
ROOT\LEGACY_0001969D\0000
ROOT\LEGACY_0001971A\0000
ROOT\LEGACY_00019862\0000
ROOT\LEGACY_000198B1\0000
ROOT\LEGACY_0001997C\0000
ROOT\LEGACY_00019DB2\0000
ROOT\LEGACY_ACPIDISK\0000
ROOT\LEGACY_00019EBB\0000
ROOT\LEGACY_00019ECB\0000
ROOT\LEGACY_00019F58\0000
ROOT\LEGACY_0001A2A3\0000
ROOT\LEGACY_00018085\0000
ROOT\LEGACY_0001A35F\0000
ROOT\LEGACY_0001A3CC\0000
ROOT\LEGACY_0001A514\0000
ROOT\LEGACY_0001A69B\0000
ROOT\LEGACY_0001AED8\0000
ROOT\LEGACY_ALCWDRV\0000
ROOT\LEGACY_0001AF55\0000
ROOT\LEGACY_0001B5BE\0000
ROOT\LEGACY_0001B5CE\0000
ROOT\LEGACY_0001B8CB\0000
ROOT\LEGACY_0001BDDC\0000
ROOT\LEGACY_00018121\0000
ROOT\LEGACY_0001C04D\0000
ROOT\LEGACY_0001C1E3\0000
ROOT\LEGACY_0001C60A\0000
ROOT\LEGACY_0001C752\0000
ROOT\LEGACY_ALIIMZ\0000
ROOT\LEGACY_0001C7CF\0000
ROOT\LEGACY_0001C83C\0000
ROOT\LEGACY_0001C86B\0000
ROOT\LEGACY_0001C8AA\0000
ROOT\LEGACY_0001CADC\0000
ROOT\LEGACY_0001CCF0\0000
ROOT\LEGACY_0001816F\0000
ROOT\LEGACY_0001CCFF\0000
ROOT\LEGACY_0001CD5D\0000
ROOT\LEGACY_0001CDF9\0000
ROOT\LEGACY_000184DA\0000
ROOT\LEGACY_0001CE18\0000
ROOT\LEGACY_0001CEA5\0000
ROOT\LEGACY_0001D126\0000
ROOT\LEGACY_0001D183\0000
ROOT\LEGACY_0001D1B2\0000
ROOT\LEGACY_0001D25E\0000
ROOT\LEGACY_0001D2FA\0000
ROOT\LEGACY_000181FC\0000
ROOT\LEGACY_0001D387\0000
ROOT\LEGACY_0001D404\0000
ROOT\LEGACY_ANOKO\0000
ROOT\LEGACY_0001D4C0\0000
ROOT\LEGACY_0001D53D\0000
ROOT\LEGACY_0001D7EC\0000
ROOT\LEGACY_0001DA2E\0000
ROOT\LEGACY_0001DD5B\0000
ROOT\LEGACY_0001DE84\0000
ROOT\LEGACY_0001EAE7\0000
ROOT\LEGACY_0001F085\0000
ROOT\LEGACY_00018269\0000
ROOT\LEGACY_0001F1CD\0000
ROOT\LEGACY_ASDCFVGTYUAM\0000
ROOT\LEGACY_0001FA0A\0000
ROOT\LEGACY_000223E9\0000
ROOT\LEGACY_00022E59\0000
ROOT\LEGACY_000238D9\0000
ROOT\LEGACY_00023E86\0000
ROOT\LEGACY_0002400C\0000
ROOT\LEGACY_00024154\0000
ROOT\LEGACY_00025A0D\0000
ROOT\LEGACY_09ACBF9B\0000
ROOT\LEGACY_ASKDTW\0000
ROOT\LEGACY_AXYOQ\0000
ROOT\LEGACY_b06bdrv\0000
ROOT\LEGACY_111111S1RO1S1A\0000
ROOT\LEGACY_B770CA2\0000
ROOT\LEGACY_BAPIDRV\0000
ROOT\LEGACY_BDLAL\0000
ROOT\LEGACY_BEATTROJANHELPERONE\0000
ROOT\LEGACY_BFSDRV\0000
ROOT\LEGACY_00018529\0000
ROOT\LEGACY_BOPXY\0000
ROOT\LEGACY_BPCXY\0000
ROOT\LEGACY_BUCMLSGQ\0000
ROOT\LEGACY_C362051765\0000
ROOT\LEGACY_360SelfProtection\0000
ROOT\LEGACY_C6424110\0000
ROOT\LEGACY_CA99D57\0000
ROOT\LEGACY_CAUKV\0000
ROOT\LEGACY_CFSJP\0000
ROOT\LEGACY_CITY\0000
ROOT\LEGACY_CO_MON\0000
ROOT\LEGACY_000185C5\0000
ROOT\LEGACY_CVCBHYJHGBVGFREDFRTGFVBGTYHGBHG\0000
ROOT\LEGACY_CVMVB\0000
ROOT\LEGACY_CXOPX\0000
ROOT\LEGACY_3dd78e68\0000
ROOT\LEGACY_CXYQR\0000
ROOT\LEGACY_D7B49FA\0000
ROOT\LEGACY_FGHCYUAQU\0000
ROOT\LEGACY_FILAR\0000
ROOT\LEGACY_FILPP\0000
ROOT\LEGACY_FRJNVCZ\0000
ROOT\LEGACY_FTVFK\0000
ROOT\LEGACY_00018603\0000
ROOT\LEGACY_FVGTYHJ\0000
ROOT\LEGACY_GAGP440P\0000
ROOT\LEGACY_5102a80\0000
ROOT\LEGACY_GENERIC\0000
ROOT\LEGACY_GLUX\0000
ROOT\LEGACY_GTGFESCW\0000
ROOT\LEGACY_GUARDIAN\0000
ROOT\LEGACY_GVGFP\0000
ROOT\LEGACY_HBKERNEL\0000
ROOT\LEGACY_HCPIDESK\0000
ROOT\LEGACY_IG2GX\0000
ROOT\LEGACY_00018642\0000
ROOT\LEGACY_IRANCH\0000
ROOT\LEGACY_6457AED\0000
ROOT\LEGACY_IRENUMQ\0000
ROOT\LEGACY_IUUNK\0000
ROOT\LEGACY_JATMLANO\0000
ROOT\LEGACY_JGAMEENP\0000
ROOT\LEGACY_JGRNQ\0000
ROOT\LEGACY_JMLQHKTSTQIVC\0000
ROOT\LEGACY_JVQJJ\0000
ROOT\LEGACY_KAVSAFE\0000
ROOT\LEGACY_KLAN\0000
ROOT\LEGACY_000186EE\0000
ROOT\LEGACY_8CNVNI4FRX\0000
ROOT\LEGACY_KOON\0000
ROOT\LEGACY_LSOWX\0000
ROOT\LEGACY_LONGRADRV\0000
ROOT\LEGACY_LXKVN\0000
ROOT\LEGACY_MMQPI\0000
ROOT\LEGACY_MSFPFIS64\0000
ROOT\LEGACY_MSIFFEI\0000
ROOT\LEGACY_MSP2P32\0000
ROOT\LEGACY_MYPROT\0000
ROOT\LEGACY_NSDLRK250\0000
ROOT\LEGACY_8J89L\0000
ROOT\LEGACY_00018836\0000
ROOT\LEGACY_NSPSDK00\0000
ROOT\LEGACY_NSPSDK01\0000
ROOT\LEGACY_NSPSDK02\0000
ROOT\LEGACY_NSPSDK03\0000
ROOT\LEGACY_NSPSDK04\0000
ROOT\LEGACY_NSRK1\0000
ROOT\LEGACY_OPXYZ\0000
ROOT\LEGACY_OPYZQ\0000
ROOT\LEGACY_OREANS32\0000

Collect device list

Collect files in Virus Scan Log
BKDR_Generic.ADV
PE_Generic.Z
TROJ_GEN.0X0312S
Cryp_MEW-11
TROJ_GEN.0X0405
TROJ_GEN.0X0412S
TROJ_GEN.0X2412S
TROJ_GEN.0X2512S
TROJ_GEN.0X2712S
TROJ_GEN.0Z0304
TROJ_GEN.0Z0913S
TROJ_Gen.0Z0958
PE_Generic.ZA
TROJ_GEN.0Z2011S
TROJ_GEN.4X2539
BKDR_Generic.DMS
Cryp_Naix-6
TROJ_Gen.4X2651
TROJ_GEN.4Z0739
TROJ_GEN.7X2418S
TROJ_GEN.7X2620S
TROJ_Gen.8V3000
TROJ_Gen.8X0533
Possible_Asprox
TROJ_GEN.8X2539
TROJ_Gen.8X4033
TROJ_Gen.8X4036
TROJ_Gen.8Z0032
Cryp_Naix-7
TROJ_Gen.8Z0729
TROJ_Gen.8Z0736
TROJ_Gen.8Z0832
TROJ_GEN.9Z0939
TROJ_Gen.BX0239
Cryp_FakeAV-6
TROJ_Gen.BX4078
TROJ_Gen.BZ0869
TROJ_Gen.CX0553
TROJ_Gen.CX07U1
TROJ_Gen.CX46U3
Cryp_Nsanti
TROJ_Gen.CX46U5
TROJ_Gen.CZ00Q3
TROJ_Gen.CZ01I6
TROJ_Gen.CZ01I9
Possible_Bnkr-6
TROJ_Gen.CZ0383
TROJ_Gen.CZ04R0
TROJ_Gen.CZ06K5
TROJ_Gen.CZ0847
TROJ_Gen.CZ0867
TROJ_Gen.CZ0947
Cryp_NSAnti-1
TROJ_Gen.CZ09Q4
TROJ_Gen.CZ09R8
TROJ_Gen.CZ3390
Possible_Crypt-6
TROJ_Gen.CZ33I5
TROJ_Gen.CZ33L1
TROJ_GEN.F43C6K8
TROJ_GEN.F4AB5HA
TROJ_GEN.F4AB5HH
TROJ_GEN.F4AB5HJ
TROJ_GEN.F4AB5HO
Cryp_NSAnti-2
TROJ_GEN.F4AC2HG
TROJ_GEN.F4AE1HD
Possible_DLDER
TROJ_GEN.HC9900
TROJ_Gen.MZ40L8
TROJ_Gen.MZ40P8
TROJ_GEN.PAB181F
TROJ_GEN.PAC011A
TROJ_GEN.PAD291C
TROJ_GEN.PAD291D
TROJ_GEN.PAE121E
Cryp_NSAnti-3
TROJ_GEN.PAF171F
Possible_EncScr
TROJ_GEN.PAF181C
TROJ_GEN.R01B1K8
TROJ_GEN.R01C2K8
TROJ_GEN.R1BC5GD
TROJ_GEN.R1CC2GN
TROJ_GEN.R2CC2GK
TROJ_GEN.R2CC2HC
TROJ_GEN.R2CC2HD
TROJ_GEN.R2CC4H6
Cryp_NSAnti-4
Possible_Fujak-2
TROJ_GEN.R2CE1GD
TROJ_GEN.R2CE1H5
TROJ_GEN.R2FB1GM
TROJ_GEN.R2FB1H5
TROJ_GEN.R2FC2HG
TROJ_GEN.R2FE1HD
TROJ_GEN.R3BB1K7
TROJ_GEN.R42B1K8
TROJ_GEN.R43B1GU
TROJ_GEN.R43B1HB
Possible_Gobot
Cryp_NSAnti-5
TROJ_GEN.R43B1HI
TROJ_GEN.R43C2GV
TROJ_GEN.R43C2H6
TROJ_GEN.R43C2HU
TROJ_GEN.R43C5H3
TROJ_GEN.R44B1H4
TROJ_GEN.R44C2H1
TROJ_GEN.R44C2HD
TROJ_GEN.R47B1G4
Cryp_FakeAV-5
Possible_Hifrm
TROJ_GEN.R47B1GK
Cryp_NSAnti-6
TROJ_GEN.R47B1GM
TROJ_GEN.R47B1GO
TROJ_GEN.R47B1GV
TROJ_GEN.R47B1H1
TROJ_GEN.R47B1H2
TROJ_GEN.R47B1H3
TROJ_GEN.R47B1H7
TROJ_GEN.R47B1HJ
Possible_Hifrm-1
TROJ_GEN.R47B1HU
TROJ_GEN.R47B1K7
Cryp_NSAnti-7
TROJ_GEN.R47C2GQ
TROJ_GEN.R47C2GV
TROJ_GEN.R47C2H9
TROJ_GEN.R47C2HA
TROJ_GEN.R47C2HD
TROJ_GEN.R47C3GD
TROJ_GEN.R47C3H1
Possible_Hifrm-2
TROJ_GEN.R47C3H6
TROJ_GEN.R47C4HN
TROJ_GEN.R47E1HC
Cryp_Bero
Cryp_NSAnti-8
TROJ_GEN.R49B1HB
TROJ_GEN.R49C2GU
TROJ_GEN.R4AB1GO
TROJ_GEN.R4AC2GU
TROJ_GEN.R4AC2GV
Possible_Hifrm-3
TROJ_GEN.R4AC2K8
TROJ_GEN.R4AE1H4
TROJ_GEN.R72B1H3
TROJ_GEN.R80C3G4
TROJ_GEN.RB4B1K8
Cryp_NSAnti-9
TROJ_Gen.RE50B5
TROJ_Gen.RZ3077
TROJ_Gen.RZ3090
TROJ_GEN.UAB251W
Cryp_FakeAV-7
TROJ_GEN.UAB261Y
TROJ_GEN.UAE041U
TROJ_GEN.UAE061V
TROJ_GEN.UAE191Y
TROJ_GEN.UAF021W
TROJ_GEN.UAF091V
Cryp_Nsanti-X
TROJ_GEN.UAF101V
TROJ_GEN.UAF161Z
TROJ_GEN.UAF291X
Possible_Hifrm-4
TROJ_GEN.UAG041X
TROJ_GEN.UAG141X
TROJ_GEN.UAG151W
TROJ_GEN.UAG151X
TROJ_GEN.UAG161V
TROJ_GEN.UAG211X
TROJ_GEN.UAG221X
Cryp_Opet-1
TROJ_GEN.US008T
TROJ_GEN.US019T
Possible_Hifrm-5
TROJ_GEN.US01AT
TROJ_GEN.USE00BF
TROJ_GEN.USE00UF
TROJ_GEN.USE01IF
TROJ_GEN.USE0LJ
TROJ_GEN.USG07MO
TROJ_GEN.USG21MO
TROJ_Gen.XZ09U3
Cryp_Opet-2
TROJ_Gen.XZ33A0
Possible_HPGN-1
TROJ_Generic
TROJ_Generic.ADV
TROJ_Generic.APC
TROJ_Generic.CON
TROJ_Generic.DIF
TROJ_Generic.DIM
TROJ_Generic.DIS
TROJ_Generic.DIT
TROJ_Generic.DMS
Cryp_Opet-3
Possible_HPGN-3
TROJ_Generic.F01
TROJ_Generic.J01
TROJ_Generic.L01
TROJ_Generic.L02
TROJ_Generic.L03
TROJ_Generic.L04
TROJ_Generic.L05
TROJ_Generic.S03
TROJ_Generic.SFB
TROJ_Generic.Z
Possible_Infostl
Cryp_Opet-3_1
TROJ_Generic.Z01
TROJ_Generic.Z02
TROJ_Generic.Z03
TROJ_Generic.Z04
TROJ_Generic.Z05
TROJ_Generic.Z06
TROJ_Generic.Z07
TROJ_Generic.Z08
TROJ_Generic.Z0E
PAK_Generic.019
Possible_Invader
TROJ_Generic.ZA
Cryp_Pai-15
TSPY_ONLINE.DAM
WORM_GENERIC
WORM_Generic.CON
WORM_Generic.DIT
WORM_Generic.Z
WORM_Generic.ZA
Cryp_Pai-3
Cryp_Palevo6
Possible_Legmir
Cryp_Bits
Cryp_PESpin
Cryp_Sinned-1
Cryp_Tap-1
Cryp_Tap-2
Cryp_Tap-3
Cryp_Tap-4
Cryp_Tap-5
Cryp_Tap-6
Cryp_TROJ.A-CN
Possible_Legmir1
Cryp_Upack
Cryp_DownAd-4
Cryp_Vundo-23
Cryp_Vundo-26
Cryp_Xed-1
Cryp_Xed-10
Cryp_Xed-12
Cryp_Xed-13
Cryp_Xed-17
Cryp_Xed-2
Possible_Lineage
Cryp_Xed-3
Cryp_Xed-4
Cryp_FakeAV-1
Cryp_Xed-5
Cryp_Xed-6
Cryp_Xed-7
Cryp_Xed-8
Cryp_Xed-9
Cryp_Xin1
Cryp_Yayay
Possible_Looked
Cryp_Yodap
Generic_Grayware
GRAY_Gen.0Z0251
Cryp_FakeAV-2
GRAY_Gen.4X1851
GRAY_GEN.7Z1118S
GRAY_Gen.CC53S7
PACKER-GEN.001
PACKER-GEN.002
PACKER-GEN.101
Cryp_FakeAV-8
PACKER-GEN.102
PACKER-GEN.103
PACKER-GEN.104
PACKER-GEN.105
Cryp_FakeAV-3
PACKER-GEN.106
PAK_GEN.001
PAK_Generic.001
PAK_Generic.002
PAK_Generic.003
Possible_Looksky
PAK_Generic.004
PAK_Generic.005
PAK_Generic.006
PAK_Generic.007
PAK_Generic.008
Cryp_FakeAV-4
PAK_Generic.009
PAK_Generic.010
PAK_Generic.011
PAK_Generic.012
Possible_MLWR-1
PAK_Generic.013
PAK_Generic.014
PAK_Generic.015
PAK_Generic.016
PAK_Generic.017
PAK_Generic.018
Possible_MlWR-13
Possible_MLWR-2
PAK_Generic.020
Possible_MLWR-24
Possible_MLWR-3
Possible_MLWR-4
Possible_MLWR-5
Possible_MLWR-6
Possible_Movly-1
Cryp_FakeAV-9
Possible_Nucrp-2
Possible_Nucrp-3
Possible_Nucrp-4
PAK_ScramUPX
Possible_Nucrp-5
Possible_Nucrp-6
Possible_Nucrypt
Possible_Obfus
Possible_OLGM
Possible_OLGM-1
Possible_OLGM-11
Cryp_FlySFX
Possible_OLGM-12
Possible_OLGM-13
PE_GENERIC
Possible_OLGM-14
Possible_OLGM-15
Possible_OLGM-2
Possible_OLGM-23
Possible_OLGM-3
Possible_OLGM-4
Possible_OLGM-5
Possible_OLGM-6
Cryp_Fraud-3
Possible_OLGM-7
PE_Generic.ADV
Possible_OLGM-8
Possible_OLGM-9
Possible_Otorun
Possible_Otorun1
Possible_Otorun2
Possible_Otorun-2
Possible_Otorun5
Possible_Otorun6
Possible_Otorun7
Cryp_Krap
PE_Generic.CON
Possible_Otorun8
Possible_Pai-2
Possible_PClient
Possible_PkElib
Possible_Qqhook
Possible_SCRDL
Possible_Strat-1
Possible_Strat-2
Possible_Strat-3
Possible_Strat-4
PE_Generic.DIT
Cryp_Mangled
Possible_Strat-5
Possible_Strat-6
Possible_Swzr-3
Possible_Virus
Possible_Vundo-9
Possible_VundoG
Possible_Zlob
SLIENT_PAK.001
TROJ_GEN.0X0212S

Delete specific files
%ProgramFile%\3721\CnsM.dll
M:\32o3.cmd
M:\af93gcf.exe
N:\ghdf1.com
Z:\h2.com
%ProgramFile%\winsoft9\ie2.exe
%ProgramFiles%\Common Files\Microsoft Shared\MSINFO\rejoice2009.exe
%windir%\evxx.exe
Z:\h2t6u.exe
Z:\h3hi1k3.exe
Z:\h8i.com
Z:\hfap.exe
Z:\higj2p.bat
Z:\hn.cmd
N:\gicchk2s.exe
Z:\hnkvaa2.exe
Z:\host.exe
Z:\hovrflst.bat
Z:\hpkq.cmd
%windir%\ewobis.exe
Z:\hqx292nu.exe
Z:\hsi.com
Z:\hsjnkj.exe
Z:\htjtq8o.exe
Z:\hupxj.bat
%ProgramFiles%\bmi8eilkp\3ff70larq.exe
Z:\hv8fv2.exe
Z:\hvoxmq.exe
Z:\hxbpamjb.cmd
Z:\hxs.bat
Z:\hyj2gunw.exe
%Windir%\expiorer.exe
Z:\i.bat
Z:\i2.com
Z:\ib3qc3t.cmd
Z:\if6ch9k6.bat
%Temp%\ig9p8adh.dll
Z:\ig.bat
Z:\igcmrtjw.cmd
Z:\il0byu3h.com
Z:\il6.exe
Z:\iluqcwr.exe
Z:\imt8.cmd
%windir%\explore.exe
Z:\iok.exe
Z:\ipy.cmd
Z:\iscwam2h.cmd
N:\gmi1jxy.com
Z:\it1d.exe
Z:\iu.bat
Z:\iw.bat
Z:\iwjj.com
Z:\ixsla.exe
Z:\j.bat
Z:\j0.exe
%windir%\extext438220t.exe
Z:\j0mpdkja.cmd
Z:\j1.cmd
N:\gnc.bat
Z:\j16dp6.exe
Z:\j1rxka1n.exe
Z:\j83uv.exe
Z:\jatxgwcj.bat
Z:\jc1r11.exe
Z:\jcmmawa.bat
Z:\jdt2ofp.exe
Z:\jg.com
%windir%\ezojone.exe
Z:\jg6w3yx.com
N:\gnwav.exe
Z:\jhcqxax.exe
Z:\jix9a.bat
Z:\jj2.com
Z:\jkxrox.exe
Z:\jl.com
Z:\jvu69.bat
Z:\jy.exe
Z:\k.com
Z:\k08aww.bat
%windir%\fatycalyk.com
N:\gnwwy.exe
Z:\k2.cmd
Z:\k6wkwon2.exe
Z:\k9cuos2q.exe
Z:\ka1nk.bat
Z:\karina///debeja.exe
Z:\kdy.cmd
Z:\kg18j.exe
Z:\kgnkxc.exe
Z:\kk.bat
Z:\kk36.exe
N:\gplpn.exe
%windir%\fbgfeje.exe
Z:\kk38g1.exe
Z:\kpvqk.exe
Z:\kqsr.exe
Z:\kuqskg2s.bat
Z:\kuruna.exe
Z:\kya6l.bat
Z:\l1.cmd
Z:\l3v.exe
Z:\l6w2eaih.exe
N:\gqsk.bat
Z:\ldgybkp.bat
%windir%\FCARDTax.dll
Z:\lgcadwx.bat
Z:\lgnaqil.exe
Z:\lgrncie.bat
Z:\lgvg8q.exe
Z:\lhwdcgcb.bat
Z:\lj.exe
Z:\lj6hdv.com
Z:\ll.exe
M:\af9rgm8h.bat
N:\gswrij.exe
Z:\lp3c.bat
Z:\lsfjg.com
%windir%\fdh23g.exe
Z:\lsg6jj9.exe
Z:\lskeqbfc.exe
Z:\lulu.exe
Z:\lwd.bat
Z:\lyhwcea.exe
Z:\m.bat
Z:\m.exe
N:\gsxlexd.cmd
Z:\m6dqm2vd.exe
Z:\m6n.com
Z:\m8wafly.com
%ProgramFiles%\Common Files\Microsoft Shared\MSInfo\Server2010.exe
%windir%\fdxx.exe
Z:\m9as2c.cmd
Z:\mayyuk9g.bat
Z:\mbewb2n.exe
Z:\mcmm.bat
Z:\mka.bat
N:\gx.bat
Z:\mm6q.exe
Z:\momo.exe
Z:\motr.exe
Z:\mpstxgx.exe
Z:\mrghykh.exe
%windir%\fezice.com
Z:\mrsne.bat
Z:\msbackup.exe
Z:\msn.exe
Z:\mt.com
N:\gx.com
Z:\mtlhieej.cmd
Z:\n.com
Z:\n.exe
Z:\n1m.exe
Z:\n1v93rqo.exe
Z:\n6j6pc0.com
%windir%\file.exe
Z:\n89f1d1w.exe
Z:\nbke.exe
Z:\ncc.exe
%Temp%\iMSPCLOj.sys
Z:\ndmego0f.cmd
Z:\net.exe
Z:\ngq6hva0.exe
Z:\nmje9v6d.bat
Z:\nncu6kk.com
Z:\nooakkv.exe
Z:\np.exe
%windir%\Fonts\12B71F3A.EXE
Z:\nq.bat
Z:\nqgcd.com
N:\gxul.com
Z:\nskmu.exe
Z:\nsv.bat
Z:\nt6ry3bn.cmd
Z:\ntdeiect.com
Z:\ntdelect.com
Z:\NTDETECT.EXE
Z:\ntnq.exe
Z:\ntphyy.com
%windir%\fonts\16E06CA0.EXE
Z:\nvrfc.bat
N:\gymussy.bat
Z:\nw.exe
Z:\nw0t1l0d.exe
Z:\nxvhpc.exe
Z:\ny36jjt.exe
Z:\nyat.exe
Z:\O.cmd
Z:\o.exe
Z:\o6opnro.bat
Z:\o6pq1n8.com
%windir%\Fonts\237C730F.DLL
N:\h.bat
Z:\o93ml8.bat
Z:\o9o2.com
Z:\o9o2u.bat
Z:\oaljb6.exe
Z:\obg.exe
Z:\obtpf.bat
Z:\oc.cmd
Z:\ocbqsqj.bat
Z:\Oeboyg.exe
Z:\okelg.exe
N:\h.CMD
%windir%\Fonts\24C493E0.EXE
Z:\okhr.exe
Z:\ol.exe
Z:\om.cmd
Z:\om0.com
Z:\op.bat
Z:\ot.exe
Z:\ot2.exe
Z:\otf.cmd
Z:\ox.cmd
N:\h0j8w.exe
Z:\p.cmd
%windir%\fonts\26b294b1.dll
Z:\p0sc9t.cmd
Z:\p1t.bat
Z:\p3r1ud.exe
Z:\p8ihdw.exe
Z:\p9.exe
Z:\pamn.exe
Z:\patp.exe
Z:\pbwkwj.COM
M:\alt.exe
N:\h0ti1de.bat
Z:\pchkh.cmd
Z:\pjben6y.exe
%windir%\fonts\2ec010b.ttf
Z:\pjwtv.cmd
Z:\pkxfkrki.bat
Z:\pllq.exe
Z:\pnc.exe
Z:\popo.exe
Z:\ppinbnp9.exe
Z:\prjydpe.cmd
N:\h2.com
Z:\px.bat
Z:\pxbn6y.exe
Z:\pytnmk.exe
%windir%\Fonts\342787E8.DLL
Z:\q.bat
Z:\q.exe
Z:\q0rppr.exe
Z:\q10js.exe
Z:\q1pady.cmd
Z:\q2.exe
N:\h2t6u.exe
Z:\q2vl2fiy.com
Z:\q83iwmgf.bat
Z:\qb1.exe
Z:\qh.cmd
%ProgramFiles%\Common Files\Microsoft Shared\nqyltsy.exe
%windir%\Fonts\360rptt.exe
Z:\qjatw9aj.exe
Z:\qjfl.exe
Z:\qkarc.exe
Z:\qkolx.exe
N:\h3hi1k3.exe
Z:\qngbvkhl.exe
Z:\qotdyl.bat
Z:\qpe6.com
Z:\qr.exe
Z:\qs6m.bat
Z:\qsid8g.exe
%windir%\fonts\3EFEAF36.fon
Z:\r.com
Z:\r.exe
Z:\r120.bat
N:\h8i.com
Z:\r2mkn.exe
Z:\r8wb.bat
Z:\r9ghv9.com
Z:\rcpi.exe
Z:\rehsas.com
Z:\resycled\boot.com
Z:\rf.cmd
%windir%\Fonts\47F22CC4.EXE
Z:\rjiybg.exe
Z:\rjx0.exe
%Temp%\init.exe
Z:\rmydqsiw.exe
Z:\rn.exe
Z:\rtnlpipu.com
Z:\rv36m1f9.exe
Z:\rwrte.exe
Z:\s2vgyp.exe
Z:\s38k.exe
Z:\s39tg.cmd
%windir%\Fonts\62CA11B1.EXE
Z:\s6.bat
N:\hfap.exe
Z:\s6muem.cmd
Z:\s8.exe
Z:\s9l.exe
Z:\SafeSys.exe
Z:\sasyg1y8.com
Z:\sdc.bat
Z:\se11.cmd
Z:\server2010.exe
Z:\ServerXp.exe
%windir%\Fonts\63C8062F.fon
N:\higj2p.bat
Z:\sh.exe
Z:\shadu.exe
Z:\Shell.exe
Z:\sie2v8.exe
Z:\SiZhu.exe
Z:\slphfx.bat
Z:\sm.exe
Z:\snaoc9i.exe
Z:\SofwareUpdater.exe
Z:\spkr9wou.bat
N:\hn.cmd
%windir%\Fonts\7254C830.EXE
Z:\SRCHost.exe
Z:\SRCost.exe
Z:\stwi.com
Z:\suqfl.exe
Z:\svchost.exe
Z:\svchovst.EXE
Z:\system.dll
Z:\systex.exe
Z:\t.bat
N:\hnkvaa2.exe
Z:\t.cmd
%windir%\fonts\931cd8e.exe
Z:\t.exe
Z:\t1xdgvq.exe
Z:\t2f.exe
Z:\t2jl.exe
Z:\t2ydo.exe
Z:\t3.com
Z:\t82e2v.cmd
Z:\tan3yt.bat
%Temp%\546301
N:\home.exe
Z:\tbhje.cmd
Z:\tcburi.exe
%windir%\Fonts\9322D4F0.EXE
Z:\temp28.exe
Z:\tg.com
Z:\tgtighg.cmd
Z:\thghikva.exe
Z:\tigi.cmd
Z:\tikett.exe
Z:\tj8odymw.exe
N:\host.exe
Z:\tlmjw.cmd
Z:\tmd.exe
Z:\tmf3w3g0.com
%windir%\Fonts\9A285362.EXE
Z:\tmf3w3go.com
Z:\tn.exe
Z:\tn0k.exe
Z:\ts6k.exe
Z:\tt.com
Z:\tudqrfw.exe
N:\hovrflst.bat
Z:\txfl1rhh.com
Z:\tyfr.com
Z:\tyvq.exe
Z:\u.cmd
%windir%\fonts\A0CCA6FD.DLL
Z:\u.exe
Z:\u08.cmd
Z:\u18vxqle.com
Z:\u26ufgv.exe
Z:\u2by.exe
N:\hpkq.cmd
Z:\u3dsc.com
Z:\u63urr.exe
Z:\u6k.cmd
Z:\u82.exe
Z:\u99.exe
%ProgramFiles%\Common Files\Microsoft Shared\Office10\dymso7ftp.exe
%windir%\fonts\A0CCA6FD.DLL.bak
Z:\ud.exe
Z:\ufwi6sq.exe
Z:\uh.exe
N:\hqx292nu.exe
Z:\uh31.exe
Z:\uhjqlk.exe
Z:\un_tc.exe
Z:\uorys.cmd
Z:\up.exe
Z:\up0ppxwr.com
Z:\update220.exe
%windir%\fonts\A97CRaCB.fon
Z:\update2201.exe
Z:\updater697.exe
N:\hsi.com
Z:\UpdateThis.exe
Z:\UpdateWindows.exe
Z:\updds3.exe
Z:\ups.exe
Z:\Ups3.exe
Z:\upsf.exe
Z:\uptes.exe
Z:\upts3.exe
%windir%\fonts\aBwruKPXHdP.fon
Z:\uptsd.exe
%Temp%\Internat.exe
Z:\Upz.exe
Z:\uqb0julr.bat
Z:\us8amqf.exe
Z:\ut.bat
Z:\ut9x.bat
Z:\utcn8c63.exe
Z:\uuhgt.bat
Z:\uwlmj.com
Z:\uxkktr.cmd
%windir%\Fonts\ad7731.exe
N:\hsjnkj.exe
Z:\v0f8rqc.cmd
Z:\v2h3.exe
Z:\v3pif.bat
Z:\v86htgx.cmd
Z:\v9l1l.com
Z:\v9l8.exe
Z:\v9ug2p2.com
Z:\vcf0.exe
Z:\vctio.com
Z:\vd91t29.exe
N:\htjtq8o.exe
%windir%\fonts\adcvpbzn.dll
Z:\vdej3e.exe
Z:\vkrg.exe
Z:\vmhr.bat
Z:\vnkucvv.com
Z:\vp.exe
Z:\vpqdgkx.com
Z:\vt6e.cmd
Z:\w.bat
Z:\w.cmd
N:\hupxj.bat
Z:\w.exe
%windir%\Fonts\aeoha.fon
Z:\w2qagd.com
Z:\w3dn9f.bat
Z:\w6hikrv.com
Z:\w9fc.exe
Z:\wdm.exe
Z:\Webhost2.exe
Z:\webhost4.exe
Z:\Weeiivruved.exe
M:\aluj8r.exe
N:\hv8fv2.exe
Z:\weg6sp.com
Z:\wehds63.exe
%windir%\Fonts\afmom.fon
Z:\wewt425.exe
Z:\wewtf.exe
Z:\wex.exe
Z:\wg0kpd.bat
Z:\wg6jj0.exe
Z:\wglplm6g.bat
Z:\wgp.com
N:\hvoxmq.exe
Z:\Windows.exe
Z:\winhost.exe
Z:\winser.exe
%windir%\Fonts\agfivyhp.dll
Z:\wjlc.exe
Z:\wkcay8u.cmd
Z:\wpkx.bat
Z:\wstk.exe
Z:\wuwu.exe
Z:\wv.exe
N:\hxbpamjb.cmd
Z:\wycgb8.cmd
Z:\wyqrvts.exe
Z:\wyzlo.exe
Z:\x.bat
%windir%\fonts\ahcohvkb.dll
Z:\x.cmd
Z:\x1.cmd
Z:\x1dg.exe
Z:\x1o8uo.exe
Z:\x63rnneh.exe
N:\hxs.bat
Z:\xa8v8.exe
Z:\xadeiect.com
Z:\xc.exe
Z:\xe9fdii1.cmd
Z:\xedex.exe
%windir%\Fonts\alcqyovo.dll
Z:\xene9.bat
Z:\xievhrf.exe
Z:\xjs.exe
Z:\xjv.exe
N:\hyj2gunw.exe
Z:\xnfrqlvf.exe
Z:\xppg3r6.exe
Z:\xpq63xl.exe
Z:\xqg0.exe
Z:\xqyl68.exe
Z:\xue.exe
%ProgramFiles%\Common Files\Microsoft Shared\Office10\eomso7ftps.exe
%windir%\Fonts\amosatzl.dll
Z:\xv.com
Z:\xyh.exe
N:\i.bat
Z:\y.com
Z:\y319s.exe
Z:\y6u.bat
Z:\y9rlqi.cmd
Z:\ydmj.exe
Z:\yfmqo.cmd
Z:\yfpaoty.exe
Z:\ygvtn.exe
%windir%\Fonts\anoko.fon
Z:\yh.bat
N:\i2.com
Z:\yi9.exe
Z:\yjkjfuo.cmd
Z:\ymxf3q.exe
Z:\yp.bat
Z:\ypjq1.cmd
Z:\yq.com
Z:\yq00tht.exe
Z:\yt8a.exe
Z:\yv.exe
%windir%\Fonts\aroqs.fon
%Temp%\iv.dll
Z:\yw6mmv0.exe
Z:\zx.exe
C:\1.exe
D:\1.exe
E:\1.exe
F:\1.exe
G:\1.exe
H:\1.exe
I:\1.exe
J:\1.exe
N:\ib3qc3t.cmd
%windir%\Fonts\avdli.fon
K:\1.exe
L:\1.exe
M:\1.exe
N:\1.exe
O:\1.exe
P:\1.exe
Q:\1.exe
R:\1.exe
S:\1.exe
N:\if6ch9k6.bat
T:\1.exe
%windir%\Fonts\awtxj.fon
U:\1.exe
V:\1.exe
W:\1.exe
X:\1.exe
Y:\1.exe
Z:\1.exe
C:\108i.CMD
D:\108i.CMD
M:\anky8.exe
N:\ig.bat
E:\108i.CMD
F:\108i.CMD
%windir%\Fonts\baueacnq.dll
G:\108i.CMD
H:\108i.CMD
I:\108i.CMD
J:\108i.CMD
K:\108i.CMD
L:\108i.CMD
M:\108i.CMD
N:\igcmrtjw.cmd
N:\108i.CMD
O:\108i.CMD
P:\108i.CMD
%windir%\Fonts\bdlal.fon
Q:\108i.CMD
R:\108i.CMD
S:\108i.CMD
T:\108i.CMD
U:\108i.CMD
V:\108i.CMD
N:\il0byu3h.com
W:\108i.CMD
X:\108i.CMD
Y:\108i.CMD
Z:\108i.CMD
%windir%\Fonts\bkeoxbde.dll
C:\11d9o.exe
D:\11d9o.exe
E:\11d9o.exe
F:\11d9o.exe
G:\11d9o.exe
N:\il6.exe
H:\11d9o.exe
I:\11d9o.exe
J:\11d9o.exe
K:\11d9o.exe
L:\11d9o.exe
%windir%\Fonts\bnfxh.fon
M:\11d9o.exe
N:\11d9o.exe
O:\11d9o.exe
P:\11d9o.exe
N:\iluqcwr.exe
Q:\11d9o.exe
R:\11d9o.exe
S:\11d9o.exe
T:\11d9o.exe
U:\11d9o.exe
V:\11d9o.exe
%windir%\Fonts\bnrdm.fon
W:\11d9o.exe
X:\11d9o.exe
Y:\11d9o.exe
N:\imt8.cmd
Z:\11d9o.exe
C:\12.exe
D:\12.exe
E:\12.exe
F:\12.exe
G:\12.exe
H:\12.exe
%ProgramFiles%\Common Files\Microsoft Shared\Office10\lbmso7ftps.exe
%windir%\fonts\bQgc5yHMSD4yd.fon
I:\12.exe
N:\iok.exe
J:\12.exe
K:\12.exe
L:\12.exe
M:\12.exe
N:\12.exe
O:\12.exe
P:\12.exe
Q:\12.exe
R:\12.exe
%windir%\Fonts\bqhpg.fon
N:\ipy.cmd
S:\12.exe
T:\12.exe
U:\12.exe
V:\12.exe
W:\12.exe
X:\12.exe
Y:\12.exe
Z:\12.exe
C:\15400.exe
D:\15400.exe
%Temp%\jatmlano.sys
%windir%\Fonts\btiyfeea.dll
E:\15400.exe
F:\15400.exe
G:\15400.exe
H:\15400.exe
I:\15400.exe
J:\15400.exe
K:\15400.exe
L:\15400.exe
M:\15400.exe
N:\iscwam2h.cmd
N:\15400.exe
%windir%\Fonts\btsrpbef.dll
O:\15400.exe
P:\15400.exe
Q:\15400.exe
R:\15400.exe
S:\15400.exe
T:\15400.exe
U:\15400.exe
V:\15400.exe
M:\aoutfq.exe
N:\it1d.exe
W:\15400.exe
X:\15400.exe
%windir%\Fonts\burti.fon
Y:\15400.exe
Z:\15400.exe
C:\16onq.bat
D:\16onq.bat
E:\16onq.bat
F:\16onq.bat
G:\16onq.bat
N:\iu.bat
H:\16onq.bat
I:\16onq.bat
J:\16onq.bat
%windir%\FONTS\BVMWWAC9WK.FON
K:\16onq.bat
L:\16onq.bat
M:\16onq.bat
N:\16onq.bat
O:\16onq.bat
P:\16onq.bat
N:\iw.bat
Q:\16onq.bat
R:\16onq.bat
S:\16onq.bat
T:\16onq.bat
%windir%\Fonts\bvpwssxh.dll
U:\16onq.bat
V:\16onq.bat
W:\16onq.bat
X:\16onq.bat
Y:\16onq.bat
N:\iwjj.com
Z:\16onq.bat
C:\19f.exe
D:\19f.exe
E:\19f.exe
F:\19f.exe
%windir%\Fonts\bxuje.fon
G:\19f.exe
H:\19f.exe
I:\19f.exe
J:\19f.exe
N:\ixsla.exe
K:\19f.exe
L:\19f.exe
M:\19f.exe
N:\19f.exe
O:\19f.exe
P:\19f.exe
%windir%\fonts\c1e075e8.exe
Q:\19f.exe
R:\19f.exe
S:\19f.exe
N:\j.bat
T:\19f.exe
U:\19f.exe
V:\19f.exe
W:\19f.exe
X:\19f.exe
Y:\19f.exe
Z:\19f.exe
%windir%\Fonts\C1E075E8.EXE
C:\19kcv.exe
D:\19kcv.exe
N:\j0.exe
E:\19kcv.exe
F:\19kcv.exe
G:\19kcv.exe
H:\19kcv.exe
I:\19kcv.exe
J:\19kcv.exe
K:\19kcv.exe
L:\19kcv.exe
%ProgramFiles%\Common Files\Microsoft Shared\OFFICE12\lvofflb.exe
%windir%\Fonts\caukv.fon
N:\j0mpdkja.cmd
M:\19kcv.exe
N:\19kcv.exe
O:\19kcv.exe
P:\19kcv.exe
Q:\19kcv.exe
R:\19kcv.exe
S:\19kcv.exe
T:\19kcv.exe
U:\19kcv.exe
V:\19kcv.exe
N:\j1.cmd
%windir%\Fonts\ccfmj.fon
W:\19kcv.exe
X:\19kcv.exe
Y:\19kcv.exe
Z:\19kcv.exe
C:\1aq1obb.bat
D:\1aq1obb.bat
E:\1aq1obb.bat
F:\1aq1obb.bat
G:\1aq1obb.bat
%Temp%\jgameenp.sys
H:\1aq1obb.bat
%windir%\Fonts\cejmolco.dll
I:\1aq1obb.bat
J:\1aq1obb.bat
K:\1aq1obb.bat
L:\1aq1obb.bat
M:\1aq1obb.bat
N:\1aq1obb.bat
O:\1aq1obb.bat
P:\1aq1obb.bat
M:\ap.com
N:\j16dp6.exe
Q:\1aq1obb.bat
R:\1aq1obb.bat
%windir%\fonts\CESPVP8FQd.fon
S:\1aq1obb.bat
T:\1aq1obb.bat
U:\1aq1obb.bat
V:\1aq1obb.bat
W:\1aq1obb.bat
X:\1aq1obb.bat
Y:\1aq1obb.bat
N:\j1rxka1n.exe
Z:\1aq1obb.bat
C:\1bg.cmd
D:\1bg.cmd
%windir%\Fonts\cfsjp.fon
E:\1bg.cmd
F:\1bg.cmd
G:\1bg.cmd
H:\1bg.cmd
I:\1bg.cmd
J:\1bg.cmd
N:\j83uv.exe
K:\1bg.cmd
L:\1bg.cmd
M:\1bg.cmd
N:\1bg.cmd
%windir%\fonts\CN28BSk5wje.fon
O:\1bg.cmd
P:\1bg.cmd
Q:\1bg.cmd
R:\1bg.cmd
S:\1bg.cmd
N:\jatxgwcj.bat
T:\1bg.cmd
U:\1bg.cmd
V:\1bg.cmd
W:\1bg.cmd
X:\1bg.cmd
%windir%\fonts\ComRes.dll
Y:\1bg.cmd
Z:\1bg.cmd
C:\1brfrip.exe
D:\1brfrip.exe
N:\jc1r11.exe
E:\1brfrip.exe
F:\1brfrip.exe
G:\1brfrip.exe
H:\1brfrip.exe
I:\1brfrip.exe
J:\1brfrip.exe
%windir%\fonts\comres1.ttf
K:\1brfrip.exe
L:\1brfrip.exe
M:\1brfrip.exe
N:\jcmmawa.bat
N:\1brfrip.exe
O:\1brfrip.exe
P:\1brfrip.exe
Q:\1brfrip.exe
R:\1brfrip.exe
S:\1brfrip.exe
T:\1brfrip.exe
%windir%\fonts\comresx.ttf
U:\1brfrip.exe
V:\1brfrip.exe
N:\jdt2ofp.exe
W:\1brfrip.exe
X:\1brfrip.exe
Y:\1brfrip.exe
Z:\1brfrip.exe
C:\1gia.com
D:\1gia.com
E:\1gia.com
F:\1gia.com
%windir%\fonts\crrp2mDP.fon
G:\1gia.com
N:\jg.com
H:\1gia.com
I:\1gia.com
J:\1gia.com
K:\1gia.com
L:\1gia.com
M:\1gia.com
N:\1gia.com
O:\1gia.com
P:\1gia.com
%ProgramFiles%\Common Files\Microsoft Shared\OFFICE12\nkmsoxmled.exe
N:\jg6w3yx.com
%windir%\Fonts\csxxr.fon
Q:\1gia.com
R:\1gia.com
S:\1gia.com
T:\1gia.com
U:\1gia.com
V:\1gia.com
W:\1gia.com
X:\1gia.com
Y:\1gia.com
N:\jhcqxax.exe
Z:\1gia.com
%windir%\fonts\CTCTq658tW.fon
C:\1i.com
D:\1i.com
E:\1i.com
F:\1i.com
G:\1i.com
H:\1i.com
I:\1i.com
J:\1i.com
M:\atymi09.bat
%Temp%\jtso.exe
K:\1i.com
L:\1i.com
%windir%\fonts\CtZ8uc499k.fon
M:\1i.com
N:\1i.com
O:\1i.com
P:\1i.com
Q:\1i.com
R:\1i.com
S:\1i.com
N:\jix9a.bat
T:\1i.com
U:\1i.com
V:\1i.com
%windir%\Fonts\cvafq.fon
W:\1i.com
X:\1i.com
Y:\1i.com
Z:\1i.com
C:\1irqtv.cmd
D:\1irqtv.cmd
N:\jj2.com
E:\1irqtv.cmd
F:\1irqtv.cmd
G:\1irqtv.cmd
H:\1irqtv.cmd
%windir%\Fonts\cvmvb.fon
I:\1irqtv.cmd
J:\1irqtv.cmd
K:\1irqtv.cmd
L:\1irqtv.cmd
M:\1irqtv.cmd
N:\jkxrox.exe
N:\1irqtv.cmd
O:\1irqtv.cmd
P:\1irqtv.cmd
Q:\1irqtv.cmd
R:\1irqtv.cmd
%windir%\fonts\cxmwmbfa.nls
S:\1irqtv.cmd
T:\1irqtv.cmd
U:\1irqtv.cmd
V:\1irqtv.cmd
N:\jl.com
W:\1irqtv.cmd
X:\1irqtv.cmd
Y:\1irqtv.cmd
Z:\1irqtv.cmd
C:\1jief.cmd
D:\1jief.cmd
%windir%\Fonts\D2C879C8.DLL
E:\1jief.cmd
F:\1jief.cmd
G:\1jief.cmd
N:\jvu69.bat
H:\1jief.cmd
I:\1jief.cmd
J:\1jief.cmd
K:\1jief.cmd
L:\1jief.cmd
M:\1jief.cmd
N:\1jief.cmd
%windir%\Fonts\D4289580.EXE
O:\1jief.cmd
P:\1jief.cmd
N:\jy.exe
Q:\1jief.cmd
R:\1jief.cmd
S:\1jief.cmd
T:\1jief.cmd
U:\1jief.cmd
V:\1jief.cmd
W:\1jief.cmd
X:\1jief.cmd
%windir%\fonts\D7019B3B.fon
Y:\1jief.cmd
N:\k.com
Z:\1jief.cmd
C:\1n.cmd
D:\1n.cmd
E:\1n.cmd
F:\1n.cmd
G:\1n.cmd
H:\1n.cmd
I:\1n.cmd
J:\1n.cmd
%windir%\Fonts\daxud.fon
N:\k08aww.bat
K:\1n.cmd
L:\1n.cmd
M:\1n.cmd
N:\1n.cmd
O:\1n.cmd
P:\1n.cmd
Q:\1n.cmd
R:\1n.cmd
S:\1n.cmd
T:\1n.cmd
N:\k2.cmd
%ProgramFiles%\Common Files\Microsoft Shared\OFFICE12\taacecnflt.exe
%windir%\Fonts\ddijwqom.dll
U:\1n.cmd
V:\1n.cmd
W:\1n.cmd
X:\1n.cmd
Y:\1n.cmd
Z:\1n.cmd
C:\1q8p0y.com
D:\1q8p0y.com
M:\auto.exe
N:\k6wkwon2.exe
E:\1q8p0y.com
F:\1q8p0y.com
%windir%\fonts\DGvbbtCNkQVHR6JNYgc.fon
G:\1q8p0y.com
H:\1q8p0y.com
I:\1q8p0y.com
J:\1q8p0y.com
K:\1q8p0y.com
L:\1q8p0y.com
M:\1q8p0y.com
%Temp%\jxinit.dat
N:\1q8p0y.com
O:\1q8p0y.com
P:\1q8p0y.com
%windir%\Fonts\dmqoa.fon
Q:\1q8p0y.com
R:\1q8p0y.com
S:\1q8p0y.com
T:\1q8p0y.com
U:\1q8p0y.com
V:\1q8p0y.com
N:\k9cuos2q.exe
W:\1q8p0y.com
X:\1q8p0y.com
Y:\1q8p0y.com
Z:\1q8p0y.com
%windir%\Fonts\dndkn.fon
C:\1rexh.com
D:\1rexh.com
E:\1rexh.com
F:\1rexh.com
G:\1rexh.com
N:\ka1nk.bat
H:\1rexh.com
I:\1rexh.com
J:\1rexh.com
K:\1rexh.com
L:\1rexh.com
%windir%\fonts\dotpwrvr.dll
M:\1rexh.com
N:\1rexh.com
O:\1rexh.com
P:\1rexh.com
N:\karina///debeja.exe
Q:\1rexh.com
R:\1rexh.com
S:\1rexh.com
T:\1rexh.com
U:\1rexh.com
V:\1rexh.com
%windir%\fonts\Dpgu7ZKe.fon
W:\1rexh.com
X:\1rexh.com
Y:\1rexh.com
N:\kdy.cmd
Z:\1rexh.com
C:\1sertc.exe
D:\1sertc.exe
E:\1sertc.exe
F:\1sertc.exe
G:\1sertc.exe
H:\1sertc.exe
%windir%\fonts\dPmKwRu3m.fon
I:\1sertc.exe
J:\1sertc.exe
N:\kg18j.exe
K:\1sertc.exe
L:\1sertc.exe
M:\1sertc.exe
N:\1sertc.exe
O:\1sertc.exe
P:\1sertc.exe
Q:\1sertc.exe
R:\1sertc.exe
%windir%\Fonts\dshga.fon
S:\1sertc.exe
N:\kgnkxc.exe
T:\1sertc.exe
U:\1sertc.exe
V:\1sertc.exe
W:\1sertc.exe
X:\1sertc.exe
Y:\1sertc.exe
Z:\1sertc.exe
C:\1wkwxgxw.com
D:\1wkwxgxw.com
%windir%\Fonts\duuyepfl.dll
N:\kjibu.com
E:\1wkwxgxw.com
F:\1wkwxgxw.com
G:\1wkwxgxw.com
H:\1wkwxgxw.com
I:\1wkwxgxw.com
J:\1wkwxgxw.com
K:\1wkwxgxw.com
L:\1wkwxgxw.com
M:\1wkwxgxw.com
N:\1wkwxgxw.com
N:\kk.bat
%windir%\Fonts\dwxutsfw.dll
O:\1wkwxgxw.com
P:\1wkwxgxw.com
Q:\1wkwxgxw.com
R:\1wkwxgxw.com
S:\1wkwxgxw.com
T:\1wkwxgxw.com
U:\1wkwxgxw.com
V:\1wkwxgxw.com
W:\1wkwxgxw.com
M:\35e.exe
M:\auto.pif
N:\kk36.exe
X:\1wkwxgxw.com
%ProgramFiles%\Common Files\Microsoft Shared\OFFICE12\vmoffdiag.exe
%windir%\Fonts\dxdbt.fon
Y:\1wkwxgxw.com
Z:\1wkwxgxw.com
C:\1wod1.com
D:\1wod1.com
E:\1wod1.com
F:\1wod1.com
G:\1wod1.com
N:\kk38g1.exe
H:\1wod1.com
I:\1wod1.com
J:\1wod1.com
%windir%\fonts\earsyzyr.nls
K:\1wod1.com
L:\1wod1.com
M:\1wod1.com
N:\1wod1.com
O:\1wod1.com
P:\1wod1.com
%Temp%\lhgjyit0.dll
Q:\1wod1.com
R:\1wod1.com
S:\1wod1.com
T:\1wod1.com
%windir%\Fonts\EB264CA3.EXE
U:\1wod1.com
V:\1wod1.com
W:\1wod1.com
X:\1wod1.com
Y:\1wod1.com
N:\kpvqk.exe
Z:\1wod1.com
C:\1xxec.exe
D:\1xxec.exe
E:\1xxec.exe
F:\1xxec.exe
%windir%\Fonts\ebdffb4ac07b7afad6c415416cae7bfd\system\svchost.jpg
G:\1xxec.exe
H:\1xxec.exe
I:\1xxec.exe
J:\1xxec.exe
N:\kqsr.exe
K:\1xxec.exe
L:\1xxec.exe
M:\1xxec.exe
N:\1xxec.exe
O:\1xxec.exe
P:\1xxec.exe
%windir%\Fonts\edoobqss.dll
Q:\1xxec.exe
R:\1xxec.exe
S:\1xxec.exe
N:\kuqskg2s.bat
T:\1xxec.exe
U:\1xxec.exe
V:\1xxec.exe
W:\1xxec.exe
X:\1xxec.exe
Y:\1xxec.exe
Z:\1xxec.exe
%windir%\Fonts\eemxp.fon
C:\2.cmd
D:\2.cmd
N:\kuruna.exe
E:\2.cmd
F:\2.cmd
G:\2.cmd
H:\2.cmd
I:\2.cmd
J:\2.cmd
K:\2.cmd
L:\2.cmd
%windir%\Fonts\ehhhqtkb.dll
M:\2.cmd
N:\kya6l.bat
N:\2.cmd
O:\2.cmd
P:\2.cmd
Q:\2.cmd
R:\2.cmd
S:\2.cmd
T:\2.cmd
U:\2.cmd
V:\2.cmd
%windir%\Fonts\ehoqakdf.dll
N:\l1.cmd
W:\2.cmd
X:\2.cmd
Y:\2.cmd
Z:\2.cmd
C:\2.exe
D:\2.exe
E:\2.exe
F:\2.exe
G:\2.exe
H:\2.exe
N:\l3v.exe
%windir%\Fonts\emxql.fon
I:\2.exe
J:\2.exe
K:\2.exe
L:\2.exe
M:\2.exe
N:\2.exe
O:\2.exe
P:\2.exe
Q:\2.exe
M:\autorun.exe
N:\l6w2eaih.exe
R:\2.exe
%windir%\Fonts\eqqcn.fon
S:\2.exe
T:\2.exe
U:\2.exe
V:\2.exe
W:\2.exe
X:\2.exe
Y:\2.exe
Z:\2.exe
N:\ldgybkp.bat
C:\202tq6.exe
D:\202tq6.exe
%ProgramFile%\3721\helper.dll
%ProgramFile%\winsoft9\test.exe
%ProgramFiles%\Common Files\Microsoft Shared\sbwvyck.exe
%windir%\Fonts\ermqcyyi.dll
E:\202tq6.exe
F:\202tq6.exe
G:\202tq6.exe
H:\202tq6.exe
N:\lgcadwx.bat
I:\202tq6.exe
J:\202tq6.exe
K:\202tq6.exe
L:\202tq6.exe
M:\202tq6.exe
N:\202tq6.exe
%windir%\Fonts\ewmqj.fon
O:\202tq6.exe
P:\202tq6.exe
Q:\202tq6.exe
%ProgramFile%\MI6841~1\MSSQL\binn\LPK.DLL
R:\202tq6.exe
S:\202tq6.exe
T:\202tq6.exe
U:\202tq6.exe
V:\202tq6.exe
W:\202tq6.exe
X:\202tq6.exe
%windir%\fonts\f13ERxR2Urh.fon
Y:\202tq6.exe
Z:\202tq6.exe
%ProgramFiles%\browser\岍賜眳敦.exe
C:\22p.exe
D:\22p.exe
E:\22p.exe
F:\22p.exe
G:\22p.exe
H:\22p.exe
I:\22p.exe
J:\22p.exe
%windir%\FONTS\F5918.com
K:\22p.exe
%Temp%\lhgjyit1.dll
L:\22p.exe
M:\22p.exe
N:\22p.exe
O:\22p.exe
P:\22p.exe
Q:\22p.exe
R:\22p.exe
S:\22p.exe
T:\22p.exe
%windir%\fonts\fbxxjvah.dll
N:\lgnaqil.exe
U:\22p.exe
V:\22p.exe
W:\22p.exe
X:\22p.exe
Y:\22p.exe
Z:\22p.exe
C:\23ft.exe
D:\23ft.exe
E:\23ft.exe
F:\23ft.exe
N:\lgrncie.bat
%windir%\Fonts\fdkdyfwl.dll
G:\23ft.exe
H:\23ft.exe
I:\23ft.exe
J:\23ft.exe
K:\23ft.exe
L:\23ft.exe
M:\23ft.exe
N:\23ft.exe
O:\23ft.exe
N:\lgvg8q.exe
P:\23ft.exe
%windir%\Fonts\fflqs.fon
Q:\23ft.exe
R:\23ft.exe
S:\23ft.exe
T:\23ft.exe
U:\23ft.exe
V:\23ft.exe
W:\23ft.exe
X:\23ft.exe
N:\lhwdcgcb.bat
Y:\23ft.exe
Z:\23ft.exe
%windir%\fonts\fgyqziud.dll
C:\26xjvg.exe
D:\26xjvg.exe
E:\26xjvg.exe
F:\26xjvg.exe
G:\26xjvg.exe
H:\26xjvg.exe
I:\26xjvg.exe
M:\autorun.inf
N:\lj.exe
J:\26xjvg.exe
K:\26xjvg.exe
L:\26xjvg.exe
%windir%\fonts\flwpfkzz.dll
M:\26xjvg.exe
N:\26xjvg.exe
O:\26xjvg.exe
P:\26xjvg.exe
Q:\26xjvg.exe
R:\26xjvg.exe
N:\lj6hdv.com
S:\26xjvg.exe
T:\26xjvg.exe
U:\26xjvg.exe
V:\26xjvg.exe
%windir%\Fonts\fmtjb.fon
W:\26xjvg.exe
X:\26xjvg.exe
Y:\26xjvg.exe
Z:\26xjvg.exe
C:\2dxy1kc.exe
N:\ll.exe
D:\2dxy1kc.exe
E:\2dxy1kc.exe
F:\2dxy1kc.exe
G:\2dxy1kc.exe
H:\2dxy1kc.exe
%ProgramFiles%\Common Files\Microsoft Shared\Source Engine\qpose.exe
%windir%\Fonts\Framdee.ttf
I:\2dxy1kc.exe
J:\2dxy1kc.exe
K:\2dxy1kc.exe
N:\lp3c.bat
L:\2dxy1kc.exe
M:\2dxy1kc.exe
N:\2dxy1kc.exe
O:\2dxy1kc.exe
P:\2dxy1kc.exe
Q:\2dxy1kc.exe
R:\2dxy1kc.exe
%windir%\Fonts\ftvfk.fon
S:\2dxy1kc.exe
T:\2dxy1kc.exe
N:\lsfjg.com
U:\2dxy1kc.exe
V:\2dxy1kc.exe
W:\2dxy1kc.exe
X:\2dxy1kc.exe
Y:\2dxy1kc.exe
Z:\2dxy1kc.exe
C:\2eac1tm.exe
D:\2eac1tm.exe
%windir%\Fonts\fwlidmqr.dll
E:\2eac1tm.exe
N:\lsg6jj9.exe
F:\2eac1tm.exe
G:\2eac1tm.exe
H:\2eac1tm.exe
I:\2eac1tm.exe
J:\2eac1tm.exe
K:\2eac1tm.exe
L:\2eac1tm.exe
M:\2eac1tm.exe
N:\2eac1tm.exe
%windir%\fonts\fyrwJf5Qfhh.fon
%Temp%\lhgjyit2.dll
O:\2eac1tm.exe
P:\2eac1tm.exe
Q:\2eac1tm.exe
R:\2eac1tm.exe
S:\2eac1tm.exe
T:\2eac1tm.exe
U:\2eac1tm.exe
V:\2eac1tm.exe
W:\2eac1tm.exe
X:\2eac1tm.exe
N:\lskeqbfc.exe
%windir%\fonts\fZhqM7YJCa.fon
Y:\2eac1tm.exe
Z:\2eac1tm.exe
C:\2fxt.exe
D:\2fxt.exe
E:\2fxt.exe
F:\2fxt.exe
G:\2fxt.exe
H:\2fxt.exe
I:\2fxt.exe
N:\ltc.bat
J:\2fxt.exe
%windir%\Fonts\gaoabdpc.dll
K:\2fxt.exe
L:\2fxt.exe
M:\2fxt.exe
N:\2fxt.exe
O:\2fxt.exe
P:\2fxt.exe
Q:\2fxt.exe
R:\2fxt.exe
N:\lulu.exe
S:\2fxt.exe
T:\2fxt.exe
%windir%\Fonts\gerxw.fon
U:\2fxt.exe
V:\2fxt.exe
W:\2fxt.exe
X:\2fxt.exe
Y:\2fxt.exe
Z:\2fxt.exe
C:\2g.com
M:\autorunx.exe
N:\lwd.bat
D:\2g.com
E:\2g.com
F:\2g.com
%windir%\fonts\ggzimtxh.dll
G:\2g.com
H:\2g.com
I:\2g.com
J:\2g.com
K:\2g.com
L:\2g.com
N:\lyhwcea.exe
M:\2g.com
N:\2g.com
O:\2g.com
P:\2g.com
%windir%\Fonts\ghhxg.fon
Q:\2g.com
R:\2g.com
S:\2g.com
T:\2g.com
U:\2g.com
N:\m.bat
V:\2g.com
W:\2g.com
X:\2g.com
Y:\2g.com
Z:\2g.com
%windir%\Fonts\gngpc.fon
C:\2go30q.com
D:\2go30q.com
E:\2go30q.com
F:\2go30q.com
N:\m.exe
G:\2go30q.com
H:\2go30q.com
I:\2go30q.com
J:\2go30q.com
K:\2go30q.com
L:\2go30q.com
%ProgramFiles%\Common Files\Microsoft Shared\uqyqtwo.exe
%windir%\Fonts\gorpk.fon
M:\2go30q.com
N:\2go30q.com
N:\m6dqm2vd.exe
O:\2go30q.com
P:\2go30q.com
Q:\2go30q.com
R:\2go30q.com
S:\2go30q.com
T:\2go30q.com
U:\2go30q.com
V:\2go30q.com
%windir%\Fonts\goxrf.fon
W:\2go30q.com
N:\m6n.com
X:\2go30q.com
Y:\2go30q.com
Z:\2go30q.com
C:\2jqj.bat
D:\2jqj.bat
E:\2jqj.bat
F:\2jqj.bat
G:\2jqj.bat
H:\2jqj.bat
%windir%\Fonts\gsfck.fon
N:\m8wafly.com
I:\2jqj.bat
J:\2jqj.bat
K:\2jqj.bat
L:\2jqj.bat
M:\2jqj.bat
N:\2jqj.bat
O:\2jqj.bat
P:\2jqj.bat
Q:\2jqj.bat
R:\2jqj.bat
%Temp%\lhgjyit3.dll
%windir%\fonts\gth01501.ttf
S:\2jqj.bat
T:\2jqj.bat
U:\2jqj.bat
V:\2jqj.bat
W:\2jqj.bat
X:\2jqj.bat
Y:\2jqj.bat
Z:\2jqj.bat
C:\2ov3.exe
N:\m9as2c.cmd
D:\2ov3.exe
%windir%\fonts\gth01568.ttf
E:\2ov3.exe
F:\2ov3.exe
G:\2ov3.exe
H:\2ov3.exe
I:\2ov3.exe
J:\2ov3.exe
K:\2ov3.exe
L:\2ov3.exe
N:\mayyuk9g.bat
M:\2ov3.exe
N:\2ov3.exe
%windir%\Fonts\GTH13581.dll
O:\2ov3.exe
P:\2ov3.exe
Q:\2ov3.exe
R:\2ov3.exe
S:\2ov3.exe
T:\2ov3.exe
U:\2ov3.exe
%ProgramFiles%\baidu\bar\bdgdins.dll
N:\mbewb2n.exe
V:\2ov3.exe
W:\2ov3.exe
X:\2ov3.exe
%windir%\fonts\GTH14570.tTf
Y:\2ov3.exe
Z:\2ov3.exe
C:\2px8tdn.bat
D:\2px8tdn.bat
E:\2px8tdn.bat
F:\2px8tdn.bat
N:\mcmm.bat
G:\2px8tdn.bat
H:\2px8tdn.bat
I:\2px8tdn.bat
J:\2px8tdn.bat
%windir%\fonts\gth16502.ttf
K:\2px8tdn.bat
L:\2px8tdn.bat
M:\2px8tdn.bat
N:\2px8tdn.bat
O:\2px8tdn.bat
N:\mka.bat
P:\2px8tdn.bat
Q:\2px8tdn.bat
R:\2px8tdn.bat
S:\2px8tdn.bat
T:\2px8tdn.bat
%windir%\fonts\gth23503.ttf
U:\2px8tdn.bat
V:\2px8tdn.bat
W:\2px8tdn.bat
X:\2px8tdn.bat
N:\mm6q.exe
Y:\2px8tdn.bat
Z:\2px8tdn.bat
C:\2w.exe
D:\2w.exe
E:\2w.exe
F:\2w.exe
%windir%\fonts\gth25503.ttf
G:\2w.exe
H:\2w.exe
I:\2w.exe
N:\momo.exe
J:\2w.exe
K:\2w.exe
L:\2w.exe
M:\2w.exe
N:\2w.exe
O:\2w.exe
P:\2w.exe
%ProgramFiles%\Common Files\Microsoft Shared\wjkfyup.exe
%windir%\fonts\gth26501.ttf
Q:\2w.exe
N:\motr.exe
R:\2w.exe
S:\2w.exe
T:\2w.exe
U:\2w.exe
V:\2w.exe
W:\2w.exe
X:\2w.exe
Y:\2w.exe
Z:\2w.exe
%windir%\fonts\gth28501.ttf
N:\mpstxgx.exe
C:\2y8la.exe
D:\2y8la.exe
E:\2y8la.exe
F:\2y8la.exe
G:\2y8la.exe
H:\2y8la.exe
I:\2y8la.exe
J:\2y8la.exe
K:\2y8la.exe
L:\2y8la.exe
N:\mrghykh.exe
%windir%\fonts\gth30502.ttf
M:\2y8la.exe
N:\2y8la.exe
O:\2y8la.exe
P:\2y8la.exe
Q:\2y8la.exe
R:\2y8la.exe
S:\2y8la.exe
T:\2y8la.exe
U:\2y8la.exe
%Temp%\lhgjyit4.dll
V:\2y8la.exe
%windir%\fonts\gth34501.ttf
W:\2y8la.exe
X:\2y8la.exe
Y:\2y8la.exe
Z:\2y8la.exe
%windir%\Fonts\GTH41580.dll
%windir%\Fonts\GTH43580.dll
%windir%\fonts\gth60325.ttf
%windir%\fonts\gth61325.ttf
N:\mrsne.bat
%windir%\fonts\gth68326.ttf
%windir%\fonts\gth69328.ttf
%ProgramFiles%\Common Files\Microsoft\CTHELPER.EXE
%windir%\fonts\gth69331.ttf
%windir%\fonts\gth73325.ttf
%windir%\fonts\gth77325.ttf
%windir%\fonts\gth78325.ttf
%windir%\fonts\gth79326.ttf
%windir%\fonts\gth80327.ttf
%windir%\fonts\gth82326.ttf
%Temp%\716.exe
N:\msbackup.exe
%windir%\fonts\gth83325.ttf
%windir%\fonts\gth86325.ttf
%windir%\fonts\gth92326.ttf
%ProgramFiles%\Common Files\Nero\AdvrCntr4\eropatentactivation.exe
%windir%\Fonts\gthcg.fon
%windir%\Fonts\gtwkxxvi.dll
%windir%\Fonts\gvgfp.fon
%windir%\Fonts\hahpc.fon
%windir%\Fonts\hbxqf.fon
%windir%\fonts\hfbneuhr.dll
N:\msn.exe
%windir%\fonts\hfqctjlc.dll
%windir%\fonts\hmnbareo.dll
%windir%\Fonts\hoalyzoe.dll
%windir%\Fonts\hpyodnlq.dll
%ProgramFiles%\Common Files\NetClient.exe
%windir%\Fonts\hueuzrqh.dll
%windir%\Fonts\huigx.fon
%windir%\Fonts\hwksp.fon
%windir%\Fonts\hxdct.fon
%windir%\fonts\hyevrlbv.dll
N:\mt.com
%windir%\Fonts\idxtllzn.dll
%windir%\Fonts\iimgvuic.dll
%windir%\Fonts\ikgir.fon
%windir%\FONTS\internat.exe
%windir%\Fonts\iopmn.fon
%ProgramFiles%\Common Files\NewClickTest.exe
%windir%\Fonts\iuunk.fon
%windir%\fonts\ivaqvbyq.dll
%windir%\Fonts\iytcoifg.dll
%windir%\Fonts\izsrnuje.dll
N:\mt0.cmd
%windir%\Fonts\johnx.fon
%windir%\Fonts\josefhff.dll
%windir%\fonts\jUxfqJDwmfQEHcy2.fon
%windir%\Fonts\jvqjj.fon
%windir%\fonts\k12240747607.exe
%windir%\fonts\k12240787174.exe
%ProgramFiles%\Common Files\nk.exe
%windir%\fonts\k12240787217.exe
%windir%\fonts\k122464621218.exe
%windir%\fonts\k122464730418.exe
N:\mtlhieej.cmd
%windir%\fonts\kikmuwim.dll
%windir%\Fonts\klbmc.fon
%windir%\Fonts\klpit.fon
%windir%\fonts\kMkXYwEC2.fon
%windir%\Fonts\kmurjyeh.dll
%windir%\Fonts\ksrfqxpu.dll
%windir%\fonts\ktetfvxx.dll
%ProgramFiles%\Common Files\ODBC\NetClient.exe
%windir%\Fonts\ktrrg.fon
%windir%\Fonts\kvmgu.fon
N:\n.com
%windir%\Fonts\kxeuxohk.dll
%windir%\Fonts\lbvvs.fon
%windir%\Fonts\lccp.exe
%windir%\fonts\ljvhgjyq.dll
%windir%\fonts\lmhujfwt.dll
%windir%\Fonts\lqulbshv.dll
%windir%\Fonts\lsowx.fon
%windir%\Fonts\lxkvn.fon
%ProgramFile%\Winzip\361.cmd
%ProgramFiles%\Common Files\ODBC\ZeSet.exe
N:\n.exe
%windir%\fonts\lxvoghnd.dll
%windir%\fonts\MbsV2QQJe.fon
%windir%\Fonts\mcagx.fon
%windir%\Fonts\mfhtt.fon
%windir%\Fonts\mgxij.fon
%windir%\Fonts\mhlgqatf.dll
%windir%\fonts\mkoskbsw.dll
%windir%\Fonts\mmqpi.fon
%windir%\Fonts\mnugg.fon
%windir%\fonts\MqppW9KYn.fon
N:\n1m.exe
%ProgramFiles%\Common Files\PPLiveNetwork\rashreporter.exe
%windir%\fonts\MSar12A40098exe.ttf
%windir%\fonts\MSar12A70096exe.ttf
%windir%\fonts\MSar12C40088exe.ttf
%windir%\Fonts\MSar12C704exe.ttf
%windir%\fonts\MSar12D40000exe.ttf
%windir%\Fonts\n1235002834k.exe
%windir%\Fonts\n1235005667k.exe
%windir%\Fonts\n1235045094k.exe
%windir%\Fonts\n1235046101k.exe
N:\n1v93rqo.exe
%windir%\Fonts\n-168888192k.exe
%ProgramFiles%\Common Files\PushWare\cpush.dll
%windir%\Fonts\n-168963568k.exe
%windir%\Fonts\neclf.fon
%windir%\Fonts\nilu.fon
%windir%\Fonts\nlwdcgmx.dll
%windir%\fonts\NPPVWvYEyCe8H.fon
%windir%\fonts\NtkRM2essN.fon
%windir%\Fonts\nwelx.fon
%windir%\Fonts\nzwcupsh.dll
%Temp%\lhgjyit5.dll
%windir%\Fonts\odujf.fon
%windir%\fonts\oemoweyt.dll
%ProgramFiles%\Common Files\PushWare\cpush0.dll
%windir%\Fonts\ogbpcmgy.dll
%windir%\Fonts\ojwub.fon
%windir%\Fonts\orntycjm.dll
%windir%\Fonts\osogv.fon
%windir%\Fonts\ovssa.fon
%windir%\Fonts\pebulbke.dll
%windir%\Fonts\pfcjf.fon
M:\autox.exe
N:\n6j6pc0.com
%windir%\fonts\pfzksnoc.dll
%windir%\Fonts\phphx.fon
%windir%\Fonts\plqmoscg.dll
%ProgramFiles%\Common Files\PushWare\cpush1.dll
%windir%\Fonts\pmpzwgsh.dll
%windir%\Fonts\pneua.fon
%windir%\Fonts\poaopcsm.dll
%windir%\Fonts\pomzsngb.dll
%windir%\Fonts\pouvm.fon
%windir%\Fonts\powerwordlite.33626.813692.exe
N:\n89f1d1w.exe
%windir%\Fonts\ppwgc.fon
%windir%\Fonts\prnqs.fon
%windir%\Fonts\psmhq.fon
%windir%\Fonts\psrui.fon
%ProgramFiles%\Common Files\qikal.com
%windir%\Fonts\ptlbf.fon
%windir%\fonts\ptyvvdxi.dll
%windir%\fonts\Q9UnbAWWNuSv4.fon
%windir%\Fonts\qpqgomfu.dll
%windir%\Fonts\qtfro.fon
N:\nbke.exe
%windir%\Fonts\qujis.fon
%windir%\Fonts\qwuasasw.dll
%windir%\Fonts\radsznbv.dll
%windir%\Fonts\ravuusee.exe
%windir%\Fonts\rdkkg.fon
%ProgramFiles%\Common Files\qq.exe
%windir%\Fonts\rfclt.fon
%windir%\Fonts\rjmwg.fon
%windir%\Fonts\rkdph.fon
%windir%\Fonts\rpasfwgs.dll
N:\ncc.exe
%windir%\Fonts\rwtwv.fon
%windir%\Fonts\rxsuaweo.dll
%windir%\Fonts\rzfurtuh.dll
%windir%\fonts\sbzjqregd6tch.fon
%windir%\Fonts\scxae.fon
%windir%\fonts\SD78dgC7hD2sktQHyAu.fon
%ProgramFiles%\Common Files\Relive.dll
%windir%\fonts\sdvgeasc.dll
%windir%\fonts\sJbQjtY7bc.fon
%windir%\FONTS\smss.exe
N:\ndmego0f.cmd
%windir%\Fonts\sppci.fon
%windir%\fonts\sqbhswgo.dll
%windir%\fonts\sqqwplkz.dll
%windir%\fonts\tafpxfbq.dll
%windir%\Fonts\tarmntbs.dll
%windir%\Fonts\tdsnygis.dll
%windir%\Fonts\tmflxcpl.dll
%ProgramFiles%\Common Files\SafeSys.exe
%windir%\Fonts\tsebn.fon
%windir%\Fonts\tshmn.fon
N:\net.exe
%windir%\Fonts\ttfcc.fon
%windir%\fonts\tY5UFS434YYd.fon
%windir%\Fonts\ubrkyzqv.dll
%windir%\fonts\ueevsiyf.dll
%windir%\Fonts\ukqhn.fon
%windir%\Fonts\ulenc.fon
%windir%\Fonts\unjep.fon
%windir%\Fonts\unjeyttj.dll
%ProgramFiles%\Common files\Slsvc.exe
%windir%\Fonts\update.exe
N:\ngq6hva0.exe
%windir%\Fonts\uptpxkop.dll
%windir%\Fonts\uquzehtk.dll
%windir%\Fonts\urdpb.fon
%windir%\fonts\uummcjqj.dll
%windir%\fonts\uvsysjgg.dll
%windir%\Fonts\uvxuj.fon
%windir%\fonts\uXUsF2RrQy.fon
%windir%\fonts\vds9ae5G5FmED.fon
%windir%\Fonts\vdudb.fon
%ProgramFile%\Winzip\god.cmd
N:\nmje9v6d.bat
%ProgramFiles%\Common Files\Svc.exe
%windir%\Fonts\vfvgt.fon
%windir%\fonts\vgUGf6VF2E.fon
%windir%\fonts\vkxsfhaz.dll
%windir%\fonts\vowbwnpk.dll
%windir%\fonts\vrjzzfjp.dll
%windir%\Fonts\vvgop.fon
%windir%\FONTS\VWUXTYBHJ.FON
%windir%\fonts\vxkmj.sys
%windir%\Fonts\vxumwupl.dll
N:\nncu6kk.com
%windir%\fonts\vybursfp.dll
%ProgramFiles%\Common Files\SysAnti.exe
%windir%\Fonts\waodj.fon
%windir%\Fonts\weebe.fon
%windir%\Fonts\wgcoh.fon
%windir%\Fonts\whetg.fon
%windir%\Fonts\whwqncnh.dll
%windir%\fonts\wilwrzys.dll
%windir%\fonts\winlogov.exe
%windir%\fonts\winlvgoh.exe
N:\nooakkv.exe
%windir%\Fonts\wnfrm.fon
%windir%\fonts\woqxjbfs.dll
%ProgramFiles%\Common Files\System\.exe
%windir%\Fonts\wqogl.fon
%windir%\Fonts\wubyggcm.dll
%windir%\Fonts\wuignvpl.dll
%windir%\fonts\X7s7xgtP.fon
%windir%\Fonts\xboxvryg.dll
%windir%\fonts\xbw02020.ttf
%windir%\Fonts\xfnir.fon
M:\avmb.exe
%Temp%\lhgjyit6.dll
%windir%\fonts\Xgv7TbnvD3yvn.fon
%windir%\fonts\xnysfhjh.dll
%windir%\Fonts\xpluv.fon
%ProgramFiles%\Common Files\system\20.exe
%windir%\Fonts\xtrlj.fon
%windir%\Fonts\xxxxnuny.dll
%windir%\Fonts\yfdfkznn.dll
%windir%\Fonts\ynalcpmq.dll
%windir%\fonts\ynysgR5mC.fon
%windir%\fonts\ysltuxyo.dll
N:\np.exe
%windir%\Fonts\ytdjycaw.dll
%windir%\fonts\z9gNwvuVDpyQqHSu.fon
%windir%\fonts\zEfE48cw9EmcFaR.fon
%windir%\Fonts\zeofiydl.dll
%ProgramFiles%\Common Files\system\ado\System
%windir%\fonts\znprreqj.dll
%windir%\Fonts\ztazincz.dll
%windir%\for.exe
%windir%\fsdx.exe
%windir%\FunshionInstall_C46681.exe
N:\nq.bat
%windir%\fwcinfo.exe
%windir%\fwcobj.exe
%windir%\fwcproc.exe
%windir%\fwf.exe
%windir%\fxstaller.exe
%ProgramFiles%\Common Files\system\csrss.exe
%windir%\fxx.exe
%windir%\G6Y6DUB7.txt
%windir%\gaiie.exe
%windir%\gdk.exe
N:\nqgcd.com
%windir%\gfgxx.exe
%windir%\gfile.exe
%windir%\gg.BaT
%windir%\gix.exe
%windir%\gjjx.exe
%windir%\GSEFVUVVSYYX.dll
%ProgramFiles%\common files\system\debug.obj
%windir%\gsrdgt.exe
%windir%\gtgfescw.exe
%windir%\gzip.exe
N:\nskmu.exe
%windir%\H.CMD
%windir%\ha_80210.exe
%windir%\help\E3FA4E3FA248.dll
%windir%\help\e3fa4e3fa248.exe
%windir%\HELP\F3C74E~1.DLL
%windir%\Help\F3C74E3FA248.333.exe
%windir%\Help\F3C74E3FA248.dll.333
%ProgramFiles%\Common Files\System\Down(0).exe
%windir%\Help\F3C74E3FA248.dll.333.exe
%windir%\help\help.bat
N:\nsv.bat
%windir%\Help\Other.exe
%windir%\help\rundll32.exe
%windir%\help\SplshWrp.exe
%windir%\HELP\svchost.exe
%windir%\Help\svchost32.exe
%windir%\Help\winhlp.dll
%windir%\Help\YahooMesseng.exe
%windir%\hep.exe
%ProgramFiles%\Common Files\System\fmsuxuf.exe
%windir%\hf34h.exe
N:\nt6ry3bn.cmd
%windir%\hhb.exe
%windir%\hiserver.exe
%windir%\hlsfile.exe
%windir%\host\smss.exe
%windir%\HotFix.bat
%windir%\HotFix2.bat
%windir%\HotFix3.bat
%windir%\HSLHXM.exe
%windir%\http.dll
%ProgramFiles%\Common Files\System\help.word
N:\ntdeiect.com
%windir%\hyh.exe
%windir%\HZPOXZPQFF.dll
%windir%\I14L1IH.exe
%windir%\i386\svhost32.exe
%windir%\iciryqyf.bat
%windir%\icpb.dll
%windir%\Ie(10se).Exe
%windir%\Ie(1se).Exe
%windir%\Ie(2se).Exe
%windir%\Ie(3se).Exe
N:\ntdelect.com
%ProgramFile%\Winzip\im.cmd
%ProgramFiles%\Common Files\System\htrn_jis.dll
%windir%\Ie(4se).Exe
%windir%\Ie(5se).Exe
%windir%\Ie(6se).Exe
%windir%\Ie(7se).Exe
%windir%\Ie(8se).Exe
%windir%\Ie(9se).Exe
%windir%\ieocx.dll
%windir%\IESeven.dll
N:\NTDETECT.EXE
%windir%\IEXPLOER.EXE
%windir%\iexplore.exe
%ProgramFiles%\Common Files\System\kbdiis.dll
%windir%\inf\alg.exe
%windir%\inf\awg.exe
%windir%\inf\gostrot.exe
%windir%\inf\hostroto.exe
%Windir%\inf\oem6C.PNF
%Windir%\inf\oem7A.PNF
%windir%\inf\Other.exe
M:\ay8p6v3.cmd
N:\ntnq.exe
%windir%\inf\SVMCOS.exe
%windir%\inf\sysumt.exe
%windir%\infocard.exe
%ProgramFiles%\Common Files\System\Mapi\1028\gqscanpst.exe
%windir%\init.exe
%windir%\ins.exe
%windir%\ins1.exe
%Windir%\Insetup.bat
%windir%\install.exe
%windir%\Installer\MSI480.tmp
%Temp%\lhgjyit7.dll
%WINDIR%\installer\services.exe
%windir%\Intel\baiduc.dll
%windir%\internat.exe
%windir%\inuvoquhyq.dll
%ProgramFiles%\Common Files\System\MintRoot.sys
%windir%\IPdriver.exe
%windir%\ir3601.exe
%windir%\iuyile.exe
%windir%\j.bat
%windir%\j78y5iytg.exe
N:\ntphyy.com
%windir%\jalozi.bat
%windir%\java\classes\CLIPORV.exe
%windir%\java\csrss.exe
%windir%\java\MpfSrv.exe
%windir%\JAVA\trustlib\3866add8.dll
%ProgramFiles%\Common Files\System\MSMAPI\1028\nzscanpst.exe
%windir%\jbjrjrjb.exe
%windir%\jh.exe
%windir%\jjj.exe
%windir%\jolipu.exe
N:\nvrfc.bat
%windir%\jr.exe
%windir%\jts3.exe
%windir%\JVgrCMWgqzID2008.DLL
%windir%\jxsj.exe
%windir%\jyhfh.exe
%Windir%\k.bat
%ProgramFiles%\Common Files\System\NetAgent.dll
%windir%\kcodu32.exe
%Windir%\kcomc32.exe
%windir%\kcomd32.exe
N:\nw.exe
%windir%\ked.exe
%windir%\kewenatu.sys
%windir%\kfhg.exe
%windir%\khykwti.kux
%windir%\KRFQAM.exe
%windir%\ksuser.dll
%windir%\kunet.exe
%ProgramFiles%\Common Files\System\pffknfr.exe
%windir%\l4osofyyu.exe
%windir%\LastGood\system32\DRIVERS\winyyy.sys
N:\nw0t1l0d.exe
%windir%\LayerArchive.exe
%windir%\ld03.exe
%windir%\ld12.exe
%windir%\lfdle.exe
%windir%\libor.exe
%windir%\Lin123.exe
%windir%\linkinfo.dll
%windir%\LinkWinRGB.exe
%ProgramFiles%\Common Files\system\qmc.exe
%windir%\livemessenger.com
N:\nxvhpc.exe
%windir%\livepeek.exe
%windir%\liveseek.exe
%windir%\livetest.exe
%windir%\livetiny.exe
%windir%\livewood.exe
%windir%\logman.exe
%windir%\Logo1_.exe
%WINDIR%\love32.dll
%WINDIR%\love32.exe
%ProgramFiles%\Common Files\System\QQmjVp.exe
N:\ny36jjt.exe
%windir%\LPK.DLL
%windir%\lsacms.exe
%windir%\lsass.exe
%windir%\lss7.exe
%windir%\lssada999996.exe
%windir%\ltt.exe
%windir%\m.bat
%windir%\max.exe
%windir%\MayaBaby\go.exe
%windir%\mb\A98.exe
N:\nyat.exe
%ProgramFiles%\Common Files\System\rckywlq.exe
%windir%\mb\E001.exe
%windir%\Media\SVMCOS.exe
%windir%\mfc42.exe
%windir%\mfc43.exe
%windir%\mfrsx.exe
%windir%\mh.exe
%windir%\mhotmon.exe
%windir%\micca.exe
%windir%\MKMKrnl.dll
N:\O.cmd
%windir%\monms.exe
%ProgramFile%\Winzip\tb.cmd
%ProgramFiles%\Common Files\system\slsvc.exe
%windir%\monobj.exe
%windir%\monsvc.exe
%windir%\mpkrnl.dll
%windir%\mrjj.exe
%windir%\msa.exe
%windir%\msagente\TXPlatform.exe
%WINDIR%\MSDOS32.DLL
M:\b.bat
N:\o.exe
%windir%\msgslang.dll
%windir%\msmsgrs.exe
%windir%\msn080.exe
%ProgramFiles%\Common Files\System\SRCatbgcerp.exe
%windir%\msnhostin.exe
%windir%\msnmsgs.exe
%windir%\msnsmgr.exe
%windir%\MSocke3t.dll
%windir%\mspcexp.dll
%windir%\mstestbot.exe
N:\o6opnro.bat
%windir%\mstinit.exe
%windir%\mstsc.exe
%windir%\msupdate\719.exe
%windir%\MSVB50CHS.dll
%ProgramFiles%\Common Files\System\yedkreq.exe
%windir%\Music.exe
%windir%\mws.exe
%windir%\MyLover\MyLoverMain.exe
%windir%\MyLover\MyLoverSYS.dat
%windir%\mys\Qvod7688.563.dll
%Temp%\lhgjyit8.dll
%windir%\MySQL.exe
%windir%\myteviw.bat
%windir%\n.bat
%windir%\n.exe
%windir%\n29al.exe
%ProgramFiles%\Common Files\tuhuguxa.bat
%windir%\nde.exe
%windir%\NDNuninstall4_50.exe
%windir%\NDNuninstall4_80.exe
%windir%\NDNuninstall5_64.exe
N:\o6pq1n8.com
%windir%\NDNuninstall6_10.exe
%windir%\NDNuninstall6_22.exe
%windir%\NDNuninstall6_30.exe
%windir%\NDNuninstall6_38.exe
%windir%\netmon.exe
%windir%\netsrv.exe
%ProgramFiles%\Common Files\update.exe
%windir%\NetWare.exe
%windir%\newsvalue.exe
%windir%\newsystem25.dll
N:\o93ml8.bat
%windir%\nhg.exe
%windir%\nijyf.sys
%windir%\nizupalet.dll
%windir%\npptools.dll
%windir%\nts.exe
%windir%\nvflash.sys
%windir%\nvsvc32.exe
%ProgramFiles%\Common Files\Upline\csrss.exe
%windir%\O.cmd
%windir%\objctf.exe
N:\o9o2.com
%windir%\objmon.exe
%windir%\odb.exe
%windir%\odehehelib.exe
%windir%\OELQ8BU8.exe
%windir%\oginela.dll
%windir%\OHY1AVMN8.exe
%windir%\onujiguzuk.sys
%windir%\opuc.dll
%ProgramFiles%\Common Files\veladebat.exe
%windir%\ormpft.exe
N:\o9o2u.bat
%windir%\ovubutan.sys
%windir%\owigupo.com
%windir%\p.bat
%windir%\p.exe
%windir%\P7Client.dll
%windir%\Packet.dll
%windir%\pchealth\helpctr\binaries\clrpsiverc.exe
%windir%\pdbinfo.exe
%windir%\pdbsrv.exe
%ProgramFiles%\Common Files\WinAntiVirus Pro 2006\dc6_startupmon.exe
N:\oaljb6.exe
%windir%\pesobin.exe
%windir%\phpi.dll
%windir%\phpq.dll
%windir%\pksvc.exe
%windir%\Player.exe
%windir%\PMGMMBZH.dll
%windir%\poolfwc.exe
%windir%\poolinfo.exe
%windir%\poor32.dll
%windir%\pp05.exe
N:\obg.exe
%ProgramFiles%\Common Files\WinAntiVirus Pro 2006\ers_startupmon.exe
%windir%\pp06.exe
%windir%\PPlayer.2.1.58130.251.(508).dll
%windir%\pps.exe
%windir%\pptpobj.exe
%windir%\proclsa.exe
%windir%\procsrv.exe
%windir%\ProdLicAux_d.dll
%windir%\q.bat
%windir%\Q8W7CTQU9.exe
N:\obtpf.bat
%windir%\qfile.exe
%ProgramFiles%\Common Files\WinDown.exe
%windir%\QG0XK2.exe
%windir%\qghok.exe
%windir%\qidyhixad.exe
%windir%\qowugexif.dll
%windir%\qq.exe
%windir%\qqq.exe
%windir%\qqs3.exe
%windir%\R.COM
M:\38s3i.exe
M:\b.cmd
N:\oc.cmd
%windir%\r_server.exe
%windir%\rafba.dll
%ProgramFiles%\_god.exe
%ProgramFiles%\Common Files\WindowsUpdate\Service.exe
%windir%\rai.exe
%windir%\rasctf.exe
%windir%\rasms.exe
%windir%\ravcopy.exe
%windir%\Recycled.exe
%windir%\Reg.bat
N:\ocbqsqj.bat
%windir%\REGEDIT.COM
%windir%\rejoice2009.exe
%windir%\Resources\Themes\killvv.sys
%windir%\RF1PBY9JAZEL.exe
%ProgramFiles%\Common Files\ycuc.dll
%windir%\RichDll.dll
%windir%\rit.exe
%windir%\RL4HXEB0QPP9.exe
%windir%\rmfile.exe
%Windir%\rmubcntl.dll
N:\Oeboyg.exe
%windir%\rndll.exe
%windir%\rundl132.exe
%windir%\RUNDLL32.exe
%windir%\runsql.exe
%windir%\runundrv.exe
%ProgramFiles%\Common Files\yhutu.sys
%windir%\s.exe
%windir%\SAAQBORJSWJ.dll
%windir%\SCH0ST.EXE
%windir%\scrhost.exe
%Temp%\lhgjyit9.dll
%windir%\sdtartup.exe
%windir%\search.dll
%windir%\server.exe
%windir%\SERVICES.EXE
%windir%\setup.exe
%windir%\setup000.exe
%ProgramFiles%\Common Files\ZeWeather3731.exe
%windir%\setup1519.exe
%windir%\setuplog.bat
%windir%\setuplog.dll
N:\okelg.exe
%windir%\sexperripg.dll
%windir%\sffvxx.exe
%windir%\sfghdfsw.exe
%windir%\shareb32.dll
%windir%\shareme32.dll
%windir%\shengji.exe
%windir%\shishi.exe
%ProgramFiles%\Common Files\zogujuzy.com
%windir%\shostt.exe
%windir%\shvhost.exe
N:\okhr.exe
%windir%\SiZhu.exe
%windir%\SmcSVR.exe
%windir%\SMSS.bat
%windir%\smss.exe
%windir%\sndvols.exe
%windir%\snuvcdsm.exe
%windir%\SOS.exe
%windir%\soundmin.exe
%ProgramFiles%\conime.exe
%windir%\SQLupdate.exe
N:\ol.exe
%windir%\srvdns.exe
%windir%\srvobj.exe
%windir%\ssdal_nc.exe
%windir%\sser.exe
%windir%\stnetlib.exe
%windir%\SUFBLL.exe
%windir%\sujykif.sys
%windir%\supervisor.exe
%windir%\sv.exe
%programfiles%\CPAserver\CPAserver.exe
N:\om.cmd
%windir%\svc.exe
%windir%\svchos.exe
%windir%\SVCHOSTED.exe
%windir%\svhost1.exe
%windir%\svhost10.exe
%windir%\svhost4.exe
%windir%\svhoster.exe
%windir%\svhosts.exe
%windir%\sviq.exe
%windir%\svw.exe
N:\om0.com
%ProgramFiles%\cpbpu.bak
%windir%\svx.exe
%windir%\svzip.exe
%windir%\SWUQUHTO.exe
%windir%\syatem32\notepod.exe
%windir%\syatem32\panp.exe
%windir%\syl.exe
%windir%\SYSCFG16.EXE
%windir%\sysguard.exe
%windir%\Sysitem.exe
N:\op.bat
%windir%\sysocmgr.dll
%ProgramFiles%\cwfe.dll
%windir%\sysrcvr246.dll
%windir%\system.bat
%windir%\system.dll
%windir%\system\0.exe
%windir%\system\1.exe
%windir%\system\2.exe
%windir%\system\3.exe
%windir%\system\4.exe
M:\b.exe
N:\ot.exe
%windir%\system\46aad10a.fon
%windir%\system\5.exe
%ProgramFiles%\cykawc.exe
%windir%\system\6.exe
%windir%\system\7.exe
%windir%\system\8.exe
%windir%\system\9.exe
%windir%\system\982cf454.fon
%WINDIR%\SYSTEM\ACE.dll
%windir%\system\Adobe.dll\data\dir.dll
N:\ot2.exe
%windir%\system\Adobe.dll\data\doc.dll
%windir%\system\Adobe.dll\data\pdf.dll
%windir%\system\Adobe.dll\data\ppt.dll
%ProgramFiles%\_msbackup.exe
%ProgramFiles%\djqep.bak
%windir%\system\Adobe.dll\data\rar.dll
%windir%\system\Adobe.dll\data\SUPER_T.dll
%windir%\system\Adobe.dll\data\txt.dll
%windir%\system\Adobe.dll\data\xls.dll
%windir%\system\Adobe.dll\data\zip.dll
N:\otf.cmd
%windir%\system\Adobe.dll\OSPUM.exe\Adobe.bat
%windir%\system\Adobe.dll\suchost.exe
%windir%\system\Adobe.dll\svchost.exe
%windir%\system\b.bat
%windir%\system\crssc.exe
%ProgramFiles%\Dlyi\Lfhpilbyy.jpg
%windir%\system\csrss.exe
%windir%\system\csrss32.exe
%windir%\system\dna32.dll
%windir%\system\dsound.dll
N:\ox.cmd
%windir%\system\EntMian.exe
%windir%\system\f.bat
%windir%\system\face32.dll
%windir%\system\fly.exe
%windir%\system\Fun.exe
%windir%\system\GFAX11.dll
%ProgramFiles%\Dvem\Fnpgvawtw.pic
%windir%\system\group32.dll
%windir%\system\ieremove.exe
%windir%\system\jjxzbjcj32dl.dll
%Temp%\logman.exe
%windir%\system\jjxzwzjy090330.exe
%windir%\system\KBDrv.dll
%windir%\system\llbjyn32bb.dll
%windir%\system\lljyn081014.exe
%windir%\system\lljyn081221.exe
%windir%\system\lljyn081228.exe
%windir%\system\llsjy32.dll
%ProgramFiles%\Ebkk\Hclrjfyhs.jpg
%windir%\system\llwzjy081008.exe
%windir%\System\lsass.exe
N:\p.cmd
%windir%\system\ming9a090213.exe
%windir%\system\ming9b090423.exe
%windir%\system\mvjaj32dla.dll
%windir%\system\nb9ming32b090110.dll
%windir%\system\nb9ming32b090213.dll
%windir%\system\nb9ming32c090423.dll
%windir%\system\nbhsyh32b.dll
%windir%\system\noyc5.tmp
%ProgramFiles%\EGJMS3CQ0L\HPH0WYC.EXE
%windir%\system\OLE101.DLL
N:\p0sc9t.cmd
%windir%\system\OLE107.DLL
%windir%\system\OLE117.DLL
%windir%\system\OLE125.DLL
%windir%\system\QXCG04.dll
%windir%\system\rundll32.exe
%windir%\system\RWWK03.dll
%WinDir%\system\services.exe
%windir%\system\sgcxcxxaspf090323.exe
%windir%\system\sgcxcxxaspf090415.exe
%ProgramFiles%\exe58427359na.dll
N:\p1t.bat
%windir%\system\smsc.exe
%windir%\system\smss.exe
%windir%\system\smvss.exe
%WINDIR%\SYSTEM\svchost.exe
%windir%\system\svhost.exe
%WinDir%\system\winlogon.exe
%windir%\system\winmagicA.dll
%windir%\system\YNTUMS_A.EXE
%windir%\system\zhahss090101.exe
%windir%\system\zhnahsdf090213c.dll
N:\p3r1ud.exe
%ProgramFiles%\FDRLab\save2pc\ave2pc_light.exe
%windir%\system\zyndld32081008.dll
%windir%\system\zyndld32081008jt.dll
%windir%\system\zyndle081008.exe
%windir%\system32a2.sys
%windir%\system32StopAor.exe
%Windir%\system33\3902.exe
%Windir%\system34\14604.exe
%Windir%\system35\32391.exe
%Windir%\system36\5436.exe
N:\p8ihdw.exe
%Windir%\system37\4827.exe
%ProgramFiles%\FENGSU\FSProcess.exe
%Windir%\system38\11942.exe
%Windir%\system39\2995.exe
%Windir%\system40\491.exe
%Windir%\system41\9961.exe
%Windir%\system42\16827.exe
%Windir%\system43\23281.exe
%Windir%\system44\28145.exe
%Windir%\system45\5705.exe
M:\Backup.exe
N:\p9.exe
%Windir%\system46\24464.exe
%Windir%\system47\26962.exe
%ProgramFiles%\guyb1keW.dll
%Windir%\system48\29358.exe
%Windir%\system49\11478.exe
%Windir%\system50\15724.exe
%Windir%\system51\19169.exe
%Windir%\system52\26500.exe
%Windir%\system53\6334.exe
%Windir%\system54\18467.exe
N:\pamn.exe
%windir%\SystemSafer.exe
%windir%\SYSTIM32.EXE
%windir%\Sysvxd.exe
%ProgramFiles%\Helper\1205593098.dll
%windir%\SysWOW64\a9kpoyj.dll
%windir%\SysWOW64\a9tya9g.dll
%windir%\SysWOW64\af2ioi7.dll
%windir%\SysWOW64\afj3k99.dll
%windir%\SysWOW64\bmjp25q.dll
%windir%\SysWOW64\bysg6r4.dll
N:\patp.exe
%windir%\SysWOW64\d3yzriv.dll
%windir%\SysWOW64\d42idnp.dll
%windir%\SysWOW64\e9eiwew.dll
%windir%\SysWOW64\el7f9cs.dll
%ProgramFiles%\_rejoice2009.exe
%ProgramFiles%\hewlett-packard\default settings\cpqset.exe
%windir%\SysWOW64\erc3dk3.dll
%windir%\SysWOW64\f89ozph.dll
%windir%\SysWOW64\gc1zn5v.dll
%windir%\SysWOW64\gcmtilx.dll
N:\pbwkwj.COM
%windir%\SysWOW64\hdbrahx.dll
%windir%\SysWOW64\hscd3md.dll
%windir%\SysWOW64\i3z251f.dll
%windir%\SysWOW64\jj3o7s7.dll
%windir%\SysWOW64\k2691bc.dll
%windir%\SysWOW64\kambidt.dll
%ProgramFiles%\Hewlett-Packard\HPZ\Glue\vmhpfsched.exe
%windir%\SysWOW64\nswo6p5.dll
%windir%\SysWOW64\pf7pg3c.dll
%windir%\SysWOW64\pk6ssln.dll
N:\pchkh.cmd
%windir%\SysWOW64\prsgrc.dll
%windir%\SysWOW64\q08oitn.dll
%windir%\SysWOW64\r6p7i2c.dll
%windir%\SysWOW64\rq6s5eb.dll
%windir%\SysWOW64\saw1xwv.dll
%windir%\SysWOW64\tal84gc.dll
%windir%\SysWOW64\tnzp27s.dll
%ProgramFiles%\HomeAntivirus2010\HomeAntivirus2010.exe
%windir%\SysWOW64\ttultdr.dll
%windir%\SysWOW64\u2dip8n.dll
%ProgramFiles%\cfbsvq.dll
%windir%\SysWOW64\v9o1vfs.dll
%windir%\SysWOW64\w0h1cbp.dll
%windir%\SysWOW64\wj3y40q.dll
%windir%\SysWOW64\xyt9nbw.dll
%windir%\SysWOW64\ycirz9f.dll
%windir%\t.bat
%windir%\taobao.ico
%windir%\tar.exe
%ProgramFiles%\hp deskjet 948c series\rmhpfiui.exe
%windir%\Task\752ac.job
%Temp%\mc21.tmp
%windir%\task\752b.job
%windir%\Tasks\2VeFNvQbcyFhKUaXTVE9.inf
%windir%\Tasks\7xa6vJPUxshvgQhTZH.inf
%windir%\Tasks\c2nH4numz9knY5zqnC.inf
%windir%\Tasks\CgbYR44s5jCmgAd6ar.inf
%Windir%\Tasks\conime.exe
%windir%\Tasks\CxsxepuZefXkXcNY8h.inf
%windir%\Tasks\EfEPEaD4ZpVMUXrDbS.inf
%windir%\Tasks\FkTQEF2gVvZ9fR7v5HE.inf
%ProgramFiles%\hpdeskjet948cseries\gbhpfxicm.exe
N:\pjben6y.exe
%windir%\Tasks\JJX5r8wnsqUnNxGwpwn.inf
%windir%\Tasks\K6xzVUK4MRGJBPE76F.inf
%windir%\Tasks\KzuFUQHxezWBCenC2A.inf
%windir%\Tasks\SbrmpxjdCrgRAFhz4gHh.inf
%windir%\Tasks\taskmgr.exe
%windir%\Tasks\txPsQUxAThX8QTR6s6Yn.inf
%windir%\Tasks\ybmux4Mu6FUnQJEHWu.inf
%windir%\Tasks\yGfdVUegEQm9fhY5rnN.inf
%windir%\tbsetup(-33554365).exe
%windir%\tcpsvr1.exe
N:\pjwtv.cmd
%ProgramFiles%\HR9ZKHL6RS\X69BYXJJKP.EXE
%windir%\tcpsvr2.exe
%windir%\tcpsvr3.exe
%windir%\tcpsvrs1.exe
%windir%\tcpsyi2.exe
%windir%\tcpsyi3.exe
%windir%\tdhy.exe
%windir%\TElem32.dll
%windir%\Temp\~5.bat
%windir%\Temp\~6088875.ex
N:\pkxfkrki.bat
%windir%\temp\012.exe
%ProgramFiles%\icicyo.exe
%Windir%\Temp\012027.exe
%windir%\temp\100172046.dll
%windir%\temp\10203343.dll
%windir%\TEMP\11478.exe
%windir%\temp\120122906.dll
%windir%\temp\130279875.dll
%windir%\temp\140187156.dll
%windir%\temp\160261203.dll
M:\baksql.bat
N:\pllq.exe
%windir%\temp\170139953.dll
%windir%\temp\180166093.dll
%ProgramFiles%\idm\quickfind\PlugIns\IEHelp.dll
%windir%\temp\190214625.dll
%windir%\temp\200238859.dll
%windir%\temp\20227625.dll
%windir%\TEMP\21.exe
%windir%\temp\210246843.dll
%windir%\temp\220271437.dll
%windir%\temp\230220531.dll
N:\pnc.exe
%windir%\temp\250252046.dll
%windir%\TEMP\29358.exe
%Windir%\Temp\321109.exe
%ProgramFiles%\ie6.exe
%Windir%\Temp\32446.exe
%windir%\TEMP\3443734.exe
%windir%\temp\40288015.dll
%windir%\TEMP\41.exe
%windir%\temp\50158078.dll
%windir%\temp\60195203.dll
N:\popo.exe
%windir%\temp\70130953.dll
%windir%\TEMP\732171.txt
%windir%\TEMP\76.exe
%windir%\temp\80146906.dll
%ProgramFiles%\Iibt\Qybvouabf.bmp
%windir%\TEMP\ACQV1.EXE
%windir%\TEMP\bra9.tmp
%windir%\TEMP\c.dll
%windir%\TEMP\ff.exe
%windir%\TEMP\GBNP2.EXE
N:\ppinbnp9.exe
%windir%\TEMP\GKQN1.EXE
%windir%\TEMP\IXUV0.EXE
%windir%\TEMP\JGPF2.EXE
%windir%\TEMP\JREA1.EXE
%windir%\TEMP\KFWU0.EXE
%ProgramFiles%\0ULAII5T390H\QYGO7.EXE
%ProgramFiles%\inst.exe
%windir%\TEMP\LWWR1.EXE
%windir%\TEMP\mc25.tmp
%windir%\TEMP\MCWR0.EXE
N:\prjydpe.cmd
%windir%\TEMP\MPGR2.EXE
%windir%\TEMP\ntdll64.dll
%windir%\TEMP\poihnapnbudgcg.sys
%windir%\TEMP\pp.exe
%windir%\TEMP\pqa8.tmp
%windir%\TEMP\QLFQ2.EXE
%windir%\TEMP\RWVB0.EXE
%ProgramFiles%\Internet Explorer\002.tmp
%windir%\temp\swymq.exe
%windir%\Temp\TDSS3a1c.tmp
N:\px.bat
%windir%\Temp\TDSS639d.tmp
%windir%\Temp\TDSS6a34.tmp
%windir%\Temp\TDSS6e99.tmp
%windir%\Temp\TDSS72df.tmp
%windir%\Temp\TDSS7735.tmp
%windir%\Temp\TDSS7c65.tmp
%windir%\temp\tmp.exe
%windir%\TEMP\tmp11.tmp
%ProgramFiles%\Internet Explorer\53u1ttMe.2ys
%windir%\temp\uuu.exe
N:\pxbn6y.exe
%windir%\TEMP\wmsetup.dll
%windir%\Temp\wpv061273735655.exe
%windir%\Temp\wpv071242765100.exe
%windir%\Temp\wpv101273913086.exe
%windir%\Temp\wpv281274083779.exe
%windir%\Temp\wpv361273934964.exe
%windir%\Temp\wpv401254983689.exe
%windir%\Temp\wpv461254042811.exe
%windir%\temp\wpv541273735473.exe
%ProgramFiles%\Internet Explorer\aaaa(0).exe
%Temp%\mhso.exe
%windir%\Temp\wpv551254042811.exe
%windir%\Temp\wpv711273931622.exe
%windir%\Temp\wpv711274083878.exe
%windir%\Temp\wpv741254007820.exe
%windir%\temp\wpv831272465393.exe
%windir%\Temp\wpv841273913623.exe
%windir%\Temp\wpv881254042811.exe
%Windir%\TEMP\xouf.tmp\svchost.exe
%windir%\Temp\xrg1.exe
%windir%\test.exe
N:\pytnmk.exe
%ProgramFiles%\Internet Explorer\aaaa(1).exe
%windir%\thtxx.exe
%windir%\timessquare.exe
%windir%\tinlater.exe
%windir%\tmp93375.bat
%Windir%\tool1.exe
%Windir%\tool2.exe
%Windir%\tool3.exe
%Windir%\tool4.exe
%Windir%\tool5.exe
N:\q.bat
%Windir%\toolbar.exe
%ProgramFiles%\Internet Explorer\aaaa(2).exe
%windir%\TSSafeEdit.DAT
%windir%\tt.exe
%windir%\ttile.exe
%windir%\twunk_64.exe
%windir%\u.bat
%windir%\udem.exe
%windir%\udhwgxxs.exe
%windir%\udv.exe
M:\Beanfun.exe
N:\q.exe
%WinDir%\Uer.bat
%windir%\ufixitprotector.exe
%ProgramFiles%\Internet Explorer\agiexplore.exe
%windir%\Uhupokuhu.dll
%windir%\uifile.exe
%windir%\UIN_OD01.EXE
%windir%\ujuro.dll
%windir%\ukajimoced.com
%windir%\uninstal.BAT
%WINDIR%\uninstall\rundl132.exe
N:\q0rppr.exe
%windir%\unit.dll
%windir%\unyq.com
%windir%\UoDo\game.dll
%ProgramFiles%\Internet Explorer\Antikrphh.exe
%windir%\Update.dll
%windir%\urnetf.dll
%windir%\Usaji.dll
%Windir%\usb6xxxkl.sys
%windir%\userinit.exe
%windir%\userxp.exe
N:\q10js.exe
%windir%\usmsho.dll
%windir%\usmsvc.exe
%WinDir%\Utility Mang.exe
%windir%\uzabozyh.com
%ProgramFiles%\Internet Explorer\BoboChen.jsp
%windir%\v8jh2akbdg.exe
%windir%\vasyzity.com
%windir%\vdll.dll
%windir%\vfdg2evxx.exe
%windir%\vfdh23g.exe
N:\q1pady.cmd
%windir%\vfhyjh.exe
%windir%\vfpcs60.dll
%windir%\vg8iqb.dll
%windir%\vlc.exe
%windir%\vrsdg.exe
%ProgramFiles%\Internet Explorer\CoboMake.jsp
%windir%\vsnp2uvc.exe
%windir%\vsvxx.exe
%windir%\vtdfhgbfv.exe
%windir%\vva.exe
N:\q2.exe
%windir%\vvxx.exe
%windir%\VWTYIQ1G.exe
%windir%\VZHFDBKI.DLL
%windir%\w0pg2p3u68s.exe
%windir%\WanPacket.dll
%windir%\waw.exe
%ProgramFiles%\123\2\3\gaopdxxcvhlmtd.dll
%ProgramFiles%\Internet Explorer\CoboMakt.asp
%windir%\wdmaud.drv
%windir%\wdmon.exe
N:\q2vl2fiy.com
%windir%\WDVRCtrl.exe
%windir%\WEB\csrss.exe
%WINDIR%\Web\PRINTERS\IMAGES\1khgfs.dll
%windir%\Web\printers\images\dfgdfgdfgwer.dll
%windir%\Web\printers\images\drcerwq.dll
%windir%\Web\printers\images\herwx.dll
%windir%\Web\printers\images\jhgfd.dll
%windir%\Web\printers\images\jhtwesd.dll
%ProgramFiles%\Internet Explorer\conin.exe
%windir%\Web\printers\images\khgf2.dll
N:\q83iwmgf.bat
%windir%\Web\printers\images\khgf2.exe
%WINDIR%\Web\PRINTERS\IMAGES\khgfs.dll
%windir%\Web\printers\images\kudes.dll
%WINDIR%\WEB\PRINTERS\IMAGES\NANJING.DLL
%windir%\Web\printers\images\ndmai.dll
%windir%\Web\printers\images\taiwan.dll
%windir%\Web\printers\images\windowses.dll
%windir%\Web\rundll32.exe
%windir%\wet.exe
%ProgramFiles%\Internet Explorer\Connection Wizard\azinetwiz.exe
N:\qb1.exe
%windir%\wftadfi16_090415a.dll
%windir%\WFXDEL.BAT
%windir%\wiadss.exe
%windir%\Win32DLL.vbs
%windir%\window.exen2.3322.org
%windir%\WINDOWS\ccproxy.exe
%windir%\WINDOWS\SVSHOST.exe
%windir%\WinFZG.dll
%windir%\winhoq32.dll
%windir%\winimg.exe
%Temp%\mnso.exe
%ProgramFiles%\Internet Explorer\Connection Wizard\coinetwiz.exe
%windir%\winlogin.scr
%windir%\WINLOGON.EXE
%windir%\winpafile.dll
%windir%\winpow32.dll
%windir%\winpsfisle.dll
%windir%\winsccoo.exe
%windir%\winsscoo.exe
%windir%\winsys.exe
%windir%\wintfgh.bat
N:\qh.cmd
%windir%\wintfgh.DLL
%ProgramFiles%\Internet Explorer\Connection Wizard\hhinetwiz.exe
%windir%\winup.exe
%windir%\winupdater.exe
%windir%\winyyy.sys
%windir%\wmedia32.exe
%windir%\wmerrrCHS.dll
%windir%\woca.exe
%windir%\wora.exe
%windir%\wos3.exe
M:\bn0.bat
N:\qjatw9aj.exe
%windir%\wpcap.dll
%windir%\wsctf.exe
%ProgramFiles%\Internet Explorer\Connection Wizard\icwsetup.exe
%windir%\wuauclt.exe
%windir%\wue.exe
%windir%\wupig.dll
%Windir%\wx.exe
%windir%\wzt.exe
%windir%\x1.exe
%windir%\xcopy.exe
N:\qjfl.exe
%windir%\xhddos.exe
%windir%\xm.exe
%windir%\XRJWHMULHU.txt
%ProgramFiles%\Internet Explorer\Connection Wizard\ilicwconn1.exe
%windir%\xx.exe
%windir%\y.BAT
%Windir%\y.exe
%windir%\Y0HWA.exe
%windir%\y9a4rlbtyn9q.exe
%windir%\yba.exe
N:\qkarc.exe
%windir%\yf.BaT
%windir%\yhuwofofo.sys
%windir%\yhx.exe
%windir%\ynicacyqo.bat
%ProgramFiles%\Internet Explorer\Connection Wizard\oeicwtutor.exe
%windir%\YNTUMS_A.EXE
%Windir%\Yt.BaT
%windir%\yv.BAt
%windir%\yy.exe
%windir%\z.bat
N:\qkolx.exe
%windir%\zd2c9hreat25203.dll
%windir%\zee8b9ckdoor555.dll
%windir%\ZROALVKHXLGCDL.log
%windir%\zt.exe
%windir%\zts3.exe
%ProgramFiles%\Internet Explorer\Connection Wizard\oticwconn2.exe
%windir%\zuhyryw.exe
%windir%\zukeqek.bat
%windir%\zzjmnjdl.exe
%windiws%\d.exe
N:\qngbvkhl.exe
C:\Documents and Settings\Administrator\「開始」功能表\程式集\啟動\Seagate 註冊.lnk
C:\Documents and Settings\Administrator\Application Data\drivers\111wfs1intwq.sys
C:\Documents and Settings\Administrator\Application Data\inst.exe
C:\Documents and Settings\Administrator\Application Data\jadujixyf.dll
C:\Documents and Settings\Administrator\Application Data\lizkavd.exe
C:\Documents and Settings\Administrator\Application Data\ojydik.dll
%ProgramFiles%\Internet Explorer\Connection Wizard\pwicwtutor.exe
C:\Documents and Settings\Administrator\Application Data\seres.exe
C:\Documents and Settings\Administrator\Application Data\svcst.exe
C:\Documents and Settings\Administrator\Application Data\trust obj\dxatdfyk.exe
N:\qotdyl.bat
C:\Documents and Settings\Administrator\Application Data\trust obj\femwxmlk.exe
C:\Documents and Settings\Administrator\Application Data\trust obj\Flap cake.exe
C:\Documents and Settings\Administrator\Application Data\xymowop.com
C:\Documents and Settings\Administrator\Cookies\zyxofyly.bat
C:\Documents and Settings\Administrator\cson.exe
C:\Documents and Settings\Administrator\delself.bat
C:\Documents and Settings\Administrator\Local Settings\Application Data\~FileLockReboot.tmp
%ProgramFile%\ainmet\Rainmeter.exe
%ProgramFiles%\123\2\3\gaopdxxcvhlmtd_1050.VIR
%ProgramFiles%\Internet Explorer\Connection Wizard\rlicwtutor.exe
N:\qpe6.com
C:\Documents and Settings\Administrator\Local Settings\Application Data\oxirecur.com
C:\Documents and Settings\Administrator\msword98.exe
C:\Documents and Settings\Administrator\restorer64_a.exe
C:\Documents and Settings\All Users.WINDOWS\「開始」功能表\程式集\啟動\d9wgrdiv1tfccbf40r.exe
C:\Documents and Settings\All Users.WINDOWS\Application Data\18712304\18712304.exe
C:\Documents and Settings\All Users\「開始」功能表\程式集\啟動\1681.lnk
C:\Documents and Settings\All Users\「開始」功能表\程式集\啟動\8K5IO6YR.lnk.exe
C:\Documents and Settings\All Users\「開始」功能表\程式集\啟動\f2hipwscn0erog289s.exe
C:\Documents and Settings\All Users\「開始」功能表\程式集\啟動\k66xo6mv4s4uxn.exe
C:\Documents and Settings\All Users\「開始」功能表\程式集\啟動\Kill Amcap.lnk
N:\qr.exe
%ProgramFiles%\Internet Explorer\Connection Wizard\sticwrmind.exe
C:\Documents and Settings\All Users\「開始」功能表\程式集\啟動\MDUQNR91.lnk.exe
C:\Documents and Settings\All Users\「開始」功能表\程式集\啟動\msconfig32.lnk
C:\Documents and Settings\All Users\「開始」功能表\程式集\啟動\pew61qeftdgqocw.exe
C:\Documents and Settings\All Users\「開始」功能表\程式集\啟動\q0op3nq07mvd.bat
C:\Documents and Settings\All Users\「開始」功能表\程式集\啟動\U2372.lnk.exe
C:\Documents and Settings\All Users\「開始」功能表\程式集\啟動\WY0QH7.lnk.exe
C:\Documents and Settings\All Users\2.exe
C:\Documents and Settings\All Users\Application Data\03863121.exe
C:\Documents and Settings\All Users\Application Data\15910934\15910934.exe
N:\qs6m.bat
C:\Documents and Settings\All Users\Application Data\16220144\16220144.exe
%ProgramFiles%\Internet Explorer\Connection Wizard\vbicwrmind.exe
C:\Documents and Settings\All Users\Application Data\17207825.exe
C:\Documents and Settings\All Users\Application Data\17207825\17207825.exe
C:\Documents and Settings\All Users\Application Data\18303594\18303594.exe
C:\Documents and Settings\All Users\Application Data\18874064\18874064.exe
C:\Documents and Settings\All Users\Application Data\19121874\19121874.exe
C:\Documents and Settings\All Users\Application Data\19335464\19335464.exe
C:\Documents and Settings\All Users\Application Data\23190465FD.sys
C:\Documents and Settings\All Users\Application Data\24yO5072.exe
%Temp%\mpxywic.dll
C:\Documents and Settings\All Users\Application Data\3DD93860C2.sys
C:\Documents and Settings\All Users\Application Data\95920926\95920926.exe
%ProgramFiles%\Internet Explorer\Connection Wizard\vdicwconn2.exe
C:\Documents and Settings\All Users\Application Data\98313586\98313586.exe
C:\Documents and Settings\All Users\Application Data\ABOUT TEAM INFO SECT\Extra Pure.exe
C:\Documents and Settings\All Users\Application Data\afecubi.exe
C:\Documents and Settings\All Users\Application Data\B6727BDAC4.sys
C:\Documents and Settings\All Users\Application Data\bike bold move shim\ante dale.exe
C:\Documents and Settings\All Users\Application Data\burn download defy inside\mail pile.exe
C:\Documents and Settings\All Users\Application Data\burn download defy inside\Safe Browse.exe
%Temp%\828048
N:\qsid8g.exe
C:\Documents and Settings\All Users\Application Data\cast dale way math\browse vga.exe
C:\Documents and Settings\All Users\Application Data\comcat.exe
C:\Documents and Settings\All Users\Application Data\does dog two city\MEDIA WAVE.exe
%ProgramFiles%\Internet Explorer\Connection Wizard\vyicwconn2.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\LPK.DLL
C:\Documents and Settings\All Users\Application Data\esusoq.sys
C:\Documents and Settings\All Users\Application Data\flag ace stupid data\Love info.exe
C:\Documents and Settings\All Users\Application Data\flag ace stupid data\type grim.exe
C:\Documents and Settings\All Users\Application Data\FreeApp_Rezer.exe
C:\Documents and Settings\All Users\Application Data\fypexudim.sys
N:\r.com
C:\Documents and Settings\All Users\Application Data\internet settings clock blue\creative heart.exe
C:\Documents and Settings\All Users\Application Data\ityt.exe
C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
C:\Documents and Settings\All Users\Application Data\kingsoft\*.*
%ProgramFiles%\Internet Explorer\Connection Wizard\weicwconn2.exe
C:\Documents and Settings\All Users\Application Data\KrMS5wpauYa.exe
C:\Documents and Settings\All Users\Application Data\lanmao.exe
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\gdi.exe
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\2012.exe
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\2097.exe
N:\r.exe
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\2214.exe
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\YiqilaiLyrics_2001.exe
C:\Documents and Settings\All Users\Application Data\Microsoft\Media Player\obj\wmpobj.sys
C:\Documents and Settings\All Users\Application Data\Microsoft\Media Player\wmp\mtlrd.sys
C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\2ohwUveEqL_2263.exe
%ProgramFiles%\Internet Explorer\ConnectionWizard\kwicwtutor.exe
C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\fdHrupPQg8_2263.exe
C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\finder.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\m7F5xSG70T_2263.exe
C:\Documents and Settings\All Users\Application Data\Microsoft\Office\SYSTEM\V4JHMMkCxL.exe
N:\r120.bat
C:\Documents and Settings\All Users\Application Data\Microsoft\Office\USERDATA\c7dhcQCrhr_2002.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\Office\USERDATA\UcRew1FjO5.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2012.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2234.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\Outlook Express\2234.exe
C:\Documents and Settings\All Users\Application Data\Microsoft\PCTools\pctools.dll
%ProgramFiles%\Internet Explorer\CSRSS.exe
C:\Documents and Settings\All Users\Application Data\Microsoft\Protect\svhost.exe
C:\Documents and Settings\All Users\Application Data\Microsoft\Protect\track.sys
C:\Documents and Settings\All Users\Application Data\Microsoft\wd\*.*
N:\r2mkn.exe
C:\Documents and Settings\All Users\Application Data\nBwhGyYIndfV.exe
C:\Documents and Settings\All Users\Application Data\noti.sys
C:\Documents and Settings\All Users\Application Data\NRmq1l44p.exe
C:\Documents and Settings\All Users\Application Data\oUrVPuPddVDgXoF.exe
C:\Documents and Settings\All Users\Application Data\qtrTdkRFQkQo.dll
C:\Documents and Settings\All Users\Application Data\remube.dll
C:\Documents and Settings\All Users\Application Data\sBiLfGvINagxmit.exe
%ProgramFiles%\Internet Explorer\D9.dll
C:\Documents and Settings\All Users\Application Data\STORE LESS JUGS SURF\HIDE DEAF.exe
C:\Documents and Settings\All Users\Application Data\svhost.exe
N:\r8wb.bat
C:\Documents and Settings\All Users\Application Data\t2jDx9PgC.exe
C:\Documents and Settings\All Users\Application Data\Tick Find Close Surf\grid show.exe
C:\Documents and Settings\All Users\Application Data\urawofyje.exe
C:\Documents and Settings\All Users\Application Data\wd\kswbc.dll
C:\Documents and Settings\All Users\Application Data\wd\kswebshield.dll
C:\Documents and Settings\All Users\Application Data\wd\KSWebShield.exe
C:\Documents and Settings\All Users\Application Data\wd\kwssp.dll
C:\Documents and Settings\All Users\Application Data\wd\kwsui.dll
%ProgramFiles%\Internet Explorer\DotooBt.doc
C:\Documents and Settings\All Users\application data\weemi\weemi129.exe
N:\r9ghv9.com
C:\Documents and Settings\All Users\Application Data\YRUvoXXeDU.exe
C:\Documents and Settings\All Users\Documents\Fun.exe
C:\Documents and Settings\All Users\Documents\gxcdue.exe
C:\Documents and Settings\All Users\Documents\inugalav.sys
C:\Documents and Settings\All Users\Documents\jepi.com
C:\Documents and Settings\All Users\Documents\kelemygij.bat
C:\Documents and Settings\All Users\Documents\lytavib.com
C:\Documents and Settings\All Users\Documents\odosoco.sys
C:\Documents and Settings\All Users\Documents\ryrusipeh.dll
%ProgramFiles%\123\2\3\gaopdxxcvhlmtd_be8.VIR
N:\rcpi.exe
%ProgramFiles%\Internet Explorer\DotoooBt.doc
C:\Documents and Settings\All Users\Documents\tidado.bat
C:\Documents and Settings\All Users\Documents\zakiq.bat
C:\Documents and Settings\All Users\Favorites\KUDAJYBV.exe
C:\Documents and Settings\Default User\「開始」功能表\程式集\啟動 的目錄\cmd.cmd
C:\Documents AND Settings\Local Qf\NATzyc.dll
C:\Documents and Settings\Local User\QQpinyin.dll
C:\Documents and Settings\LocalService\Application Data\Dna.sys
C:\Documents and Settings\LocalService\Application Data\lizkavd.exe
C:\Documents and Settings\supervisor\Local Settings\Temp\704671_xeex.exe
N:\rehsas.com
D:\Download\BFSDRV.sys
%ProgramFiles%\Internet Explorer\DxPlroBt.Rxf
D:\Download\BREGDRV.sys
D:\Windows Media Player\*.*
D:\Windows Media Player\Program Files\npdrmv2.jpg
C:\Documents and Settings\Administrator\fswagz.exe
%SystemDrive%\Documents and Settings\Administrator\fswagz.exe
%UserProfile%\fswagz.exe
%SystemDrive%\ProgramData\43a5a334-80c5-4815-bc0d-590e9356b558.dat
%ProgramFiles%\43a5a334-80c5-4815-bc0d-590e9356b558.dat
N:\resycled\boot.com
%SystemDrive%\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{EC9A6CA3-4F8B-4F10-84B0-72079D90295B}\MpKsl5d04b853.sys
%SystemDrive%\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{B3729834-B7F4-4B68-A162-1C44DF1F5A52}\MpKsl75cb81fe.sys
%ProgramFiles%\Internet Explorer\Explo2eMt.456
%SystemDrive%\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{89A7570E-27B4-46C1-917C-54565265AC4D}\MpKsl834fa970.sys
%SystemDrive%\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{92E75D72-766E-4F56-BF79-670C2FAE4C47}\MpKslc81d2729.sys
%ProgramFiles%\Microsoft\Microsoft Antimalware\Definition Updates\{EC9A6CA3-4F8B-4F10-84B0-72079D90295B}\MpKsl5d04b853.sys
%ProgramFiles%\Microsoft\Microsoft Antimalware\Definition Updates\{B3729834-B7F4-4B68-A162-1C44DF1F5A52}\MpKsl75cb81fe.sys
%ProgramFiles%\Microsoft\Microsoft Antimalware\Definition Updates\{89A7570E-27B4-46C1-917C-54565265AC4D}\MpKsl834fa970.sys
%ProgramFiles%\Microsoft\Microsoft Antimalware\Definition Updates\{92E75D72-766E-4F56-BF79-670C2FAE4C47}\MpKslc81d2729.sys
C:\Documents and Settings\Administrator\cbzvl.exe
M:\BNB_029.exe
%Temp%\msdfjsadfjd.dat
%SystemDrive%\Documents and Settings\Administrator\cbzvl.exe
%UserProfile%\cbzvl.exe
%windir%\avp.exe
%ProgramFiles%\Internet Explorer\explor.exe
%Windir%\ e.exe
%windir%\admier.exe
%windir%\ali.exe
%windir%\BDE32.dll
%windir%\cl200961.exe
%windir%\DEBUG\096476AA7661.dll
N:\rf.cmd
%windir%\DEBUG\0C9C4681802F.dll
%windir%\DEBUG\0C9C4681802F.exe
%windir%\DEBUG\1D54BD5BC206.dll
%windir%\DEBUG\1D54BD5BC206.exe
%ProgramFiles%\Internet Explorer\export.exe
%windir%\DEBUG\231346E28D27.dll
%windir%\DEBUG\231346E28D27.exe
%windir%\DEBUG\2798448C9E17.dll
%windir%\DEBUG\29124D4AA81F.dll
%windir%\DEBUG\29124D4AA81F.exe
N:\rjiybg.exe
%windir%\DEBUG\31AB48B7A1FE.dll
%windir%\DEBUG\31AB48B7A1FE.exe
%windir%\DEBUG\35C4496FB94C.dll
%windir%\DEBUG\35C4496FB94C.exe
%windir%\DEBUG\3A164BDB8EB1.dll
%ProgramFiles%\Internet Explorer\fzsKetNt.Ps2
%windir%\DEBUG\3E9F4542BFB2.dll
%windir%\DEBUG\62D4F8F5DDAC.DLL
%windir%\DEBUG\62D4F8F5DDAC.EXE
%windir%\DEBUG\6C2E46F9BF9F.dll
N:\rjx0.exe
%windir%\DEBUG\6C2E46F9BF9F.exe
%windir%\DEBUG\85E94AF2BCA4.dll
%windir%\DEBUG\85E94AF2BCA4.exe
%windir%\DEBUG\88EB427299AC.dll
%windir%\DEBUG\88EB427299AC.exe
%windir%\DEBUG\8BF414B99AFE.dll
%ProgramFiles%\Internet Explorer\hjkiubreb.scr
%windir%\DEBUG\8BF414B99AFE.exe
%windir%\DEBUG\92F54D81A560.dll
%windir%\DEBUG\92F54D81A560.exe
N:\rmydqsiw.exe
%windir%\DEBUG\94524F281A33.dll
%windir%\DEBUG\948640568BF9.dll
%windir%\DEBUG\B831406A9770.dll
%windir%\DEBUG\B831406A9770.exe
%windir%\DEBUG\B8334CF3A8B1.dll
%windir%\DEBUG\BE8540978C80.dll
%windir%\DEBUG\BE8540978C80.exe
%ProgramFiles%\internet explorer\iedw.dll
%windir%\DEBUG\CC34FC9CC812.dll
%windir%\DEBUG\CC34FC9CC812.exe
N:\rn.exe
%windir%\DEBUG\F01A4ACBB854.dll
%windir%\DEBUG\F405430C86A6.dll
%windir%\DEBUG\F405430C86A6.exe
%windir%\Debug\found.exe
%windir%\Debug\found32.dll
%windir%\Debug\Lilo.dll
%windir%\DEBUG\pctools.dll
%windir%\DEBUG\sysutils32.dll
%ProgramFiles%\Internet Explorer\IETimber\IETimber.dll
%windir%\DEBUG\tasb32.dll
N:\rtnlpipu.com
%windir%\DEBUG\tasb32.exe
%windir%\DEBUG\thread.dll
%windir%\DEBUG\web32.dll
%windir%\Debug\winalo.dll
%windir%\DEBUG\winhlp.dll
%windir%\DEBUG\xmlDown.dll
%windir%\DEBUG\xmldown32.dll
%windir%\DownUpdater.exe
%windir%\end32.dll
%ProgramFiles%\internet explorer\launcher.exe
N:\rv36m1f9.exe
%windir%\fly32.dll
%windir%\good32.dll
%windir%\goods32.dll
%windir%\HELP\2ACE4CFBAF2C.dll
%windir%\HELP\2ACE4CFBAF2C.exe
%windir%\Help\30D54BF98859.dll
%windir%\Help\30D54BF98859.exe
%windir%\HELP\3CC74E3FA248.dll
%windir%\HELP\3CC74E3FA248.exe
%windir%\Help\45AD9FCA.dll
N:\rwrte.exe
%ProgramFiles%\123\2\3\gaopdxxcvhlmtd_f1c.VIR
%ProgramFiles%\Internet Explorer\LookHttp.jsp
%windir%\Help\45AD9FCA.exe
%windir%\Help\8B154471.DLL
%windir%\Help\8B154471.exe
%windir%\Help\B41346EFA848.dll
%windir%\Help\B41346EFA848.exe
%windir%\Help\BE124B92.dll
%windir%\Help\BE124B92.exe
%windir%\Help\E5ED8BC94A26.dll
N:\s2vgyp.exe
%windir%\Help\E5ED8BC94A26.exe
%windir%\Help\EB6C4499B05F.dll
%ProgramFiles%\Internet Explorer\mduzhl.exe
%windir%\Help\EB6C4499B05F.exe
%windir%\HELP\F3C74E3FA248.dll
%windir%\HELP\F3C74E3FA248.ex
%windir%\HELP\F3C74E3FA248.exe
%windir%\Help\WINCOOLATICE.dll
%windir%\Help\WINCOOLATICE.exe
%Windir%\inf\3CC74E3FA246.dll
M:\bnkxy.exe
N:\s38k.exe
%Windir%\inf\3CC74E3FA246.exe
%windir%\java\4B8A877E1319.dll
%windir%\java\4B8A877E1319.exe
%ProgramFiles%\Internet Explorer\MicioSoft.scr
%windir%\java\4D1B90FDDF6B.dll
%windir%\java\4D1B90FDDF6B.exe
%windir%\JAVA\914BD3003935.DLL
%windir%\java\A1224A67C97A.dll
%windir%\java\A1224A67C97A.exe
%windir%\JAVA\A4C9484C051E.dll
%Temp%\msdll.dat
%windir%\scrker.exe
%windir%\svchost.exe
%windir%\wincheck.exe
C:\3.exe
%ProgramFiles%\Internet Explorer\msimg32.dll
C:\300y.cmd
C:\30c0e.cmd
C:\30ed3.exe
C:\31n3b2h.exe
C:\32o3.cmd
N:\s39tg.cmd
C:\35e.exe
C:\360Geywt.exe
C:\38s3i.exe
C:\39ysi89.com
C:\3bo9tn.cmd
%ProgramFiles%\Internet Explorer\msvcrt.dll
C:\3ce.exe
C:\3dohrt.com
C:\3ds.cmd
C:\3ehxs6.cmd
N:\s6.bat
C:\3g3.exe
C:\3hihyi.exe
C:\3iugonx.com
C:\3jkka91.com
C:\3jkkdo.exe
C:\3o0fp.exe
%ProgramFiles%\Internet Explorer\mzyqmh.exe
C:\3p9wj19.exe
C:\3r33c.CMD
C:\3vf9968r.exe
N:\s6muem.cmd
C:\3wmvmd.cmd
C:\3wy1vm.cmd
C:\3y.bat
C:\3yr1.cmd
C:\535.exe
C:\6.bat
C:\6.exe
%ProgramFiles%\Internet Explorer\New7Mail.vbs
C:\62oop0ak.bat
C:\63e.exe
N:\s8.exe
C:\6hg.exe
C:\6j2j.com
C:\6o0.bat
C:\6phx.com
C:\6qe.com
C:\6r3p.com
C:\6rq6.exe
C:\6vu680.com
%ProgramFiles%\Internet Explorer\NewBho.dll
C:\6wqhah.exe
N:\s9l.exe
C:\6xdgw26.com
C:\806.com
C:\82.exe
C:\82i.cmd
C:\82tgk9eg.exe
C:\8386nac.com
C:\8a.exe
C:\8ae2q.exe
C:\8b3.bat
%ProgramFiles%\Internet Explorer\PLUGINS\b54321.bho
N:\SafeSys.exe
C:\8df.EXE
C:\8e.com
C:\8gidy.exe
C:\8h3hh3m.exe
C:\8iyqbsp1.exe
C:\8m08ty.com
C:\8mt8bm.exe
C:\8nlo1q.cmd
C:\8ot8y86.exe
C:\8oupido.bat
N:\sasyg1y8.com
%ProgramFiles%\Internet Explorer\PLUGINS\DosSys08.Sys
C:\8ox61l6.cmd
c:\8q6h.exe
C:\8tss2gwq.bat
C:\8u.com
C:\8uot.exe
C:\8xlwbngd.exe
C:\90imhpnc.exe
C:\91.exe
C:\91m.COM
N:\sdc.bat
C:\92j11sm.com
%ProgramFiles%\1FVAVY3AO\RI770RKVH.EXE
%programfiles%\Internet Explorer\PLUGINS\NEWTEMP.BAK
C:\96.com
C:\9b8kmipy.com
C:\9bid6bl.exe
C:\9dl.cmd
C:\9es.com
C:\9l66g8k1.com
C:\9o.exe
M:\bnmv.exe
N:\se11.cmd
C:\9r8hh2f.exe
C:\9tb8ist.bat
C:\9yp8nyvg.exe
%programfiles%\Internet Explorer\PLUGINS\NewTemp.bkk
C:\a.bat
C:\a.exe
C:\a2r.exe
C:\a8qengab.exe
C:\ab.cmd
C:\abqk2c3i.bat
N:\server2010.exe
C:\adba2.exe
C:\af93gcf.exe
C:\af9rgm8h.bat
C:\alt.exe
%programfiles%\Internet Explorer\PLUGINS\NewTemp.dll
C:\aluj8r.exe
C:\anky8.exe
C:\aoutfq.exe
C:\ap.com
C:\atymi09.bat
%Temp%\MsgPlusUninstall.exe
C:\auto.exe
C:\auto.pif
C:\autorun.exe
C:\autorun.inf
C:\autorunx.exe
%programfiles%\Internet Explorer\PLUGINS\system.BAK
C:\autox.exe
C:\avmb.exe
C:\avmt.bak
C:\ay8p6v3.cmd
N:\ServerXp.exe
C:\b.bat
C:\b.cmd
C:\b.exe
C:\Backup.exe
C:\baksql.bat
C:\Beanfun.exe
%programfiles%\Internet Explorer\PLUGINS\system.JMP
C:\blse.bak
C:\bn0.bat
C:\BNB_029.exe
N:\sh.exe
C:\bnkxy.exe
C:\bnmv.exe
C:\bplrl98.cmd
C:\bpvwvays.exe
C:\bpx9q3j.exe
C:\bqcw.bak
C:\bqk.bat
%programfiles%\Internet Explorer\PLUGINS\system16.BAK
C:\brnn.bak
C:\bs3ol8kd2.exe
N:\shadu.exe
C:\bsp.cmd
C:\bt8vuaw.com
C:\bunip.bat
C:\bunp.bak
C:\bxuup9r.bat
C:\c.bat
C:\c.exe
C:\cbpd.exe
%ProgramFiles%\Internet Explorer\PowerDw.Rel
C:\ccc.exe
N:\Shell.exe
C:\CD8IDOYL.COM
C:\ceqfqp.bat
C:\cfv90h.com
C:\check.exe
C:\chlf9.exe
C:\cjrp8.com
C:\cjsc.bak
C:\clc1al.com
C:\clc3k.com
%ProgramFiles%\Internet Explorer\PowerJa.ask
N:\sie2v8.exe
C:\clxam6r6.exe
C:\cm0.com
C:\cmon.exe
C:\cn.exe
C:\co.com
C:\copetttt.com
C:\copy.exe
C:\cp13cg.exe
C:\cube.bak
C:\cubp.bat
N:\SiZhu.exe
%ProgramFiles%\Internet Explorer\PowerJo.ase
C:\d.bat
C:\d.exe
C:\d218eht.exe
C:\d22xl.bat
C:\d3bn0j.exe
C:\d4740.exe
C:\d6r6jmp.exe
C:\d8ur3qs.bat
C:\dagd.exe
N:\slphfx.bat
C:\dblnq.exe
%ProgramFiles%\Internet Explorer\PowerJv.ask
C:\dboycao.exe
C:\ddyikr.CMD
C:\delshare.bat
C:\dgf.exe
C:\dgkx.exe
C:\dh66ln.cmd
C:\dhcore.exe
C:\di3su.exe
M:\39ysi89.com
M:\bplrl98.cmd
N:\sm.exe
C:\dialupass.exe
C:\diox3j.com
%ProgramFiles%\26BI6DJNOIJU\S5P60.EXE
%ProgramFiles%\Internet Explorer\PowerJz.zsk
C:\dmf.exe
C:\down.bat
C:\down.exe
C:\down2.bat
C:\dp.cmd
C:\dp.exe
N:\snaoc9i.exe
C:\dpu1.exe
C:\dqi.exe
C:\dqpw.bak
C:\ds.exe
%ProgramFiles%\Internet Explorer\PowerNeNt.Onz
C:\dsty.com
C:\dv6pp.exe
C:\dvhyi.exe
C:\dwkq.bak
C:\dwpy.bak
N:\SofwareUpdater.exe
C:\dxv.bat
C:\dynrn6e.cmd
C:\dyr2j6mv.exe
C:\e.cmd
C:\e.exe
%ProgramFiles%\Internet Explorer\pqtwdz.exe
C:\e00233it.com
C:\e0t9n6.exe
C:\e6.com
C:\e619e.cmd
%Temp%\ntdll64.dll
C:\E6IEG.EXE
C:\e898.com
C:\eadf6s.exe
C:\eb9ehyh.exe
C:\ecn.com
C:\eeqt.exe
%ProgramFiles%\Internet Explorer\rksldk.dll
C:\eftwl.exe
C:\eg1.cmd
C:\eito.exe
N:\spkr9wou.bat
C:\ejoq.exe
C:\ek.com
C:\ell.exe
C:\erdeIect.com
C:\erjhni.exe
C:\ermvu8.cmd
C:\et.exe
%ProgramFiles%\Internet Explorer\RsenRz.R91
C:\ewatr.cmd
C:\f.bat
N:\SRCHost.exe
C:\f.exe
C:\ff1q0gw.bat
C:\fgj3lc8.exe
C:\find.exe
C:\fipgnfww.cmd
C:\fjb2.exe
C:\fp.exe
C:\fphj6j31.bat
%ProgramFiles%\Internet Explorer\sdk2.dll
C:\fsdg.exe
N:\SRCost.exe
C:\ft8.exe
C:\ftiduico.bat
C:\fufb6tq3.cmd
C:\fvan.exe
C:\fvbk.exe
C:\g.exe
C:\g0.cmd
C:\g2p3s.exe
C:\g8rruyw.exe
%ProgramFiles%\Internet Explorer\SedtMail.R12
N:\stwi.com
C:\g9rv.exe
C:\gaagw.bat
C:\gabptk6d.bat
C:\gclwpivc.cmd
C:\gdsag.exe
C:\ggkxgvf.bat
C:\ggl.cmd
C:\ggqn.exe
C:\ghdf1.com
C:\gicchk2s.exe
N:\suqfl.exe
%ProgramFiles%\Internet Explorer\SedtMazl.Rz2
C:\gmi1jxy.com
C:\gnc.bat
C:\gnwav.exe
C:\gnwwy.exe
C:\gplpn.exe
C:\gqsk.bat
C:\gswrij.exe
C:\gsxlexd.cmd
C:\gx.bat
N:\svchost.exe
C:\gx.com
%ProgramFiles%\Internet Explorer\SentRs.R21
C:\gxul.com
C:\gymussy.bat
C:\h.bat
C:\h.CMD
C:\h0j8w.exe
C:\h0ti1de.bat
C:\h2.com
C:\h2t6u.exe
M:\bpvwvays.exe
N:\svchovst.EXE
C:\h3hi1k3.exe
C:\h8i.com
%ProgramFiles%\Internet Explorer\SentRsst.R31
C:\hfap.exe
C:\higj2p.bat
C:\hn.cmd
C:\hnkvaa2.exe
C:\home.exe
C:\host.exe
C:\hovrflst.bat
N:\system.dll
C:\hpbxpu.exe
C:\hpkq.cmd
C:\hqx292nu.exe
%ProgramFiles%\2kdhb9f4s\y68j889y8.exe
%ProgramFiles%\Internet Explorer\SentRz.R91
C:\hsi.com
C:\hsjnkj.exe
C:\htjtq8o.exe
C:\hupxj.bat
C:\hv8fv2.exe
N:\systex.exe
C:\hvoxmq.exe
C:\hxbpamjb.cmd
C:\hxs.bat
C:\hyj2gunw.exe
C:\i.bat
%ProgramFiles%\internet explorer\setmail.r52
C:\i2.com
C:\ib3qc3t.cmd
C:\if6ch9k6.bat
C:\ig.bat
N:\t.bat
C:\igcmrtjw.cmd
C:\il0byu3h.com
C:\il6.exe
C:\iluqcwr.exe
C:\imt8.cmd
C:\iok.exe
%ProgramFiles%\Internet Explorer\smss.exe
C:\ipy.cmd
C:\iscwam2h.cmd
C:\it1d.exe
%Temp%\ocgien.exe
C:\iu.bat
C:\iw.bat
C:\iwjj.com
C:\ixsla.exe
C:\j.bat
C:\j0.exe
C:\j0mpdkja.cmd
%programfiles%\Internet Explorer\svchost.exe
C:\j1.cmd
C:\j16dp6.exe
N:\t.cmd
C:\j1rxka1n.exe
C:\j83uv.exe
C:\jatxgwcj.bat
C:\jc1r11.exe
C:\jcmmawa.bat
C:\jdt2ofp.exe
C:\jg.com
C:\jg6w3yx.com
%ProgramFiles%\Internet Explorer\svhost32.exe
C:\jhcqxax.exe
N:\t.exe
C:\jix9a.bat
C:\jj2.com
C:\jj2.com.suspicious
C:\jkxrox.exe
C:\jl.com
C:\jlli.bak
C:\jvu69.bat
C:\jwugqi.exe
C:\jy.exe
%ProgramFiles%\Internet Explorer\SVMCOS.exe
N:\t1xdgvq.exe
C:\k.com
C:\k08aww.bat
C:\k2.cmd
C:\k6wkwon2.exe
C:\k9cuos2q.exe
C:\ka1nk.bat
C:\karina///debeja.exe
C:\kdy.cmd
C:\kg18j.exe
C:\kgnkxc.exe
N:\t2f.exe
%ProgramFiles%\Internet Explorer\Sys_NtMe.Zys
C:\kjibu.com
C:\kk.bat
C:\kk36.exe
C:\kk38g1.exe
C:\kpvqk.exe
C:\kqsr.exe
C:\kuqskg2s.bat
C:\kuruna.exe
C:\kya6l.bat
N:\t2jl.exe
C:\l1.cmd
%ProgramFiles%\Internet Explorer\Sys6NtMe.Zys
C:\l3v.exe
C:\l6w2eaih.exe
C:\lass.exe
C:\ldgybkp.bat
C:\lgcadwx.bat
C:\lgnaqil.exe
C:\lgrncie.bat
C:\lgvg8q.exe
M:\bpx9q3j.exe
N:\t2ydo.exe
C:\lhwdcgcb.bat
C:\lj.exe
%ProgramFiles%\Internet Explorer\SysNetNe.Sys
C:\lj6hdv.com
C:\ll.exe
C:\lp3c.bat
C:\lsfjg.com
C:\lsg6jj9.exe
C:\lskeqbfc.exe
C:\ltc.bat
N:\t3.com
C:\lulu.exe
C:\lwd.bat
C:\lyhwcea.exe
%ProgramFiles%\Internet Explorer\SysNetNt.Sys
C:\m.bat
C:\m.exe
C:\m6dqm2vd.exe
C:\m6n.com
C:\m8wafly.com
C:\m9as2c.cmd
N:\t82e2v.cmd
C:\mayyuk9g.bat
C:\mbewb2n.exe
C:\mcmm.bat
C:\mka.bat
%ProgramFiles%\360\360Safe\deepscan\zhudongfangyu.exe
%ProgramFiles%\Internet Explorer\tmiedw.exe
C:\mm6q.exe
c:\MMM.exe
C:\momo.exe
C:\motr.exe
N:\tan3yt.bat
C:\mpstxgx.exe
C:\mrghykh.exe
C:\mrsne.bat
C:\msbackup.exe
C:\msn.exe
C:\mt.com
%ProgramFiles%\Internet Explorer\UfzsKetNt.Ps3
C:\mt0.cmd
C:\mtlhieej.cmd
C:\n.com
N:\tbhje.cmd
C:\n.exe
C:\n1m.exe
C:\n1v93rqo.exe
C:\n6j6pc0.com
C:\n89f1d1w.exe
C:\nbke.exe
C:\ncc.exe
%ProgramFiles%\Internet Explorer\UzzzKtzNt.Ozg
C:\ndmego0f.cmd
C:\net.exe
%Temp%\OCM19.tmp
C:\ngq6hva0.exe
C:\nmje9v6d.bat
C:\nncu6kk.com
C:\nooakkv.exe
C:\np.exe
C:\nq.bat
C:\nqgcd.com
C:\nskmu.exe
%ProgramFiles%\Internet Explorer\Vet4321t.321
C:\nsv.bat
N:\tcburi.exe
C:\nt6ry3bn.cmd
C:\ntdeiect.com
C:\ntdelect.com
C:\NTDETECT.EXE
C:\ntnq.exe
C:\ntphyy.com
C:\nvrfc.bat
C:\nw.exe
C:\nw0t1l0d.exe
%ProgramFiles%\Internet Explorer\VitnNt64.987
N:\temp.exe
C:\nxvhpc.exe
C:\ny36jjt.exe
C:\nyat.exe
C:\O.cmd
C:\o.exe
C:\o6opnro.bat
C:\o6pq1n8.com
C:\o93ml8.bat
C:\o9o2.com
C:\o9o2u.bat
N:\temp28.exe
%ProgramFiles%\Internet Explorer\VneNt64.987
C:\oaljb6.exe
C:\obg.exe
C:\obtpf.bat
C:\oc.cmd
C:\ocbqsqj.bat
C:\Oeboyg.exe
C:\okelg.exe
C:\okhr.exe
C:\ol.exe
N:\tfa8rk6.com
C:\om.cmd
%ProgramFiles%\Internet Explorer\vrfebe.exe
C:\om0.com
C:\op.bat
C:\ot.exe
C:\ot2.exe
C:\otf.cmd
C:\ox.cmd
C:\p.cmd
C:\p0sc9t.cmd
M:\bqk.bat
N:\tg.com
C:\p1t.bat
C:\p3r1ud.exe
%ProgramFiles%\Internet Explorer\Vv54321t.321
C:\p8ihdw.exe
C:\p9.exe
C:\pamn.exe
C:\patp.exe
C:\pbwkwj.COM
C:\pchkh.cmd
C:\pjben6y.exe
N:\tgtighg.cmd
C:\pjwtv.cmd
C:\pkxfkrki.bat
C:\pllq.exe
%ProgramFiles%\Internet Explorer\wybho.exe
C:\pnc.exe
C:\popo.exe
C:\ppinbnp9.exe
C:\prjydpe.cmd
C:\px.bat
C:\pxbn6y.exe
N:\thghikva.exe
C:\pytnmk.exe
C:\q.bat
C:\q.exe
C:\q0rppr.exe
%ProgramFiles%\InternetSecurity2010\IS2010.exe
C:\q10js.exe
C:\q1pady.cmd
C:\q2.exe
C:\q2vl2fiy.com
C:\q83iwmgf.bat
N:\tigi.cmd
C:\qb1.exe
C:\qh.cmd
C:\qjatw9aj.exe
C:\qjfl.exe
C:\qkarc.exe
%ProgramFiles%\360\360safebox\safeboxTray.exe
%ProgramFiles%\IS4FPGIJHL\WYRTL0OBMRG.EXE
C:\qkolx.exe
C:\qngbvkhl.exe
C:\qotdyl.bat
N:\tikett.exe
C:\qpe6.com
C:\qr.exe
C:\qs6m.bat
C:\qsid8g.exe
C:\r.com
C:\r.exe
C:\r120.bat
%ProgramFiles%\j0jnw3iri9s76qq.exe
C:\r2mkn.exe
C:\r8wb.bat
N:\tj8odymw.exe
C:\r9ghv9.com
C:\rcpi.exe
C:\rehsas.com
C:\resycled\boot.com
C:\rf.cmd
C:\rjiybg.exe
C:\rjx0.exe
C:\rmydqsiw.exe
%ProgramFiles%\Java\jre6\bin\rvertool.exe
C:\rn.exe
%ProgramFiles%\cloud\LongRADrv.sys
C:\rtnlpipu.com
C:\ruaa.bak
C:\rv36m1f9.exe
C:\rwrte.exe
C:\s2vgyp.exe
c:\s384..dll
C:\s38k.exe
C:\s39tg.cmd
C:\s6.bat
%ProgramFiles%\Java\jre6\bin\wtjava-rmi.exe
%Temp%\qemy.dll
C:\s6muem.cmd
C:\s8.exe
C:\s9l.exe
C:\SafeSys.exe
C:\sasyg1y8.com
C:\sdc.bat
C:\se11.cmd
C:\server2010.exe
C:\ServerXp.exe
C:\sh.exe
N:\tlmjw.cmd
%ProgramFiles%\JiangMin\Antivirus\KVMonXP.kxp
C:\shadu.exe
C:\Shell.exe
C:\sie2v8.exe
C:\SiZhu.exe
C:\slphfx.bat
C:\sm.exe
C:\snaoc9i.exe
C:\SofwareUpdater.exe
C:\spkr9wou.bat
N:\tmd.exe
C:\spolssv.exe
%ProgramFiles%\Jiangmin\AntiVirus\kvsrvxp.exe
C:\spolusv.exe
C:\SRCHost.exe
C:\SRCost.exe
C:\stwi.com
C:\sunny.exe
C:\suqfl.exe
C:\svchost.exe
C:\svchovst.EXE
M:\bs3ol8kd2.exe
N:\tmf3w3g0.com
c:\svhcsots.exe
c:\svhcuots.exe
%ProgramFiles%\Jmih\Ybpoqxlll.bmp
C:\systex.exe
C:\t.bat
C:\t.cmd
C:\t.exe
C:\t1xdgvq.exe
C:\t2f.exe
C:\t2jl.exe
N:\tmf3w3go.com
C:\t2ydo.exe
C:\t3.com
C:\t82e2v.cmd
%ProgramFiles%\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe
C:\tan3yt.bat
C:\tbhje.cmd
C:\tcburi.exe
C:\temp.exe
c:\temp\svchost.exe
C:\temp28.exe
N:\tn.exe
C:\tfa8rk6.com
C:\tg.com
C:\tgtighg.cmd
C:\thghikva.exe
%ProgramFiles%\KB26633.exe
C:\tigi.cmd
C:\tikett.exe
C:\tj8odymw.exe
C:\tlmjw.cmd
C:\tmd.exe
N:\tn0k.exe
C:\tmf3w3g0.com
C:\tmf3w3go.com
c:\tmp\AD0317220341.exe
C:\tn.exe
C:\tn0k.exe
%ProgramFiles%\Kingsoft\Kingsoft Internet Security V9.0\kas\kaslua.dll
C:\ts6k.exe
C:\tt.com
C:\tudqrfw.exe
C:\txfl1rhh.com
N:\ts6k.exe
C:\tyfr.com
C:\tyvq.exe
C:\u.cmd
C:\u.exe
C:\u08.cmd
C:\u18vxqle.com
%ProgramFiles%\360\360sd\360rp.exe
%ProgramFiles%\kiuzodhz3\yevtolik4.exe
C:\u26ufgv.exe
C:\u2by.exe
N:\tt.com
C:\u3dsc.com
C:\u63urr.exe
C:\u6k.cmd
C:\u82.exe
C:\u99.exe
C:\ud.exe
C:\ufwi6sq.exe
C:\uh.exe
%ProgramFiles%\kpqye\kpqye.ref
C:\uh31.exe
N:\tudqrfw.exe
C:\uhjqlk.exe
C:\un_tc.exe
C:\uorys.cmd
C:\up.exe
C:\up0ppxwr.com
C:\update220.exe
C:\update2201.exe
C:\updater697.exe
C:\UpdateThis.exe
%ProgramFiles%\Lrao\Gvwtsefli.gif
N:\txfl1rhh.com
C:\UpdateWindows.exe
C:\updds3.exe
C:\ups.exe
C:\Ups3.exe
C:\upsf.exe
C:\uptes.exe
C:\upts3.exe
C:\uptsd.exe
C:\Upz.exe
C:\uqb0julr.bat
%Temp%\QGL1B.tmp
%ProgramFiles%\MalwareRemovalBot\MalwareRemovalBot.exe
C:\us8amqf.exe
C:\ut.bat
C:\ut9x.bat
C:\utcn8c63.exe
C:\uuhgt.bat
C:\uwlmj.com
C:\uxkktr.cmd
C:\uyfd9cck.cmd
C:\v0f8rqc.cmd
N:\tyfr.com
C:\v0vj.exe
%ProgramFiles%\meex.exe
C:\v2h3.exe
C:\v3pif.bat
C:\v86htgx.cmd
C:\v9l1l.com
C:\v9l8.exe
C:\v9ug2p2.com
C:\vcf0.exe
C:\vctio.com
M:\bsp.cmd
N:\tyvq.exe
C:\vd91t29.exe
C:\vdej3e.exe
%ProgramFiles%\Messenger\41.exe
C:\vkrg.exe
C:\vmhr.bat
C:\vnkucvv.com
C:\vp.exe
C:\vpqdgkx.com
C:\vt6e.cmd
C:\w.bat
N:\u.cmd
C:\w.cmd
C:\w.exe
C:\w2qagd.com
%ProgramFiles%\Messenger\43.dll
C:\w3dn9f.bat
C:\w6hikrv.com
C:\w9fc.exe
C:\wdm.exe
C:\Webhost2.exe
C:\webhost4.exe
N:\u.exe
C:\Weeiivruved.exe
C:\weg6sp.com
C:\wehds63.exe
C:\wewt425.exe
%ProgramFiles%\Messenger\coshelp.dll
C:\wewtf.exe
C:\wex.exe
C:\wg0kpd.bat
C:\wg6jj0.exe
C:\wglplm6g.bat
N:\u08.cmd
C:\wgp.com
C:\Windows.exe
C:\winhost.exe
C:\winser.exe
C:\wjlc.exe
%ProgramFiles%\Messenger\dcap32.dll
C:\wkcay8u.cmd
C:\wpkx.bat
C:\wstk.exe
C:\wuwu.exe
N:\u18vxqle.com
C:\wv.exe
C:\wycgb8.cmd
C:\wyqrvts.exe
C:\wyzlo.exe
C:\x.bat
C:\x.cmd
%ProgramFiles%\Messenger\msgmr.dll
C:\x1.cmd
C:\x1dg.exe
C:\x1o8uo.exe
N:\u26ufgv.exe
C:\x63rnneh.exe
C:\xa8v8.exe
C:\xadeiect.com
C:\xc.exe
C:\xe9fdii1.cmd
C:\xedex.exe
C:\xene9.bat
%ProgramFiles%\360\360sd\Scan.dll
%ProgramFiles%\Messenger\msnmsgrs.exe
C:\xievhrf.exe
N:\u2by.exe
C:\xjs.exe
C:\xjv.exe
C:\xnfrqlvf.exe
C:\xppg3r6.exe
C:\xpq63xl.exe
C:\xqg0.exe
C:\xqyl68.exe
C:\xue.exe
C:\xv.com
%ProgramFiles%\Messenger\RECserverj.exe
N:\u3dsc.com
C:\xwpehlv.com
C:\xyh.exe
C:\y.com
C:\y319s.exe
C:\y6u.bat
C:\y9rlqi.cmd
C:\yapwjlo.exe
C:\ydmj.exe
C:\yfmqo.cmd
C:\yfpaoty.exe
N:\u63urr.exe
%ProgramFiles%\Messenger\temsmsgs.exe
C:\ygvtn.exe
C:\yh.bat
C:\yi9.exe
C:\yjkjfuo.cmd
C:\ymxf3q.exe
C:\yp.bat
C:\ypjq1.cmd
C:\yq.com
C:\yq00tht.exe
%Temp%\qjso.exe
C:\yt8a.exe
%ProgramFiles%\Messenger\yhmsseces.exe
C:\yv.exe
C:\yw6mmv0.exe
C:\zx.exe
D:\3.exe
D:\300y.cmd
D:\30c0e.cmd
D:\30ed3.exe
D:\31n3b2h.exe
M:\bt8vuaw.com
N:\u6k.cmd
D:\32o3.cmd
D:\35e.exe
%ProgramFiles%\mhzx\tlmhzx1130.dll
D:\38s3i.exe
D:\39ysi89.com
D:\3bo9tn.cmd
D:\3ce.exe
D:\3dohrt.com
D:\3ds.cmd
D:\3ehxs6.cmd
N:\u82.exe
D:\3g3.exe
D:\3hihyi.exe
D:\3iugonx.com
%ProgramFiles%\micros~1.net\lvbyad.dll
D:\3jkka91.com
D:\3jkkdo.exe
D:\3o0fp.exe
D:\3p9wj19.exe
D:\3r33c.CMD
D:\3vf9968r.exe
N:\u99.exe
D:\3wmvmd.cmd
D:\3wy1vm.cmd
D:\3y.bat
D:\3yr1.cmd
%ProgramFiles%\Microsoft Common\svchost.exe
D:\535.exe
D:\6.bat
D:\6.exe
D:\62oop0ak.bat
D:\63e.exe
N:\ud.exe
D:\6hg.exe
D:\6j2j.com
D:\6o0.bat
D:\6phx.com
D:\6qe.com
%ProgramFiles%\Microsoft Common\wuauclt.exe
D:\6r3p.com
D:\6rq6.exe
D:\6vu680.com
D:\6wqhah.exe
N:\ufwi6sq.exe
D:\6xdgw26.com
D:\806.com
D:\82.exe
D:\82i.cmd
D:\82tgk9eg.exe
D:\8386nac.com
%ProgramFiles%\Microsoft Explorer\svmssc.exe
D:\8a.exe
D:\8ae2q.exe
D:\8b3.bat
N:\uh.exe
D:\8df.EXE
D:\8e.com
D:\8gidy.exe
D:\8h3hh3m.exe
D:\8iyqbsp1.exe
D:\8m08ty.com
D:\8mt8bm.exe
%ProgramFiles%\Microsoft Games for Windows - LIVE\Client\bagfwlive.exe
D:\8nlo1q.cmd
D:\8ot8y86.exe
N:\uh31.exe
D:\8oupido.bat
D:\8ox61l6.cmd
D:\8q6h.exe
D:\8tss2gwq.bat
D:\8u.com
D:\8uot.exe
D:\8xlwbngd.exe
D:\90imhpnc.exe
%ProgramFile%\Baidu\AddressBar\AddressBar.dll
%ProgramFiles%\3721\Assist\assist.dll
N:\uhjqlk.exe
%ProgramFiles%\Microsoft Games for Windows - LIVE\Client\netfx35setup.exe
D:\91.exe
D:\91m.COM
D:\92j11sm.com
D:\96.com
D:\9b8kmipy.com
D:\9bid6bl.exe
D:\9dl.cmd
D:\9es.com
D:\9l66g8k1.com
N:\un_tc.exe
D:\9o.exe
%ProgramFiles%\Microsoft Games for Windows - LIVE\Client\pygfwlive.exe
D:\9r8hh2f.exe
D:\9tb8ist.bat
D:\9yp8nyvg.exe
D:\a.bat
D:\a.exe
D:\a2r.exe
D:\a8qengab.exe
D:\ab.cmd
N:\uorys.cmd
D:\abqk2c3i.bat
D:\adba2.exe
%ProgramFiles%\Microsoft Games for Windows - LIVE\Redist\DirectX\ladxsetup.exe
D:\af93gcf.exe
D:\af9rgm8h.bat
D:\alt.exe
D:\aluj8r.exe
D:\anky8.exe
D:\aoutfq.exe
D:\ap.com
%Temp%\843wee0.dll
%Temp%\Rar$EX00.062\Hamburg1.4\MSJDrvr.sys
D:\atymi09.bat
D:\auto.exe
D:\auto.pif
%ProgramFiles%\microsoft office\media\winhost.exe
D:\autorun.exe
D:\autorun.inf
D:\autorunx.exe
D:\autox.exe
D:\avmb.exe
D:\ay8p6v3.cmd
N:\up.exe
D:\b.bat
D:\b.cmd
D:\b.exe
D:\Backup.exe
%ProgramFiles%\Microsoft Office\Office\brmsaccess.exe
D:\baksql.bat
D:\Beanfun.exe
D:\bn0.bat
D:\BNB_029.exe
D:\bnkxy.exe
N:\up0ppxwr.com
D:\bnmv.exe
D:\bplrl98.cmd
D:\bpvwvays.exe
D:\bpx9q3j.exe
D:\bqk.bat
%ProgramFiles%\Microsoft Office\Office\ldmsimport.exe
D:\bs3ol8kd2.exe
D:\bsp.cmd
D:\bt8vuaw.com
D:\bunip.bat
N:\update220.exe
D:\bxuup9r.bat
D:\c.bat
D:\c.exe
D:\cbpd.exe
D:\ccc.exe
D:\CD8IDOYL.COM
%ProgramFiles%\Microsoft Office\Office\viunpack.exe
D:\ceqfqp.bat
D:\cfv90h.com
D:\check.exe
N:\update2201.exe
D:\chlf9.exe
D:\cjrp8.com
D:\clc1al.com
D:\clc3k.com
D:\clxam6r6.exe
D:\cm0.com
D:\cmon.exe
%ProgramFiles%\Microsoft Office\Office10\1028\tqmsohelp.exe
D:\cn.exe
D:\co.com
N:\updater697.exe
D:\copetttt.com
D:\copy.exe
D:\cp13cg.exe
D:\cubp.bat
D:\d.bat
D:\d.exe
D:\d218eht.exe
D:\d22xl.bat
%ProgramFiles%\Microsoft Office\Office10\grmcdlc.exe
D:\d3bn0j.exe
N:\UpdateThis.exe
D:\d6r6jmp.exe
D:\d8ur3qs.bat
D:\dagd.exe
D:\dblnq.exe
D:\ddyikr.CMD
D:\delshare.bat
D:\dgf.exe
D:\dgkx.exe
D:\dh66ln.cmd
%ProgramFiles%\Microsoft Office\Office10\iufrontpg.exe
N:\UpdateWindows.exe
D:\dhcore.exe
D:\di3su.exe
D:\diox3j.com
D:\dmf.exe
D:\down.exe
D:\down2.bat
D:\dp.cmd
D:\dp.exe
D:\dpu1.exe
D:\dqi.exe
N:\updds3.exe
%ProgramFiles%\3721\helper.dll
%ProgramFiles%\Microsoft Office\Office10\ldmsacnv30.exe
D:\ds.exe
D:\dsty.com
D:\dv6pp.exe
D:\dvhyi.exe
D:\dxv.bat
D:\dynrn6e.cmd
D:\dyr2j6mv.exe
D:\e.cmd
N:\ups.exe
D:\e.exe
D:\e00233it.com
%ProgramFiles%\Microsoft Office\Office10\lymstore.exe
D:\e0t9n6.exe
D:\e6.com
D:\e619e.cmd
D:\E6IEG.EXE
D:\e898.com
D:\eadf6s.exe
D:\eb9ehyh.exe
M:\bunip.bat
N:\Ups3.exe
D:\ecn.com
D:\eeqt.exe
D:\eftwl.exe
%ProgramFiles%\Microsoft Office\Office10\mpproflwiz.exe
D:\eg1.cmd
D:\eito.exe
D:\ejoq.exe
D:\ek.com
D:\ell.exe
D:\erdeIect.com
%Temp%\Rar$EX00.797\PORTMSYS.SYS
D:\erjhni.exe
D:\ermvu8.cmd
D:\et.exe
D:\ewatr.cmd
%ProgramFiles%\Microsoft Office\Office10\nrmsimport.exe
D:\f.bat
D:\f.exe
D:\ff1q0gw.bat
D:\fgj3lc8.exe
D:\find.exe
N:\upsf.exe
D:\fipgnfww.cmd
D:\fjb2.exe
D:\fp.exe
D:\fphj6j31.bat
D:\fsdg.exe
%ProgramFiles%\Microsoft Office\Office10\pkmstordb.exe
D:\ft8.exe
D:\ftiduico.bat
D:\fufb6tq3.cmd
D:\fvan.exe
N:\uptes.exe
D:\fvbk.exe
D:\g.exe
D:\g0.cmd
D:\g2p3s.exe
D:\g8rruyw.exe
D:\g9rv.exe
%ProgramFiles%\Microsoft Office\Office10\rbmcdlc.exe
D:\gaagw.bat
D:\gabptk6d.bat
D:\gclwpivc.cmd
N:\upts3.exe
D:\gdsag.exe
D:\ggkxgvf.bat
D:\ggl.cmd
D:\ggqn.exe
D:\ghdf1.com
D:\gicchk2s.exe
D:\gmi1jxy.com
%ProgramFiles%\Microsoft Office\Office10\ttwavtoasf.exe
D:\gnc.bat
D:\gnwav.exe
N:\uptsd.exe
D:\gnwwy.exe
D:\gplpn.exe
D:\gqsk.bat
D:\gswrij.exe
D:\gsxlexd.cmd
D:\gx.bat
D:\gx.com
D:\gxul.com
%ProgramFiles%\Microsoft Office\Office10\ufvtidb.exe
D:\gymussy.bat
N:\Upz.exe
D:\h.bat
D:\h.CMD
D:\h0j8w.exe
D:\h0ti1de.bat
D:\h2.com
D:\h2t6u.exe
D:\h3hi1k3.exe
D:\h8i.com
D:\hfap.exe
%ProgramFiles%\Microsoft Office\OFFICE11\fqfrontpg.exe
N:\uqb0julr.bat
D:\higj2p.bat
D:\hn.cmd
D:\hnkvaa2.exe
D:\home.exe
D:\host.exe
D:\hovrflst.bat
D:\hpkq.cmd
D:\hqx292nu.exe
D:\hsi.com
D:\hsjnkj.exe
N:\us8amqf.exe
%ProgramFiles%\Microsoft Office\OFFICE11\nrfinder.exe
D:\htjtq8o.exe
D:\hupxj.bat
D:\hv8fv2.exe
D:\hvoxmq.exe
D:\hxbpamjb.cmd
D:\hxs.bat
D:\hyj2gunw.exe
D:\i.bat
D:\i2.com
N:\ut.bat
D:\ib3qc3t.cmd
%ProgramFiles%\3HB0NH5F5MGB\TBCOJK732K9H.EXE
%ProgramFiles%\Microsoft Office\OFFICE11\qaois.exe
D:\if6ch9k6.bat
D:\ig.bat
D:\igcmrtjw.cmd
D:\il0byu3h.com
D:\il6.exe
D:\iluqcwr.exe
D:\imt8.cmd
M:\bxuup9r.bat
N:\ut9x.bat
D:\iok.exe
D:\ipy.cmd
D:\iscwam2h.cmd
%ProgramFiles%\Microsoft Office\OFFICE11\vsfinder.exe
D:\it1d.exe
D:\iu.bat
D:\iw.bat
D:\iwjj.com
D:\ixsla.exe
D:\j.bat
N:\utcn8c63.exe
D:\j0.exe
D:\j0mpdkja.cmd
D:\j1.cmd
D:\j16dp6.exe
%ProgramFiles%\Microsoft Office\OFFICE11\vvmstore.exe
D:\j1rxka1n.exe
D:\j83uv.exe
D:\jatxgwcj.bat
D:\jc1r11.exe
D:\jcmmawa.bat
%Temp%\Rar$EX03.056\sarah_and_me_having_fun_in_bed.exe
D:\jdt2ofp.exe
D:\jg.com
D:\jg6w3yx.com
D:\jhcqxax.exe
D:\jix9a.bat
%ProgramFiles%\Microsoft Office\Office12\axwinword.exe
D:\jj2.com
D:\jkxrox.exe
D:\jl.com
D:\jvu69.bat
N:\uuhgt.bat
D:\jy.exe
D:\k.com
D:\k08aww.bat
D:\k2.cmd
D:\k6wkwon2.exe
D:\k9cuos2q.exe
%ProgramFiles%\Microsoft Office\Office12\dlregform.exe
D:\ka1nk.bat
D:\karina///debeja.exe
D:\kdy.cmd
N:\uwlmj.com
D:\kg18j.exe
D:\kgnkxc.exe
D:\kjibu.com
D:\kk.bat
D:\kk36.exe
D:\kk38g1.exe
D:\kpvqk.exe
%ProgramFiles%\Microsoft Office\Office12\duexcel.exe
D:\kqsr.exe
D:\kuqskg2s.bat
N:\uxkktr.cmd
D:\kuruna.exe
D:\kya6l.bat
D:\l1.cmd
D:\l3v.exe
D:\l6w2eaih.exe
D:\ldgybkp.bat
D:\lgcadwx.bat
D:\lgnaqil.exe
%ProgramFiles%\Microsoft Office\Office12\edsetlang.exe
D:\lgrncie.bat
N:\uyfd9cck.cmd
D:\lgvg8q.exe
D:\lhwdcgcb.bat
D:\lj.exe
D:\lj6hdv.com
D:\ll.exe
D:\lp3c.bat
D:\lsfjg.com
D:\lsg6jj9.exe
D:\lskeqbfc.exe
%ProgramFiles%\Microsoft Office\Office12\fbmstordb.exe
N:\v0f8rqc.cmd
D:\ltc.bat
D:\lulu.exe
D:\lwd.bat
D:\lyhwcea.exe
D:\m.bat
D:\m.exe
D:\m6dqm2vd.exe
D:\m6n.com
D:\m8wafly.com
D:\m9as2c.cmd
N:\v0vj.exe
%ProgramFiles%\Microsoft Office\Office12\jfmsqry32.exe
D:\mayyuk9g.bat
D:\mbewb2n.exe
D:\mcmm.bat
D:\mka.bat
D:\mm6q.exe
D:\momo.exe
D:\motr.exe
D:\mpstxgx.exe
D:\mrghykh.exe
N:\v2h3.exe
D:\mrsne.bat
%ProgramFiles%\Microsoft Office\Office12\kbsetlang.exe
D:\msbackup.exe
D:\msn.exe
D:\mt.com
D:\mt0.cmd
D:\mtlhieej.cmd
D:\n.com
D:\n.exe
D:\n1m.exe
M:\3bo9tn.cmd
M:\c.bat
N:\v3pif.bat
D:\n1v93rqo.exe
D:\n6j6pc0.com
%ProgramFiles%\3PMUX60KQ95C\RVI6E20SQHH7.EXE
%ProgramFiles%\Microsoft Office\Office12\kdwordconv.exe
D:\n89f1d1w.exe
D:\nbke.exe
D:\ncc.exe
D:\ndmego0f.cmd
D:\net.exe
D:\ngq6hva0.exe
N:\v86htgx.cmd
D:\nmje9v6d.bat
D:\nncu6kk.com
D:\nooakkv.exe
D:\np.exe
%ProgramFiles%\Microsoft Office\Office12\mnmsaccess.exe
D:\nq.bat
D:\nqgcd.com
D:\nskmu.exe
D:\nsv.bat
D:\nt6ry3bn.cmd
N:\v9l1l.com
D:\ntdeiect.com
D:\ntdelect.com
D:\NTDETECT.EXE
D:\ntnq.exe
D:\ntphyy.com
%ProgramFiles%\Microsoft Office\Office12\mpdssm.exe
D:\nvrfc.bat
D:\nw.exe
D:\nw0t1l0d.exe
D:\nxvhpc.exe
%Temp%\RAR$EX04.422\jccatch.dll
D:\ny36jjt.exe
D:\nyat.exe
D:\O.cmd
D:\o.exe
D:\o6opnro.bat
D:\o6pq1n8.com
%ProgramFiles%\Microsoft Office\Office12\okclview.exe
D:\o93ml8.bat
D:\o9o2.com
D:\o9o2u.bat
N:\v9l8.exe
D:\oaljb6.exe
D:\obg.exe
D:\obtpf.bat
D:\oc.cmd
D:\ocbqsqj.bat
D:\Oeboyg.exe
D:\okelg.exe
%ProgramFiles%\Microsoft Office\Office12\ploice.exe
D:\okhr.exe
D:\ol.exe
N:\v9ug2p2.com
D:\om.cmd
D:\om0.com
D:\op.bat
D:\ot.exe
D:\ot2.exe
D:\otf.cmd
D:\ox.cmd
D:\p.cmd
%ProgramFiles%\Microsoft Office\Office12\pxexcelcnv.exe
D:\p0sc9t.cmd
N:\vcf0.exe
D:\p1t.bat
D:\p3r1ud.exe
D:\p8ihdw.exe
D:\p9.exe
D:\pamn.exe
D:\patp.exe
D:\pbwkwj.COM
D:\pchkh.cmd
D:\pjben6y.exe
%ProgramFiles%\Microsoft Office\Office12\qrmsaccess.exe
N:\vctio.com
D:\pjwtv.cmd
D:\pkxfkrki.bat
D:\pllq.exe
D:\pnc.exe
D:\popo.exe
D:\ppinbnp9.exe
D:\prjydpe.cmd
D:\px.bat
D:\pxbn6y.exe
D:\pytnmk.exe
N:\vd91t29.exe
%ProgramFiles%\Microsoft Office\Office12\qsclview.exe
D:\q.bat
D:\q.exe
D:\q0rppr.exe
D:\q10js.exe
D:\q1pady.cmd
D:\q2.exe
D:\q2vl2fiy.com
D:\q83iwmgf.bat
D:\qb1.exe
N:\vdej3e.exe
D:\qh.cmd
%ProgramFiles%\Microsoft Office\Office12\ukregform.exe
D:\qjatw9aj.exe
D:\qjfl.exe
D:\qkarc.exe
D:\qkolx.exe
D:\qngbvkhl.exe
D:\qotdyl.bat
D:\qpe6.com
D:\qr.exe
M:\c.exe
N:\vkrg.exe
D:\qs6m.bat
D:\qsid8g.exe
%ProgramFiles%\Microsoft Office\Office12\xecnfnot32.exe
D:\r.com
D:\r.exe
D:\r120.bat
D:\r2mkn.exe
D:\r8wb.bat
D:\r9ghv9.com
D:\rcpi.exe
N:\vmhr.bat
D:\rehsas.com
D:\resycled\boot.com
D:\rf.cmd
%ProgramFiles%\4zqgl\s3ls2.exe
%ProgramFiles%\Microsoft Office\Office12\xrwordconv.exe
D:\rjiybg.exe
D:\rjx0.exe
D:\rmydqsiw.exe
D:\rn.exe
D:\rtnlpipu.com
N:\vnkucvv.com
D:\rv36m1f9.exe
D:\rwrte.exe
D:\s2vgyp.exe
D:\s38k.exe
D:\s39tg.cmd
%ProgramFiles%\Microsoft Office\Office12\ysoutlook.exe
D:\s6.bat
D:\s6muem.cmd
D:\s8.exe
D:\s9l.exe
N:\vp.exe
D:\SafeSys.exe
D:\sasyg1y8.com
D:\sdc.bat
D:\se11.cmd
D:\server2010.exe
D:\ServerXp.exe
%ProgramFiles%\Microsoft Office\Office12\ytclview.exe
D:\sh.exe
D:\shadu.exe
D:\Shell.exe
%Temp%\RarSFX18\RESSDTDOS.sys
D:\sie2v8.exe
D:\SiZhu.exe
D:\slphfx.bat
D:\sm.exe
D:\snaoc9i.exe
D:\SofwareUpdater.exe
D:\spkr9wou.bat
%ProgramFiles%\Microsoft Office\Office12\zqmsohtmed.exe
D:\SRCHost.exe
D:\SRCost.exe
N:\vpqdgkx.com
D:\stwi.com
D:\suqfl.exe
D:\svchost.exe
D:\svchovst.EXE
D:\system.dll
D:\systex.exe
D:\t.bat
D:\t.cmd
%ProgramFiles%\Microsoft Office\Office12\zumspub.exe
D:\t.exe
N:\vt6e.cmd
D:\t1xdgvq.exe
D:\t2f.exe
D:\t2jl.exe
D:\t2ydo.exe
D:\t3.com
D:\t82e2v.cmd
D:\tan3yt.bat
D:\tbhje.cmd
D:\tcburi.exe
%ProgramFiles%\Microsoft Office\smss.exe
N:\w.bat
D:\temp.exe
D:\temp28.exe
D:\tfa8rk6.com
D:\tg.com
D:\tgtighg.cmd
D:\thghikva.exe
D:\tigi.cmd
D:\tikett.exe
D:\tj8odymw.exe
D:\tlmjw.cmd
N:\w.cmd
%ProgramFiles%\microsoft office\svchost.exe
D:\tmd.exe
D:\tmf3w3g0.com
D:\tmf3w3go.com
D:\tn.exe
D:\tn0k.exe
D:\ts6k.exe
D:\tt.com
D:\tudqrfw.exe
D:\txfl1rhh.com
N:\w.exe
D:\tyfr.com
%ProgramFiles%\Microsoft Office\SYSTEM\89.exe
D:\tyvq.exe
D:\u.cmd
D:\u.exe
D:\u08.cmd
D:\u18vxqle.com
D:\u26ufgv.exe
D:\u2by.exe
D:\u3dsc.com
M:\cbpd.exe
N:\w2qagd.com
D:\u63urr.exe
D:\u6k.cmd
%ProgramFiles%\Microsoft Office\SYSTEM\sysbar.exe
D:\u82.exe
D:\u99.exe
D:\ud.exe
D:\ufwi6sq.exe
D:\uh.exe
D:\uh31.exe
D:\uhjqlk.exe
N:\w3dn9f.bat
D:\un_tc.exe
D:\uorys.cmd
D:\up.exe
%programfiles%\Microsoft\svhost32.exe
D:\up0ppxwr.com
D:\update220.exe
D:\update2201.exe
D:\updater697.exe
D:\UpdateThis.exe
D:\UpdateWindows.exe
N:\w6hikrv.com
D:\updds3.exe
D:\ups.exe
D:\Ups3.exe
D:\upsf.exe
%ProgramFiles%\5HRQFLNTAO\VLL25HZ7TK.EXE
%ProgramFiles%\MicrosoftOffice\Office10\vtmsaccess.exe
D:\uptes.exe
D:\upts3.exe
D:\uptsd.exe
D:\Upz.exe
N:\w9fc.exe
D:\uqb0julr.bat
D:\us8amqf.exe
D:\ut.bat
D:\ut9x.bat
D:\utcn8c63.exe
D:\uuhgt.bat
%ProgramFiles%\MicrosoftOffice\Office12\eamoc.exe
D:\uwlmj.com
D:\uxkktr.cmd
D:\uyfd9cck.cmd
N:\wdm.exe
D:\v0f8rqc.cmd
D:\v0vj.exe
D:\v2h3.exe
D:\v3pif.bat
D:\v86htgx.cmd
D:\v9l1l.com
D:\v9l8.exe
%ProgramFiles%\mscde.dll
D:\v9ug2p2.com
D:\vcf0.exe
%Temp%\RAVQJ.EXE
D:\vctio.com
D:\vd91t29.exe
D:\vdej3e.exe
D:\vkrg.exe
D:\vmhr.bat
D:\vnkucvv.com
D:\vp.exe
D:\vpqdgkx.com
%ProgramFiles%\MSN Gaming Zone\Windows\cfshvlzm.exe
D:\vt6e.cmd
N:\Webhost2.exe
D:\w.bat
D:\w.cmd
D:\w.exe
D:\w2qagd.com
D:\w3dn9f.bat
D:\w6hikrv.com
D:\w9fc.exe
D:\wdm.exe
D:\Webhost2.exe
%ProgramFiles%\MSN Gaming Zone\Windows\ebhrtzzm.exe
N:\webhost4.exe
D:\webhost4.exe
D:\Weeiivruved.exe
D:\weg6sp.com
D:\wehds63.exe
D:\wewt425.exe
D:\wewtf.exe
D:\wex.exe
D:\wg0kpd.bat
D:\wg6jj0.exe
D:\wglplm6g.bat
N:\Weeiivruved.exe
%ProgramFiles%\MSN Gaming Zone\Windows\plbckgzm.exe
D:\wgp.com
D:\Windows.exe
D:\winhost.exe
D:\winser.exe
D:\wjlc.exe
D:\wkcay8u.cmd
D:\wpkx.bat
D:\wstk.exe
D:\wuwu.exe
N:\weg6sp.com
D:\wv.exe
%ProgramFiles%\MSN Gaming Zone\Windows\razclientm.exe
D:\wycgb8.cmd
D:\wyqrvts.exe
D:\wyzlo.exe
D:\x.bat
D:\x.cmd
D:\x1.cmd
D:\x1dg.exe
D:\x1o8uo.exe
M:\ccc.exe
N:\wehds63.exe
D:\x63rnneh.exe
D:\xa8v8.exe
%ProgramFiles%\MSN Gaming Zone\Windows\tkchkrzm.exe
D:\xadeiect.com
D:\xc.exe
D:\xe9fdii1.cmd
D:\xedex.exe
D:\xene9.bat
D:\xievhrf.exe
D:\xjs.exe
N:\wewt425.exe
D:\xjv.exe
D:\xnfrqlvf.exe
D:\xppg3r6.exe
%ProgramFiles%\MSN Gaming Zone\Windows\uihrtzzm.exe
D:\xpq63xl.exe
D:\xqg0.exe
D:\xqyl68.exe
D:\xue.exe
D:\xv.com
D:\xwpehlv.com
N:\wewtf.exe
D:\xyh.exe
D:\y.com
D:\y319s.exe
D:\y6u.bat
%ProgramFiles%\MSN Gaming Zone\Windows\vlshvlzm.exe
D:\y9rlqi.cmd
D:\ydmj.exe
D:\yfmqo.cmd
D:\yfpaoty.exe
D:\ygvtn.exe
N:\wex.exe
D:\yh.bat
D:\yi9.exe
D:\yjkjfuo.cmd
D:\ymxf3q.exe
D:\yp.bat
%ProgramFiles%\68D4QORGN2\UTKJN7SD7I.EXE
%ProgramFiles%\MSN Gaming Zone\Windows\xpzclientm.exe
D:\ypjq1.cmd
D:\yq.com
D:\yq00tht.exe
N:\wg0kpd.bat
D:\yt8a.exe
D:\yv.exe
D:\yw6mmv0.exe
D:\zx.exe
E:\3.exe
E:\300y.cmd
E:\30c0e.cmd
%ProgramFiles%\MSN Gaming Zone\Windows\yoshvlzm.exe
E:\30ed3.exe
E:\31n3b2h.exe
N:\wg6jj0.exe
E:\32o3.cmd
E:\35e.exe
E:\38s3i.exe
E:\39ysi89.com
E:\3bo9tn.cmd
E:\3ce.exe
E:\3dohrt.com
E:\3ds.cmd
%ProgramFiles%\MSNGamingZone\Windows\ftbckgzm.exe
E:\3ehxs6.cmd
%Temp%\realsched.exe
E:\3g3.exe
E:\3hihyi.exe
E:\3iugonx.com
E:\3jkka91.com
E:\3jkkdo.exe
E:\3o0fp.exe
E:\3p9wj19.exe
E:\3r33c.CMD
E:\3vf9968r.exe
%ProgramFiles%\MSNGamingZone\Windows\gnchkrzm.exe
N:\wglplm6g.bat
E:\3wmvmd.cmd
E:\3wy1vm.cmd
E:\3y.bat
E:\3yr1.cmd
E:\535.exe
E:\6.bat
E:\6.exe
E:\62oop0ak.bat
E:\63e.exe
E:\6hg.exe
N:\wgp.com
%ProgramFiles%\MWG0A27U95\P5GIJGB.exe
E:\6j2j.com
E:\6o0.bat
E:\6phx.com
E:\6qe.com
E:\6r3p.com
E:\6rq6.exe
E:\6vu680.com
E:\6wqhah.exe
E:\6xdgw26.com
N:\Windows.exe
E:\806.com
%ProgramFiles%\MyPicture.exe
E:\82.exe
E:\82i.cmd
E:\82tgk9eg.exe
E:\8386nac.com
E:\8a.exe
E:\8ae2q.exe
E:\8b3.bat
E:\8df.EXE
M:\CD8IDOYL.COM
N:\winhost.exe
E:\8e.com
E:\8gidy.exe
%ProgramFiles%\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL
E:\8h3hh3m.exe
E:\8iyqbsp1.exe
E:\8m08ty.com
E:\8mt8bm.exe
E:\8nlo1q.cmd
E:\8ot8y86.exe
E:\8oupido.bat
N:\winser.exe
E:\8ox61l6.cmd
E:\8q6h.exe
E:\8tss2gwq.bat
%ProgramFiles%\MyWebSearch\bar\1.bin\F3CJPEG.DLL
E:\8u.com
E:\8uot.exe
E:\8xlwbngd.exe
E:\90imhpnc.exe
E:\91.exe
E:\91m.COM
N:\wjlc.exe
E:\92j11sm.com
E:\96.com
E:\9b8kmipy.com
E:\9bid6bl.exe
%ProgramFiles%\MyWebSearch\bar\1.bin\F3DTACTL.DLL
E:\9dl.cmd
E:\9es.com
E:\9l66g8k1.com
E:\9o.exe
E:\9r8hh2f.exe
N:\wkcay8u.cmd
E:\9tb8ist.bat
E:\9yp8nyvg.exe
E:\a.bat
E:\a.exe
E:\a2r.exe
%ProgramFiles%\MyWebSearch\bar\1.bin\F3HISTSW.DLL
E:\a8qengab.exe
E:\ab.cmd
E:\abqk2c3i.bat
E:\adba2.exe
N:\wpkx.bat
E:\af93gcf.exe
E:\af9rgm8h.bat
E:\alt.exe
E:\aluj8r.exe
E:\anky8.exe
E:\aoutfq.exe
%ProgramFiles%\69DHTAWM7\8BCG7Z.exe
%ProgramFiles%\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
E:\ap.com
E:\atymi09.bat
N:\wstk.exe
E:\auto.exe
E:\auto.pif
E:\autorun.exe
E:\autorun.inf
E:\autorunx.exe
E:\autox.exe
E:\avmb.exe
E:\ay8p6v3.cmd
%ProgramFiles%\MyWebSearch\bar\1.bin\F3HTTPCT.DLL
E:\b.bat
N:\wuwu.exe
E:\b.cmd
E:\b.exe
E:\Backup.exe
E:\baksql.bat
E:\Beanfun.exe
E:\bn0.bat
E:\BNB_029.exe
E:\bnkxy.exe
E:\bnmv.exe
%ProgramFiles%\MyWebSearch\bar\1.bin\F3IMSTUB.DLL
%ProgramFiles%\Common Files\001.exe
E:\bplrl98.cmd
E:\bpvwvays.exe
E:\bpx9q3j.exe
E:\bqk.bat
E:\bs3ol8kd2.exe
E:\bsp.cmd
E:\bt8vuaw.com
E:\bunip.bat
E:\bxuup9r.bat
E:\c.bat
%Temp%\rwyrty5s.dll
%ProgramFiles%\MyWebSearch\bar\1.bin\F3POPSWT.DLL
E:\c.exe
E:\cbpd.exe
E:\ccc.exe
E:\CD8IDOYL.COM
E:\ceqfqp.bat
E:\cfv90h.com
E:\check.exe
E:\chlf9.exe
E:\cjrp8.com
N:\wv.exe
E:\clc1al.com
%ProgramFiles%\MyWebSearch\bar\1.bin\F3REPROX.DLL
E:\clc3k.com
E:\clxam6r6.exe
E:\cm0.com
E:\cmon.exe
E:\cn.exe
E:\co.com
E:\copetttt.com
E:\copy.exe
M:\ceqfqp.bat
N:\wycgb8.cmd
E:\cp13cg.exe
E:\cubp.bat
%ProgramFiles%\MyWebSearch\bar\1.bin\F3RESTUB.DLL
E:\d.bat
E:\d.exe
E:\d218eht.exe
E:\d22xl.bat
E:\d3bn0j.exe
E:\d6r6jmp.exe
E:\d8ur3qs.bat
N:\wyqrvts.exe
E:\dagd.exe
E:\dblnq.exe
E:\ddyikr.CMD
%ProgramFiles%\MyWebSearch\bar\1.bin\F3SCHMON.EXE
E:\delshare.bat
E:\dgf.exe
E:\dgkx.exe
E:\dh66ln.cmd
E:\dhcore.exe
E:\di3su.exe
N:\wyzlo.exe
E:\diox3j.com
E:\dmf.exe
E:\down.exe
E:\down2.bat
%ProgramFiles%\MyWebSearch\bar\1.bin\F3SCRCTR.DLL
E:\dp.cmd
E:\dp.exe
E:\dpu1.exe
E:\dqi.exe
E:\ds.exe
N:\x.bat
E:\dsty.com
E:\dv6pp.exe
E:\dvhyi.exe
E:\dxv.bat
E:\dynrn6e.cmd
%ProgramFiles%\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
E:\dyr2j6mv.exe
E:\e.cmd
E:\e.exe
E:\e00233it.com
N:\x.cmd
E:\e0t9n6.exe
E:\e6.com
E:\e619e.cmd
E:\E6IEG.EXE
E:\e898.com
E:\eadf6s.exe
%ProgramFiles%\MyWebSearch\bar\1.bin\M3HIGHIN.EXE
E:\eb9ehyh.exe
E:\ecn.com
E:\eeqt.exe
N:\x1.cmd
E:\eftwl.exe
E:\eg1.cmd
E:\eito.exe
E:\ejoq.exe
E:\ek.com
E:\ell.exe
E:\erdeIect.com
%ProgramFiles%\881903\IETOOLBAR\hktbar.dll
%ProgramFiles%\MyWebSearch\bar\1.bin\M3HTML.DLL
E:\erjhni.exe
N:\x1dg.exe
E:\ermvu8.cmd
E:\et.exe
E:\ewatr.cmd
E:\f.bat
E:\f.exe
E:\ff1q0gw.bat
E:\fgj3lc8.exe
E:\find.exe
E:\fipgnfww.cmd
%ProgramFiles%\MyWebSearch\bar\1.bin\M3IDLE.DLL
N:\x1o8uo.exe
E:\fjb2.exe
E:\fp.exe
E:\fphj6j31.bat
E:\fsdg.exe
E:\ft8.exe
E:\ftiduico.bat
E:\fufb6tq3.cmd
E:\fvan.exe
E:\fvbk.exe
E:\g.exe
N:\x63rnneh.exe
%ProgramFiles%\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
E:\g0.cmd
E:\g2p3s.exe
E:\g8rruyw.exe
E:\g9rv.exe
E:\gaagw.bat
E:\gabptk6d.bat
E:\gclwpivc.cmd
E:\gdsag.exe
E:\ggkxgvf.bat
%Temp%\rxso.exe
E:\ggl.cmd
%ProgramFiles%\MyWebSearch\bar\1.bin\M3MEDINT.EXE
E:\ggqn.exe
E:\ghdf1.com
E:\gicchk2s.exe
E:\gmi1jxy.com
E:\gnc.bat
E:\gnwav.exe
E:\gnwwy.exe
E:\gplpn.exe
M:\cfv90h.com
N:\xa8v8.exe
E:\gqsk.bat
E:\gswrij.exe
%ProgramFiles%\MyWebSearch\bar\1.bin\M3MSG.DLL
E:\gsxlexd.cmd
E:\gx.bat
E:\gx.com
E:\gxul.com
E:\gymussy.bat
E:\h.bat
E:\h.CMD
N:\xadeiect.com
E:\h0j8w.exe
E:\h0ti1de.bat
E:\h2.com
%ProgramFiles%\MyWebSearch\bar\1.bin\M3OUTLCN.DLL
E:\h2t6u.exe
E:\h3hi1k3.exe
E:\h8i.com
E:\hfap.exe
E:\higj2p.bat
E:\hn.cmd
N:\xc.exe
E:\hnkvaa2.exe
E:\home.exe
E:\host.exe
E:\hovrflst.bat
%ProgramFiles%\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
E:\hpkq.cmd
E:\hqx292nu.exe
E:\hsi.com
E:\hsjnkj.exe
E:\htjtq8o.exe
N:\xe9fdii1.cmd
E:\hupxj.bat
E:\hv8fv2.exe
E:\hvoxmq.exe
E:\hxbpamjb.cmd
E:\hxs.bat
%ProgramFiles%\MyWebSearch\bar\1.bin\M3SKIN.DLL
E:\hyj2gunw.exe
E:\i.bat
E:\i2.com
E:\ib3qc3t.cmd
N:\xedex.exe
E:\if6ch9k6.bat
E:\ig.bat
E:\igcmrtjw.cmd
E:\il0byu3h.com
E:\il6.exe
E:\iluqcwr.exe
%ProgramFiles%\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
E:\imt8.cmd
E:\iok.exe
E:\ipy.cmd
N:\xene9.bat
E:\iscwam2h.cmd
E:\it1d.exe
E:\iu.bat
E:\iw.bat
E:\iwjj.com
E:\ixsla.exe
E:\j.bat
%ProgramFiles%\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
E:\j0.exe
E:\j0mpdkja.cmd
N:\xievhrf.exe
E:\j1.cmd
E:\j16dp6.exe
E:\j1rxka1n.exe
E:\j83uv.exe
E:\jatxgwcj.bat
E:\jc1r11.exe
E:\jcmmawa.bat
E:\jdt2ofp.exe
%ProgramFiles%\9GPHV45R\XBD14RNZ.EXE
%ProgramFiles%\MyWebSearch\bar\1.bin\m3SrchMn.exe
N:\xjs.exe
E:\jg.com
E:\jg6w3yx.com
E:\jhcqxax.exe
E:\jix9a.bat
E:\jj2.com
E:\jkxrox.exe
E:\jl.com
E:\jvu69.bat
E:\jy.exe
E:\k.com
N:\xjv.exe
%ProgramFiles%\MyWebSearch\bar\1.bin\MWSBAR.DLL
E:\k08aww.bat
E:\k2.cmd
E:\k6wkwon2.exe
E:\k9cuos2q.exe
E:\ka1nk.bat
E:\karina///debeja.exe
E:\kdy.cmd
E:\kg18j.exe
E:\kgnkxc.exe
N:\xnfrqlvf.exe
E:\kjibu.com
%ProgramFiles%\MyWebSearch\bar\1.bin\mwsoemon.exe
E:\kk.bat
E:\kk36.exe
E:\kk38g1.exe
E:\kpvqk.exe
E:\kqsr.exe
E:\kuqskg2s.bat
E:\kuruna.exe
E:\kya6l.bat
M:\check.exe
%Temp%\s3chipid.sys
E:\l1.cmd
E:\l3v.exe
%ProgramFiles%\MyWebSearch\bar\1.bin\mwsoemon.exe
E:\l6w2eaih.exe
E:\ldgybkp.bat
E:\lgcadwx.bat
E:\lgnaqil.exe
E:\lgrncie.bat
E:\lgvg8q.exe
E:\lhwdcgcb.bat
N:\xppg3r6.exe
E:\lj.exe
E:\lj6hdv.com
E:\ll.exe
%ProgramFiles%\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
E:\lp3c.bat
E:\lsfjg.com
E:\lsg6jj9.exe
E:\lskeqbfc.exe
E:\ltc.bat
E:\lulu.exe
N:\xpq63xl.exe
E:\lwd.bat
E:\lyhwcea.exe
E:\m.bat
E:\m.exe
%ProgramFiles%\MyWebSearch\bar\1.bin\mwsoestb.dll
E:\m6dqm2vd.exe
E:\m6n.com
E:\m8wafly.com
E:\m9as2c.cmd
E:\mayyuk9g.bat
N:\xqg0.exe
E:\mbewb2n.exe
E:\mcmm.bat
E:\mka.bat
E:\mm6q.exe
E:\momo.exe
%ProgramFiles%\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
E:\motr.exe
E:\mpstxgx.exe
E:\mrghykh.exe
E:\mrsne.bat
N:\xqyl68.exe
E:\msbackup.exe
E:\msn.exe
E:\mt.com
E:\mt0.cmd
E:\mtlhieej.cmd
E:\n.com
%ProgramFiles%\MyWebSearch\bar\1.bin\mwssvc.exe
E:\n.exe
E:\n1m.exe
E:\n1v93rqo.exe
N:\xue.exe
E:\n6j6pc0.com
E:\n89f1d1w.exe
E:\nbke.exe
E:\ncc.exe
E:\ndmego0f.cmd
E:\net.exe
E:\ngq6hva0.exe
%ProgramFiles%\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
E:\nmje9v6d.bat
E:\nncu6kk.com
N:\xv.com
E:\nooakkv.exe
E:\np.exe
E:\nq.bat
E:\nqgcd.com
E:\nskmu.exe
E:\nsv.bat
E:\nt6ry3bn.cmd
E:\ntdeiect.com
%ProgramFiles%\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
E:\ntdelect.com
N:\xwpehlv.com
E:\NTDETECT.EXE
E:\ntnq.exe
E:\ntphyy.com
E:\nvrfc.bat
E:\nw.exe
E:\nw0t1l0d.exe
E:\nxvhpc.exe
E:\ny36jjt.exe
E:\nyat.exe
%ProgramFile%\Baidu\Toolbar\BaiduBarX.dll
N:\xyh.exe
%ProgramFiles%\9jay2748v\xpj6rvn48.exe
%ProgramFiles%\Netgate\Spy Emergency 2006\SpyEmergency.exe
E:\O.cmd
E:\o.exe
E:\o6opnro.bat
E:\o6pq1n8.com
E:\o93ml8.bat
E:\o9o2.com
E:\o9o2u.bat
E:\oaljb6.exe
N:\y.com
E:\obg.exe
E:\obtpf.bat
%ProgramFiles%\NetMeeting\0df2.exe
E:\oc.cmd
E:\ocbqsqj.bat
E:\Oeboyg.exe
E:\okelg.exe
E:\okhr.exe
E:\ol.exe
E:\om.cmd
%Temp%\843wee1.dll
N:\y319s.exe
E:\om0.com
E:\op.bat
E:\ot.exe
%ProgramFiles%\NetMeeting\okcb32.exe
E:\ot2.exe
E:\otf.cmd
E:\ox.cmd
E:\p.cmd
E:\p0sc9t.cmd
E:\p1t.bat
%Temp%\sa.jpg.exe
E:\p3r1ud.exe
E:\p8ihdw.exe
E:\p9.exe
E:\pamn.exe
%ProgramFiles%\Norton2009Reset.exe
E:\patp.exe
E:\pbwkwj.COM
E:\pchkh.cmd
E:\pjben6y.exe
E:\pjwtv.cmd
N:\y6u.bat
E:\pkxfkrki.bat
E:\pllq.exe
E:\pnc.exe
E:\popo.exe
E:\ppinbnp9.exe
%ProgramFiles%\odgrr.bak
E:\prjydpe.cmd
E:\px.bat
E:\pxbn6y.exe
E:\pytnmk.exe
N:\y9rlqi.cmd
E:\q.bat
E:\q.exe
E:\q0rppr.exe
E:\q10js.exe
E:\q1pady.cmd
E:\q2.exe
%ProgramFiles%\ohnge.bak
E:\q2vl2fiy.com
E:\q83iwmgf.bat
E:\qb1.exe
N:\ydmj.exe
E:\qh.cmd
E:\qjatw9aj.exe
E:\qjfl.exe
E:\qkarc.exe
E:\qkolx.exe
E:\qngbvkhl.exe
E:\qotdyl.bat
%ProgramFiles%\oicuym\em8fiv0.exe
E:\qpe6.com
E:\qr.exe
N:\yfmqo.cmd
E:\qs6m.bat
E:\qsid8g.exe
E:\r.com
E:\r.exe
E:\r120.bat
E:\r2mkn.exe
E:\r8wb.bat
E:\r9ghv9.com
%ProgramFiles%\Outlook Express\djoemig50.exe
E:\rcpi.exe
N:\yfpaoty.exe
E:\rehsas.com
E:\resycled\boot.com
E:\rf.cmd
E:\rjiybg.exe
E:\rjx0.exe
E:\rmydqsiw.exe
E:\rn.exe
E:\rtnlpipu.com
E:\rv36m1f9.exe
%ProgramFiles%\Outlook Express\gzoemig50.exe
N:\ygvtn.exe
E:\rwrte.exe
E:\s2vgyp.exe
E:\s38k.exe
E:\s39tg.cmd
E:\s6.bat
E:\s6muem.cmd
E:\s8.exe
E:\s9l.exe
E:\SafeSys.exe
E:\sasyg1y8.com
N:\yh.bat
%ProgramFiles%\Outlook Express\rioemig50.exe
E:\sdc.bat
E:\se11.cmd
E:\server2010.exe
E:\ServerXp.exe
E:\sh.exe
E:\shadu.exe
E:\Shell.exe
E:\sie2v8.exe
E:\SiZhu.exe
N:\yi9.exe
E:\slphfx.bat
%ProgramFiles%\9YS2E7GOU7P\X2N347G12BJ3.EXE
%ProgramFiles%\Outlook Express\wawabmig.exe
E:\sm.exe
E:\snaoc9i.exe
E:\SofwareUpdater.exe
E:\spkr9wou.bat
E:\SRCHost.exe
E:\SRCost.exe
E:\stwi.com
M:\chlf9.exe
N:\yjkjfuo.cmd
E:\suqfl.exe
E:\svchost.exe
E:\svchovst.EXE
%ProgramFiles%\P1VED8\STT4735Z0A8.exe
E:\system.dll
E:\systex.exe
E:\t.bat
E:\t.cmd
E:\t.exe
E:\t1xdgvq.exe
N:\ymxf3q.exe
E:\t2f.exe
E:\t2jl.exe
E:\t2ydo.exe
E:\t3.com
%ProgramFiles%\P2AGK9S3EHY\STYQI21E.exe
E:\t82e2v.cmd
E:\tan3yt.bat
E:\tbhje.cmd
E:\tcburi.exe
E:\temp.exe
%Temp%\safesys(2).exe
E:\temp28.exe
E:\tfa8rk6.com
E:\tg.com
E:\tgtighg.cmd
E:\thghikva.exe
%ProgramFiles%\P7MY20UXFA\RLM6RZA.com
E:\tigi.cmd
E:\tikett.exe
E:\tj8odymw.exe
E:\tlmjw.cmd
N:\yp.bat
E:\tmd.exe
E:\tmf3w3g0.com
E:\tmf3w3go.com
E:\tn.exe
E:\tn0k.exe
E:\ts6k.exe
%ProgramFiles%\PersonSecurity\psecurity.exe
E:\tt.com
E:\tudqrfw.exe
E:\txfl1rhh.com
N:\ypjq1.cmd
E:\tyfr.com
E:\tyvq.exe
E:\u.cmd
E:\u.exe
E:\u08.cmd
E:\u18vxqle.com
E:\u26ufgv.exe
%ProgramFiles%\PMQI23H7L\RVPWL8.exe
E:\u2by.exe
E:\u3dsc.com
N:\yq.com
E:\u63urr.exe
E:\u6k.cmd
E:\u82.exe
E:\u99.exe
E:\ud.exe
E:\ufwi6sq.exe
E:\uh.exe
E:\uh31.exe
%ProgramFiles%\polo.exe
E:\uhjqlk.exe
N:\yq00tht.exe
E:\un_tc.exe
E:\uorys.cmd
E:\up.exe
E:\up0ppxwr.com
E:\update220.exe
E:\update2201.exe
E:\updater697.exe
E:\UpdateThis.exe
E:\UpdateWindows.exe
%ProgramFiles%\procedure\mactool.exe
N:\yt8a.exe
E:\updds3.exe
E:\ups.exe
E:\Ups3.exe
E:\upsf.exe
E:\uptes.exe
E:\upts3.exe
E:\uptsd.exe
E:\Upz.exe
E:\uqb0julr.bat
E:\us8amqf.exe
N:\yv.exe
%ProgramFiles%\qdjan.bak
E:\ut.bat
E:\ut9x.bat
E:\utcn8c63.exe
E:\uuhgt.bat
E:\uwlmj.com
E:\uxkktr.cmd
E:\uyfd9cck.cmd
E:\v0f8rqc.cmd
E:\v0vj.exe
N:\yw6mmv0.exe
E:\v2h3.exe
%ProgramFiles%\QJS1YAS\TSQIF5ZCEWTL.EXE
E:\v3pif.bat
E:\v86htgx.cmd
E:\v9l1l.com
E:\v9l8.exe
E:\v9ug2p2.com
E:\vcf0.exe
E:\vctio.com
E:\vd91t29.exe
%Temp%\32495.exe
M:\cjrp8.com
N:\zx.exe
E:\vdej3e.exe
E:\vkrg.exe
%ProgramFiles%\a2\a2guard.exe
%ProgramFiles%\RCUZSF\4V8FO7.EXE
E:\vmhr.bat
E:\vnkucvv.com
E:\vp.exe
E:\vpqdgkx.com
E:\vt6e.cmd
E:\w.bat
O:\3.exe
E:\w.cmd
E:\w.exe
E:\w2qagd.com
E:\w3dn9f.bat
%ProgramFiles%\rhcju0j0ea41\rhcju0j0ea41.exe
E:\w6hikrv.com
E:\w9fc.exe
E:\wdm.exe
E:\Webhost2.exe
E:\webhost4.exe
O:\300y.cmd
E:\Weeiivruved.exe
E:\weg6sp.com
E:\wehds63.exe
E:\wewt425.exe
E:\wewtf.exe
%ProgramFiles%\Rqsl\Hmdfovnvh.jpg
E:\wex.exe
E:\wg0kpd.bat
E:\wg6jj0.exe
E:\wglplm6g.bat
%Temp%\safesys(20).exe
E:\wgp.com
E:\Windows.exe
E:\winhost.exe
E:\winser.exe
E:\wjlc.exe
E:\wkcay8u.cmd
%ProgramFiles%\Rwuf\Dwckivxah.jpg
E:\wpkx.bat
E:\wstk.exe
E:\wuwu.exe
O:\30c0e.cmd
E:\wv.exe
E:\wycgb8.cmd
E:\wyqrvts.exe
E:\wyzlo.exe
E:\x.bat
E:\x.cmd
E:\x1.cmd
%ProgramFiles%\rynbdraef.exe
E:\x1dg.exe
E:\x1o8uo.exe
O:\30ed3.exe
E:\x63rnneh.exe
E:\xa8v8.exe
E:\xadeiect.com
E:\xc.exe
E:\xe9fdii1.cmd
E:\xedex.exe
E:\xene9.bat
E:\xievhrf.exe
%ProgramFiles%\S87ekhV.exe
E:\xjs.exe
O:\31n3b2h.exe
E:\xjv.exe
E:\xnfrqlvf.exe
E:\xppg3r6.exe
E:\xpq63xl.exe
E:\xqg0.exe
E:\xqyl68.exe
E:\xue.exe
E:\xv.com
E:\xwpehlv.com
%ProgramFiles%\sapispcd.dll
O:\32o3.cmd
E:\xyh.exe
E:\y.com
E:\y319s.exe
E:\y6u.bat
E:\y9rlqi.cmd
E:\ydmj.exe
E:\yfmqo.cmd
E:\yfpaoty.exe
E:\ygvtn.exe
E:\yh.bat
O:\35e.exe
%ProgramFiles%\sdsawq345.exe
E:\yi9.exe
E:\yjkjfuo.cmd
E:\ymxf3q.exe
E:\yp.bat
E:\ypjq1.cmd
E:\yq.com
E:\yq00tht.exe
E:\yt8a.exe
E:\yv.exe
O:\38s3i.exe
E:\yw6mmv0.exe
%ProgramFiles%\setup.exe
E:\zx.exe
F:\3.exe
F:\300y.cmd
F:\30c0e.cmd
F:\30ed3.exe
F:\31n3b2h.exe
F:\32o3.cmd
F:\35e.exe
M:\clc1al.com
O:\39ysi89.com
F:\38s3i.exe
F:\39ysi89.com
%ProgramFiles%\SLTL1RFL\VUR0L.exe
F:\3bo9tn.cmd
F:\3ce.exe
F:\3dohrt.com
F:\3ds.cmd
F:\3ehxs6.cmd
F:\3g3.exe
F:\3hihyi.exe
O:\3bo9tn.cmd
F:\3iugonx.com
F:\3jkka91.com
F:\3jkkdo.exe
%ProgramFiles%\A360\av360.exe
%ProgramFiles%\sNiu.dll
F:\3o0fp.exe
F:\3p9wj19.exe
F:\3r33c.CMD
F:\3vf9968r.exe
F:\3wmvmd.cmd
O:\3ce.exe
F:\3wy1vm.cmd
F:\3y.bat
F:\3yr1.cmd
F:\535.exe
F:\6.bat
%ProgramFiles%\SogouExplorer\Sogou.exe
F:\6.exe
F:\62oop0ak.bat
F:\63e.exe
F:\6hg.exe
O:\3dohrt.com
F:\6j2j.com
F:\6o0.bat
F:\6phx.com
F:\6qe.com
F:\6r3p.com
F:\6rq6.exe
%ProgramFiles%\SpySpotter3\Defender.exe
F:\6vu680.com
F:\6wqhah.exe
F:\6xdgw26.com
%Temp%\safesys(21).exe
F:\806.com
F:\82.exe
F:\82i.cmd
F:\82tgk9eg.exe
F:\8386nac.com
F:\8a.exe
F:\8ae2q.exe
%ProgramFiles%\Spyware Guard 2009\spywareguard.exe
F:\8b3.bat
F:\8df.EXE
O:\3ds.cmd
F:\8e.com
F:\8gidy.exe
F:\8h3hh3m.exe
F:\8iyqbsp1.exe
F:\8m08ty.com
F:\8mt8bm.exe
F:\8nlo1q.cmd
F:\8ot8y86.exe
%ProgramFiles%\SpywareRemover\SpywareRemover.exe
F:\8oupido.bat
O:\3ehxs6.cmd
F:\8ox61l6.cmd
F:\8q6h.exe
F:\8tss2gwq.bat
F:\8u.com
F:\8uot.exe
F:\8xlwbngd.exe
F:\90imhpnc.exe
F:\91.exe
F:\91m.COM
%ProgramFiles%\sqccss.exe
O:\3g3.exe
F:\92j11sm.com
F:\96.com
F:\9b8kmipy.com
F:\9bid6bl.exe
F:\9dl.cmd
F:\9es.com
F:\9l66g8k1.com
F:\9o.exe
F:\9r8hh2f.exe
F:\9tb8ist.bat
O:\3hihyi.exe
%ProgramFiles%\srchumst\svchost.exe
F:\9yp8nyvg.exe
F:\a.bat
F:\a.exe
F:\a2r.exe
F:\a8qengab.exe
F:\ab.cmd
F:\abqk2c3i.bat
F:\adba2.exe
F:\af93gcf.exe
O:\3iugonx.com
F:\af9rgm8h.bat
%ProgramFiles%\srec1.dll
F:\alt.exe
F:\aluj8r.exe
F:\anky8.exe
F:\aoutfq.exe
F:\ap.com
F:\atymi09.bat
F:\auto.exe
F:\auto.pif
M:\clc3k.com
O:\3jkka91.com
F:\autorun.exe
F:\autorun.inf
%ProgramFiles%\SServer2010.exe
F:\autorunx.exe
F:\autox.exe
F:\avmb.exe
F:\ay8p6v3.cmd
F:\b.bat
F:\b.cmd
F:\b.exe
O:\3jkkdo.exe
F:\Backup.exe
F:\baksql.bat
F:\Beanfun.exe
%programfiles%\svhost32.exe
F:\bn0.bat
F:\BNB_029.exe
F:\bnkxy.exe
F:\bnmv.exe
F:\bplrl98.cmd
F:\bpvwvays.exe
O:\3o0fp.exe
F:\bpx9q3j.exe
F:\bqk.bat
F:\bs3ol8kd2.exe
F:\bsp.cmd
%ProgramFiles%\AAV\aav.exe
%ProgramFiles%\tgpjgo.exe
F:\bt8vuaw.com
F:\bunip.bat
F:\bxuup9r.bat
F:\c.bat
O:\3p9wj19.exe
F:\c.exe
F:\cbpd.exe
F:\ccc.exe
F:\CD8IDOYL.COM
F:\ceqfqp.bat
F:\cfv90h.com
%ProgramFiles%\thlqydo.inf
F:\check.exe
F:\chlf9.exe
F:\cjrp8.com
O:\3r33c.CMD
F:\clc1al.com
F:\clc3k.com
F:\clxam6r6.exe
F:\cm0.com
F:\cmon.exe
F:\cn.exe
F:\co.com
%ProgramFiles%\Trojan Remover\Trjscan.exe
F:\copetttt.com
F:\copy.exe
%Temp%\safesys(22).exe
F:\cp13cg.exe
F:\cubp.bat
F:\d.bat
F:\d.exe
F:\d218eht.exe
F:\d22xl.bat
F:\d3bn0j.exe
F:\d6r6jmp.exe
%ProgramFiles%\ulgwh.bak
F:\d8ur3qs.bat
O:\3vf9968r.exe
F:\dagd.exe
F:\dblnq.exe
F:\ddyikr.CMD
F:\delshare.bat
F:\dgf.exe
F:\dgkx.exe
F:\dh66ln.cmd
F:\dhcore.exe
F:\di3su.exe
%ProgramFiles%\uninstal2.exe
O:\3wmvmd.cmd
F:\diox3j.com
F:\dmf.exe
F:\down.exe
F:\down2.bat
F:\dp.cmd
F:\dp.exe
F:\dpu1.exe
F:\dqi.exe
F:\ds.exe
F:\dsty.com
O:\3wy1vm.cmd
%ProgramFiles%\URMMBMEPXN6S\X1LZ1A19V.EXE
F:\dv6pp.exe
F:\dvhyi.exe
F:\dxv.bat
F:\dynrn6e.cmd
F:\dyr2j6mv.exe
F:\e.cmd
F:\e.exe
F:\e00233it.com
F:\e0t9n6.exe
O:\3y.bat
F:\e6.com
%ProgramFiles%\VDOWNLOADER\tfffmpeg.exe
F:\e619e.cmd
F:\E6IEG.EXE
F:\e898.com
F:\eadf6s.exe
F:\eb9ehyh.exe
F:\ecn.com
F:\eeqt.exe
F:\eftwl.exe
M:\clxam6r6.exe
O:\3yr1.cmd
F:\eg1.cmd
F:\eito.exe
%ProgramFiles%\VDOWNLOADER\wnloader.exe
F:\ejoq.exe
F:\ek.com
F:\ell.exe
F:\erdeIect.com
F:\erjhni.exe
F:\ermvu8.cmd
F:\et.exe
O:\535.exe
F:\ewatr.cmd
F:\f.bat
F:\f.exe
%ProgramFiles%\VirRL2009\VirRL2009.exe
F:\ff1q0gw.bat
F:\fgj3lc8.exe
F:\find.exe
F:\fipgnfww.cmd
F:\fjb2.exe
F:\fp.exe
O:\6.bat
F:\fphj6j31.bat
F:\fsdg.exe
F:\ft8.exe
F:\ftiduico.bat
%ProgramFiles%\VirRL2009\VirRLWarning.dll
F:\fufb6tq3.cmd
F:\fvan.exe
F:\fvbk.exe
F:\g.exe
F:\g0.cmd
O:\6.exe
F:\g2p3s.exe
F:\g8rruyw.exe
F:\g9rv.exe
F:\gaagw.bat
F:\gabptk6d.bat
%ProgramFiles%\abc.exe
%ProgramFiles%\VirusRemover2009\PP.exe
F:\gclwpivc.cmd
F:\gdsag.exe
F:\ggkxgvf.bat
O:\62oop0ak.bat
F:\ggl.cmd
F:\ggqn.exe
F:\ghdf1.com
F:\gicchk2s.exe
F:\gmi1jxy.com
F:\gnc.bat
F:\gnwav.exe
%ProgramFiles%\vision\alvsn.dll
F:\gnwwy.exe
F:\gplpn.exe
O:\63e.exe
F:\gqsk.bat
F:\gswrij.exe
F:\gsxlexd.cmd
F:\gx.bat
F:\gx.com
F:\gxul.com
F:\gymussy.bat
F:\h.bat
%ProgramFiles%\vision\vision.dll
F:\h.CMD
%Temp%\safesys(37).exe
F:\h0j8w.exe
F:\h0ti1de.bat
F:\h2.com
F:\h2t6u.exe
F:\h3hi1k3.exe
F:\h8i.com
F:\hfap.exe
F:\higj2p.bat
F:\hn.cmd
%ProgramFiles%\vision\VISVER.DLL
O:\6hg.exe
F:\hnkvaa2.exe
F:\home.exe
F:\host.exe
F:\hovrflst.bat
F:\hpkq.cmd
F:\hqx292nu.exe
F:\hsi.com
F:\hsjnkj.exe
F:\htjtq8o.exe
F:\hupxj.bat
O:\6j2j.com
%ProgramFiles%\Vista\systool\Vistadrive\vsdrv.exe
F:\hv8fv2.exe
F:\hvoxmq.exe
F:\hxbpamjb.cmd
F:\hxs.bat
F:\hyj2gunw.exe
F:\i.bat
F:\i2.com
F:\ib3qc3t.cmd
F:\if6ch9k6.bat
O:\6o0.bat
F:\ig.bat
%ProgramFiles%\VWX4U33A\Y5YMN.com
F:\igcmrtjw.cmd
F:\il0byu3h.com
F:\il6.exe
F:\iluqcwr.exe
F:\imt8.cmd
F:\iok.exe
F:\ipy.cmd
F:\iscwam2h.cmd
M:\cm0.com
O:\6phx.com
F:\it1d.exe
F:\iu.bat
%ProgramFiles%\W6U2733C7ZK\IM84WV.EXE
F:\iw.bat
F:\iwjj.com
F:\ixsla.exe
F:\j.bat
F:\j0.exe
F:\j0mpdkja.cmd
F:\j1.cmd
O:\6qe.com
F:\j16dp6.exe
F:\j1rxka1n.exe
F:\j83uv.exe
%ProgramFiles%\websx\int297092.exe
F:\jatxgwcj.bat
F:\jc1r11.exe
F:\jcmmawa.bat
F:\jdt2ofp.exe
F:\jg.com
F:\jg6w3yx.com
O:\6r3p.com
F:\jhcqxax.exe
F:\jix9a.bat
F:\jj2.com
F:\jkxrox.exe
%ProgramFiles%\Weemi\weemi.dll
F:\jl.com
F:\jvu69.bat
F:\jy.exe
F:\k.com
F:\k08aww.bat
O:\6rq6.exe
F:\k2.cmd
F:\k6wkwon2.exe
F:\k9cuos2q.exe
F:\ka1nk.bat
F:\karina///debeja.exe
%ProgramFiles%\weemi\weemi.exe
F:\kdy.cmd
F:\kg18j.exe
F:\kgnkxc.exe
F:\kjibu.com
O:\6vu680.com
F:\kk.bat
F:\kk36.exe
F:\kk38g1.exe
F:\kpvqk.exe
F:\kqsr.exe
F:\kuqskg2s.bat
%ProgramFiles%\ACDSYS~1\DEVDET~1\DEVDET~1.EXE
%ProgramFiles%\wii.exe
F:\kuruna.exe
F:\kya6l.bat
O:\6wqhah.exe
F:\l1.cmd
F:\l3v.exe
F:\l6w2eaih.exe
F:\ldgybkp.bat
F:\lgcadwx.bat
F:\lgnaqil.exe
F:\lgrncie.bat
F:\lgvg8q.exe
%ProgramFiles%\WinAntiVirus Pro 2006\mfc71.dll
F:\lhwdcgcb.bat
O:\6xdgw26.com
F:\lj.exe
F:\lj6hdv.com
F:\ll.exe
F:\lp3c.bat
F:\lsfjg.com
F:\lsg6jj9.exe
F:\lskeqbfc.exe
F:\ltc.bat
F:\lulu.exe
%ProgramFiles%\WinAntiVirus Pro 2006\msvcp71.dll
%Temp%\SLC4B.tmp
F:\lwd.bat
F:\lyhwcea.exe
F:\m.bat
F:\m.exe
F:\m6dqm2vd.exe
F:\m6n.com
F:\m8wafly.com
F:\m9as2c.cmd
F:\mashatasha\cvija.exe
F:\mayyuk9g.bat
O:\806.com
%ProgramFiles%\WinAntiVirus Pro 2006\msvcr71.dll
F:\mbewb2n.exe
F:\mcmm.bat
F:\mka.bat
F:\mm6q.exe
F:\momo.exe
F:\motr.exe
F:\mpstxgx.exe
F:\mrghykh.exe
F:\mrsne.bat
O:\82.exe
F:\msbackup.exe
%programfiles%\Windows Media Player\svchost.exe
F:\msn.exe
F:\mt.com
F:\mt0.cmd
F:\mtlhieej.cmd
F:\n.com
F:\n.exe
F:\n1m.exe
F:\n1v93rqo.exe
M:\cmon.exe
O:\82i.cmd
F:\n6j6pc0.com
F:\n89f1d1w.exe
%ProgramFiles%\Windows NT\Accessories\aewordpad.exe
F:\nbke.exe
F:\ncc.exe
F:\ndmego0f.cmd
F:\net.exe
F:\ngq6hva0.exe
F:\nmje9v6d.bat
F:\nncu6kk.com
O:\82tgk9eg.exe
F:\nooakkv.exe
F:\np.exe
F:\nq.bat
%ProgramFiles%\Windows NT\Accessories\avwordpad.exe
F:\nqgcd.com
F:\nskmu.exe
F:\nsv.bat
F:\nt6ry3bn.cmd
F:\ntdeiect.com
F:\ntdelect.com
O:\8386nac.com
F:\NTDETECT.EXE
F:\ntnq.exe
F:\ntphyy.com
F:\nvrfc.bat
%ProgramFiles%\Windows NT\Accessories\eewordpad.exe
F:\nw.exe
F:\nw0t1l0d.exe
F:\nxvhpc.exe
F:\ny36jjt.exe
F:\nyat.exe
O:\8a.exe
F:\O.cmd
F:\o.exe
F:\o6opnro.bat
F:\o6pq1n8.com
F:\o93ml8.bat
%ProgramFiles%\Windows NT\Accessories\pvuimetool.exe
F:\o9o2.com
F:\o9o2u.bat
F:\oaljb6.exe
F:\obg.exe
O:\8ae2q.exe
F:\obtpf.bat
F:\oc.cmd
F:\ocbqsqj.bat
F:\Oeboyg.exe
F:\okelg.exe
F:\okhr.exe
%ProgramFiles%\Windows NT\ijdialer.exe
F:\ol.exe
F:\om.cmd
F:\om0.com
O:\8b3.bat
F:\op.bat
F:\ot.exe
F:\ot2.exe
F:\otf.cmd
F:\ox.cmd
F:\p.cmd
F:\p0sc9t.cmd
%ProgramFiles%\Activision\Call Of Duty Modern Warfare 2\pmiw4sp.exe
%ProgramFiles%\Windows NT\lwhypertrm.exe
F:\p1t.bat
O:\8df.EXE
F:\p3r1ud.exe
F:\p8ihdw.exe
F:\p9.exe
F:\pamn.exe
F:\patp.exe
F:\pbwkwj.COM
F:\pchkh.cmd
F:\pjben6y.exe
F:\pjwtv.cmd
%ProgramFiles%\Windows NT\Pinball\ndpinball.exe
O:\8e.com
F:\pkxfkrki.bat
F:\pllq.exe
F:\pnc.exe
F:\popo.exe
F:\ppinbnp9.exe
F:\prjydpe.cmd
F:\px.bat
F:\pxbn6y.exe
F:\pytnmk.exe
F:\q.bat
%ProgramFiles%\Common Files\04174051500.exe
%ProgramFiles%\Windows NT\pjhypertrm.exe
F:\q.exe
F:\q0rppr.exe
F:\q10js.exe
F:\q1pady.cmd
F:\q2.exe
F:\q2vl2fiy.com
F:\q83iwmgf.bat
F:\qb1.exe
F:\qh.cmd
%temp%\sv2E.tmp
F:\qjatw9aj.exe
%ProgramFiles%\Windows NT\qrdialer.exe
F:\qjfl.exe
F:\qkarc.exe
F:\qkolx.exe
F:\qngbvkhl.exe
F:\qotdyl.bat
F:\qpe6.com
F:\qr.exe
F:\qs6m.bat
M:\cn.exe
O:\8gidy.exe
F:\qsid8g.exe
F:\r.com
%ProgramFiles%\Windows NT\SERVICES.EXE
F:\r.exe
F:\r120.bat
F:\r2mkn.exe
F:\r8wb.bat
F:\r9ghv9.com
F:\rcpi.exe
F:\rehsas.com
O:\8h3hh3m.exe
F:\resycled\boot.com
F:\rf.cmd
F:\rjiybg.exe
%ProgramFiles%\Windows NT\system\dbghelp.dll
F:\rjx0.exe
F:\rmydqsiw.exe
F:\rn.exe
F:\rtnlpipu.com
F:\rv36m1f9.exe
F:\rwrte.exe
O:\8iyqbsp1.exe
F:\s2vgyp.exe
F:\s38k.exe
F:\s39tg.cmd
F:\s6.bat
%ProgramFiles%\Windows NT\system\htrn_jis.dll
F:\s6muem.cmd
F:\s8.exe
F:\s9l.exe
F:\SafeSys.exe
F:\sasyg1y8.com
O:\8m08ty.com
F:\sdc.bat
F:\se11.cmd
F:\server2010.exe
F:\ServerXp.exe
F:\sh.exe
%ProgramFiles%\Windows NT\system\sovhst.exe
F:\shadu.exe
F:\Shell.exe
F:\sie2v8.exe
F:\SiZhu.exe
O:\8mt8bm.exe
F:\slphfx.bat
F:\sm.exe
F:\snaoc9i.exe
F:\SofwareUpdater.exe
F:\spkr9wou.bat
F:\SRCHost.exe
%ProgramFiles%\Windows NT\system\wdfmgr.exe
F:\SRCost.exe
F:\stwi.com
F:\suqfl.exe
O:\8nlo1q.cmd
F:\svchost.exe
F:\svchovst.EXE
F:\system.dll
F:\systex.exe
F:\t.bat
F:\t.cmd
F:\t.exe
%ProgramFiles%\WinRAR\arextloader.exe
F:\t1xdgvq.exe
F:\t2f.exe
O:\8ot8y86.exe
F:\t2jl.exe
F:\t2ydo.exe
F:\t3.com
F:\t82e2v.cmd
F:\tan3yt.bat
F:\tbhje.cmd
F:\tcburi.exe
F:\temp.exe
%ProgramFiles%\Activision\Call Of Duty Modern Warfare 2\vbiw4sp.exe
%ProgramFiles%\WinRAR\dyunrar.exe
O:\8oupido.bat
F:\temp28.exe
F:\tfa8rk6.com
F:\tg.com
F:\tgtighg.cmd
F:\thghikva.exe
F:\tigi.cmd
F:\tikett.exe
F:\tj8odymw.exe
F:\tlmjw.cmd
F:\tmd.exe
O:\8ox61l6.cmd
%ProgramFiles%\WinRAR\hqunrar.exe
F:\tmf3w3g0.com
F:\tmf3w3go.com
F:\tn.exe
F:\tn0k.exe
F:\ts6k.exe
F:\tt.com
F:\tudqrfw.exe
F:\txfl1rhh.com
F:\tyfr.com
O:\8q6h.exe
F:\tyvq.exe
%ProgramFiles%\WinRAR\iiunrar.exe
F:\u.cmd
F:\u.exe
F:\u08.cmd
F:\u18vxqle.com
F:\u26ufgv.exe
F:\u2by.exe
F:\u3dsc.com
F:\u63urr.exe
M:\co.com
%temp%\sv30.tmp
F:\u6k.cmd
F:\u82.exe
%ProgramFiles%\WinRAR\kvunrar.exe
F:\u99.exe
F:\ud.exe
F:\ufwi6sq.exe
F:\uh.exe
F:\uh31.exe
F:\uhjqlk.exe
F:\un_tc.exe
O:\8tss2gwq.bat
F:\uorys.cmd
F:\up.exe
F:\up0ppxwr.com
%ProgramFiles%\WinRAR\nstall.exe
F:\update220.exe
F:\update2201.exe
F:\updater697.exe
F:\UpdateThis.exe
F:\UpdateWindows.exe
F:\updds3.exe
O:\8u.com
F:\ups.exe
F:\Ups3.exe
F:\upsf.exe
F:\uptes.exe
%ProgramFiles%\WinZip\kvwinzip32.exe
F:\upts3.exe
F:\uptsd.exe
F:\Upz.exe
F:\uqb0julr.bat
F:\us8amqf.exe
O:\8uot.exe
F:\ut.bat
F:\ut9x.bat
F:\utcn8c63.exe
F:\uuhgt.bat
F:\uwlmj.com
%ProgramFiles%\WinZip\xswzsepe32.exe
F:\uxkktr.cmd
F:\uyfd9cck.cmd
F:\v0f8rqc.cmd
F:\v0vj.exe
O:\8xlwbngd.exe
F:\v2h3.exe
F:\v3pif.bat
F:\v86htgx.cmd
F:\v9l1l.com
F:\v9l8.exe
F:\v9ug2p2.com
%ProgramFiles%\WowUSBProtector\start.bat
F:\vcf0.exe
F:\vctio.com
F:\vd91t29.exe
O:\90imhpnc.exe
F:\vdej3e.exe
F:\vkrg.exe
F:\vmhr.bat
F:\vnkucvv.com
F:\vp.exe
F:\vpqdgkx.com
F:\vt6e.cmd
%ProgramFiles%\wqhgf.bak
F:\w.bat
F:\w.cmd
O:\91.exe
F:\w.exe
F:\w2qagd.com
F:\w3dn9f.bat
F:\w6hikrv.com
F:\w9fc.exe
F:\wdm.exe
F:\Webhost2.exe
F:\webhost4.exe
%ProgramFiles%\wraplm.dll
F:\Weeiivruved.exe
O:\91m.COM
F:\weg6sp.com
F:\wehds63.exe
F:\wewt425.exe
F:\wewtf.exe
F:\wex.exe
F:\wg0kpd.bat
F:\wg6jj0.exe
F:\wglplm6g.bat
F:\wgp.com
%ProgramFiles%\Activision\Prototype\ototypef.exe
O:\92j11sm.com
%ProgramFiles%\wrappc.dll
F:\Windows.exe
F:\winhost.exe
F:\winser.exe
F:\wjlc.exe
F:\wkcay8u.cmd
F:\wpkx.bat
F:\wstk.exe
F:\wuwu.exe
F:\wv.exe
O:\96.com
F:\wycgb8.cmd
%ProgramFiles%\wrapph.dll
F:\wyqrvts.exe
F:\wyzlo.exe
F:\x.bat
F:\x.cmd
F:\x1.cmd
F:\x1dg.exe
F:\x1o8uo.exe
F:\x63rnneh.exe
M:\copetttt.com
O:\9b8kmipy.com
F:\xa8v8.exe
F:\xadeiect.com
%ProgramFiles%\xmlns.dll
F:\xc.exe
F:\xe9fdii1.cmd
F:\xedex.exe
F:\xene9.bat
F:\xievhrf.exe
F:\xjs.exe
F:\xjv.exe
%temp%\sv5.tmp
F:\xnfrqlvf.exe
F:\xppg3r6.exe
F:\xpq63xl.exe
%ProgramFiles%\XP Antivirus\xpa.exe
F:\xqg0.exe
F:\xqyl68.exe
F:\xue.exe
F:\xv.com
F:\xwpehlv.com
F:\xyh.exe
O:\9bid6bl.exe
F:\y.com
F:\y319s.exe
F:\y6u.bat
F:\y9rlqi.cmd
%ProgramFiles%\XP_AntiSpyware\AVEngn.dll
F:\ydmj.exe
F:\yfmqo.cmd
F:\yfpaoty.exe
F:\ygvtn.exe
F:\yh.bat
O:\9dl.cmd
F:\yi9.exe
F:\yjkjfuo.cmd
F:\ymxf3q.exe
F:\yp.bat
F:\ypjq1.cmd
%ProgramFiles%\XP_AntiSpyware\XP_AntiSpyware.exe
F:\yq.com
F:\yq00tht.exe
F:\yt8a.exe
F:\yv.exe
O:\9es.com
F:\yw6mmv0.exe
F:\zx.exe
G:\3.exe
G:\300y.cmd
G:\30c0e.cmd
G:\30ed3.exe
%ProgramFiles%\Xueeueusz\srvany.exe
G:\31n3b2h.exe
G:\32o3.cmd
G:\35e.exe
O:\9l66g8k1.com
G:\38s3i.exe
G:\39ysi89.com
G:\3bo9tn.cmd
G:\3ce.exe
G:\3dohrt.com
G:\3ds.cmd
G:\3ehxs6.cmd
%ProgramFiles%\Yahoo!\Messenger\rcunwise.exe
G:\3g3.exe
G:\3hihyi.exe
O:\9o.exe
G:\3iugonx.com
G:\3jkka91.com
G:\3jkkdo.exe
G:\3o0fp.exe
G:\3p9wj19.exe
G:\3r33c.CMD
G:\3vf9968r.exe
G:\3wmvmd.cmd
%ProgramFiles%\Yeork\Dycwywa.exe
G:\3wy1vm.cmd
O:\9r8hh2f.exe
G:\3y.bat
G:\3yr1.cmd
G:\535.exe
G:\6.bat
G:\6.exe
G:\62oop0ak.bat
G:\63e.exe
G:\6hg.exe
G:\6j2j.com
%ProgramFiles%\Yzszeccoo.dll
O:\9tb8ist.bat
G:\6o0.bat
G:\6phx.com
G:\6qe.com
G:\6r3p.com
G:\6rq6.exe
G:\6vu680.com
G:\6wqhah.exe
G:\6xdgw26.com
G:\806.com
G:\82.exe
O:\9yp8nyvg.exe
%ProgramFile%\Common Files\Microsoft Shared\explorer.exe
%ProgramFiles%\Activision\Prototype\totypef.exe
%ProgramFiles%\Yzszeccoo.exe
G:\82i.cmd
G:\82tgk9eg.exe
G:\8386nac.com
G:\8a.exe
G:\8ae2q.exe
G:\8b3.bat
G:\8df.EXE
%Temp%\94.exe
O:\a.bat
G:\8e.com
G:\8gidy.exe
G:\8h3hh3m.exe
%SystemDrive%\\Documents and Settings\All Users\「開始」功能表\程式集\啟動\8K5IO6YR.lnk.exe
G:\8iyqbsp1.exe
G:\8m08ty.com
G:\8mt8bm.exe
G:\8nlo1q.cmd
G:\8ot8y86.exe
G:\8oupido.bat
O:\a.exe
G:\8ox61l6.cmd
G:\8q6h.exe
G:\8tss2gwq.bat
G:\8u.com
%SystemDrive%\\Documents and Settings\All Users\「開始」功能表\程式集\啟動\MDUQNR91.lnk.exe
G:\8uot.exe
G:\8xlwbngd.exe
G:\90imhpnc.exe
G:\91.exe
G:\91m.COM
%temp%\svDE.tmp
G:\92j11sm.com
G:\96.com
G:\9b8kmipy.com
G:\9bid6bl.exe
G:\9dl.cmd
%SystemDrive%\\Documents and Settings\All Users\「開始」功能表\程式集\啟動\U2372.lnk.exe
G:\9es.com
G:\9l66g8k1.com
G:\9o.exe
G:\9r8hh2f.exe
O:\a2r.exe
G:\9tb8ist.bat
G:\9yp8nyvg.exe
G:\a.bat
G:\a.exe
G:\a2r.exe
G:\a8qengab.exe
%SystemDrive%\\Documents and Settings\All Users\「開始」功能表\程式集\啟動\WY0QH7.lnk.exe
G:\ab.cmd
G:\abqk2c3i.bat
G:\adba2.exe
O:\a8qengab.exe
G:\af93gcf.exe
G:\af9rgm8h.bat
G:\alt.exe
G:\aluj8r.exe
G:\anky8.exe
G:\aoutfq.exe
G:\ap.com
%SystemDrive%\\downloaded\eqiwpjs0onfd.exe
G:\atymi09.bat
G:\auto.exe
O:\ab.cmd
G:\auto.pif
G:\autorun.exe
G:\autorun.inf
G:\autorunx.exe
G:\autox.exe
G:\avmb.exe
G:\ay8p6v3.cmd
G:\b.bat
%SystemDrive%\\downloaded\Error.exe
G:\b.cmd
O:\abqk2c3i.bat
G:\b.exe
G:\Backup.exe
G:\baksql.bat
G:\Beanfun.exe
G:\bn0.bat
G:\BNB_029.exe
G:\bnkxy.exe
G:\bnmv.exe
G:\bplrl98.cmd
%SystemDrive%\\Downloads\BFSDRV.sys
O:\adba2.exe
G:\bpvwvays.exe
G:\bpx9q3j.exe
G:\bqk.bat
G:\bs3ol8kd2.exe
G:\bsp.cmd
G:\bt8vuaw.com
G:\bunip.bat
G:\bxuup9r.bat
G:\c.bat
G:\c.exe
O:\af93gcf.exe
%SystemDrive%\_@1.tmp
G:\cbpd.exe
G:\ccc.exe
G:\CD8IDOYL.COM
G:\ceqfqp.bat
G:\cfv90h.com
G:\check.exe
G:\chlf9.exe
G:\cjrp8.com
G:\clc1al.com
O:\af9rgm8h.bat
G:\clc3k.com
%SystemDrive%\_@10.tmp
G:\clxam6r6.exe
G:\cm0.com
G:\cmon.exe
G:\cn.exe
G:\co.com
G:\copetttt.com
G:\copy.exe
G:\cp13cg.exe
M:\3ce.exe
M:\copy.exe
O:\alt.exe
G:\cubp.bat
G:\d.bat
%ProgramFiles%\advcsoft\macjie.exe
%SystemDrive%\_@101.tmp
G:\d.exe
G:\d218eht.exe
G:\d22xl.bat
G:\d3bn0j.exe
G:\d6r6jmp.exe
G:\d8ur3qs.bat
O:\aluj8r.exe
G:\dagd.exe
G:\dblnq.exe
G:\ddyikr.CMD
G:\delshare.bat
%SystemDrive%\_@102.tmp
G:\dgf.exe
G:\dgkx.exe
G:\dh66ln.cmd
G:\dhcore.exe
G:\di3su.exe
O:\anky8.exe
G:\diox3j.com
G:\dmf.exe
G:\down.exe
G:\down2.bat
G:\dp.cmd
%SystemDrive%\_@103.tmp
G:\dp.exe
G:\dpu1.exe
G:\dqi.exe
G:\ds.exe
%temp%\system368309ow.dll
G:\dsty.com
G:\dv6pp.exe
G:\dvhyi.exe
G:\dxv.bat
G:\dynrn6e.cmd
G:\dyr2j6mv.exe
%SystemDrive%\_@11.tmp
G:\e.cmd
G:\e.exe
G:\e00233it.com
O:\aoutfq.exe
G:\e0t9n6.exe
G:\e6.com
G:\e619e.cmd
G:\E6IEG.EXE
G:\e898.com
G:\eadf6s.exe
G:\eb9ehyh.exe
%SystemDrive%\_@11F.tmp
G:\ecn.com
G:\eeqt.exe
O:\ap.com
G:\eftwl.exe
G:\eg1.cmd
G:\eito.exe
G:\ejoq.exe
G:\ek.com
G:\ell.exe
G:\erdeIect.com
G:\erjhni.exe
%SystemDrive%\_@12.tmp
G:\ermvu8.cmd
O:\atymi09.bat
G:\et.exe
G:\ewatr.cmd
G:\f.bat
G:\f.exe
G:\ff1q0gw.bat
G:\fgj3lc8.exe
G:\find.exe
G:\fipgnfww.cmd
G:\fjb2.exe
%SystemDrive%\_@121.tmp
O:\auto.exe
G:\fp.exe
G:\fphj6j31.bat
G:\fsdg.exe
G:\ft8.exe
G:\ftiduico.bat
G:\fufb6tq3.cmd
G:\fvan.exe
G:\fvbk.exe
G:\g.exe
G:\g0.cmd
O:\auto.pif
%SystemDrive%\_@122.tmp
G:\g2p3s.exe
G:\g8rruyw.exe
G:\g9rv.exe
G:\gaagw.bat
G:\gabptk6d.bat
G:\gclwpivc.cmd
G:\gdsag.exe
G:\ggkxgvf.bat
G:\ggl.cmd
O:\autorun.exe
G:\ggqn.exe
%SystemDrive%\_@123.tmp
G:\ghdf1.com
G:\gicchk2s.exe
G:\gmi1jxy.com
G:\gnc.bat
G:\gnwav.exe
G:\gnwwy.exe
G:\gplpn.exe
G:\gqsk.bat
M:\cp13cg.exe
O:\autorun.inf
G:\gswrij.exe
G:\gsxlexd.cmd
%SystemDrive%\_@13.tmp
G:\gx.bat
G:\gx.com
G:\gxul.com
G:\gymussy.bat
G:\h.bat
G:\h.CMD
G:\h0j8w.exe
O:\autorunx.exe
G:\h0ti1de.bat
G:\h2.com
G:\h2t6u.exe
%ProgramFiles%\AEWSCAN\Aewscan.exe
%SystemDrive%\_@14.tmp
G:\h3hi1k3.exe
G:\h8i.com
G:\hfap.exe
G:\higj2p.bat
G:\hn.cmd
O:\autox.exe
G:\hnkvaa2.exe
G:\home.exe
G:\host.exe
G:\hovrflst.bat
G:\hpkq.cmd
%SystemDrive%\_@15.tmp
G:\hqx292nu.exe
G:\hsi.com
G:\hsjnkj.exe
G:\htjtq8o.exe
O:\avmb.exe
G:\hupxj.bat
G:\hv8fv2.exe
G:\hvoxmq.exe
G:\hxbpamjb.cmd
G:\hxs.bat
G:\hyj2gunw.exe
%SystemDrive%\_@150.tmp
G:\i.bat
G:\i2.com
G:\ib3qc3t.cmd
%Temp%\t.dll
G:\if6ch9k6.bat
G:\ig.bat
G:\igcmrtjw.cmd
G:\il0byu3h.com
G:\il6.exe
G:\iluqcwr.exe
G:\imt8.cmd
%SystemDrive%\_@151.tmp
G:\iok.exe
G:\ipy.cmd
O:\ay8p6v3.cmd
G:\iscwam2h.cmd
G:\it1d.exe
G:\iu.bat
G:\iw.bat
G:\iwjj.com
G:\ixsla.exe
G:\j.bat
G:\j0.exe
%SystemDrive%\_@152.tmp
G:\j0mpdkja.cmd
O:\b.bat
G:\j1.cmd
G:\j16dp6.exe
G:\j1rxka1n.exe
G:\j83uv.exe
G:\jatxgwcj.bat
G:\jc1r11.exe
G:\jcmmawa.bat
G:\jdt2ofp.exe
G:\jg.com
%SystemDrive%\_@153.tmp
O:\b.cmd
G:\jg6w3yx.com
G:\jhcqxax.exe
G:\jix9a.bat
G:\jj2.com
G:\jkxrox.exe
G:\jl.com
G:\jvu69.bat
G:\jy.exe
G:\k.com
G:\k08aww.bat
O:\b.exe
%SystemDrive%\_@16.tmp
G:\k2.cmd
G:\k6wkwon2.exe
G:\k9cuos2q.exe
G:\ka1nk.bat
G:\karina///debeja.exe
G:\kdy.cmd
G:\kg18j.exe
G:\kgnkxc.exe
G:\kjibu.com
O:\Backup.exe
G:\kk.bat
%SystemDrive%\_@164E.tmp
G:\kk36.exe
G:\kk38g1.exe
G:\kpvqk.exe
G:\kqsr.exe
G:\kuqskg2s.bat
G:\kuruna.exe
G:\kya6l.bat
G:\l1.cmd
M:\cubp.bat
O:\baksql.bat
G:\l3v.exe
G:\l6w2eaih.exe
%SystemDrive%\_@164F.tmp
G:\ldgybkp.bat
G:\lgcadwx.bat
G:\lgnaqil.exe
G:\lgrncie.bat
G:\lgvg8q.exe
G:\lhwdcgcb.bat
G:\lj.exe
O:\Beanfun.exe
G:\lj6hdv.com
G:\ll.exe
G:\lp3c.bat
%SystemDrive%\_@1650.tmp
G:\lsfjg.com
G:\lsg6jj9.exe
G:\lskeqbfc.exe
G:\ltc.bat
G:\lulu.exe
G:\lwd.bat
O:\bn0.bat
G:\lyhwcea.exe
G:\m.bat
G:\m.exe
G:\m6dqm2vd.exe
%ProgramFiles%\aidu\bar\bdgdins.dll
%SystemDrive%\_@1651.tmp
G:\m6n.com
G:\m8wafly.com
G:\m9as2c.cmd
G:\mayyuk9g.bat
O:\BNB_029.exe
G:\mbewb2n.exe
G:\mcmm.bat
G:\mka.bat
G:\mm6q.exe
G:\momo.exe
G:\motr.exe
%SystemDrive%\_@17.tmp
G:\mpstxgx.exe
G:\mrghykh.exe
G:\mrsne.bat
O:\bnkxy.exe
G:\msbackup.exe
G:\msn.exe
G:\mt.com
G:\mt0.cmd
G:\mtlhieej.cmd
G:\n.com
G:\n.exe
%SystemDrive%\_@18.tmp
G:\n1m.exe
G:\n1v93rqo.exe
%temp%\taso*.dll
G:\n6j6pc0.com
G:\n89f1d1w.exe
G:\nbke.exe
G:\ncc.exe
G:\ndmego0f.cmd
G:\net.exe
G:\ngq6hva0.exe
G:\nmje9v6d.bat
%SystemDrive%\_@19.tmp
G:\nncu6kk.com
O:\bnmv.exe
G:\nooakkv.exe
G:\np.exe
G:\nq.bat
G:\nqgcd.com
G:\nskmu.exe
G:\nsv.bat
G:\nt6ry3bn.cmd
G:\ntdeiect.com
G:\ntdelect.com
%SystemDrive%\_@1A.tmp
O:\bplrl98.cmd
G:\NTDETECT.EXE
G:\ntnq.exe
G:\ntphyy.com
G:\nvrfc.bat
G:\nw.exe
G:\nw0t1l0d.exe
G:\nxvhpc.exe
G:\ny36jjt.exe
G:\nyat.exe
G:\O.cmd
O:\bpvwvays.exe
%SystemDrive%\_@1AD.tmp
G:\o.exe
G:\o6opnro.bat
G:\o6pq1n8.com
G:\o93ml8.bat
G:\o9o2.com
G:\o9o2u.bat
G:\oaljb6.exe
G:\obg.exe
G:\obtpf.bat
O:\bpx9q3j.exe
G:\oc.cmd
%SystemDrive%\_@1B.tmp
G:\ocbqsqj.bat
G:\Oeboyg.exe
G:\okelg.exe
G:\okhr.exe
G:\ol.exe
G:\om.cmd
G:\om0.com
G:\op.bat
M:\d.bat
O:\bqk.bat
G:\ot.exe
G:\ot2.exe
%SystemDrive%\_@1C.tmp
G:\otf.cmd
G:\ox.cmd
G:\p.cmd
G:\p0sc9t.cmd
G:\p1t.bat
G:\p3r1ud.exe
G:\p8ihdw.exe
O:\bs3ol8kd2.exe
G:\p9.exe
G:\pamn.exe
G:\patp.exe
%SystemDrive%\_@1D.tmp
G:\pbwkwj.COM
G:\pchkh.cmd
G:\pjben6y.exe
G:\pjwtv.cmd
G:\pkxfkrki.bat
G:\pllq.exe
O:\bsp.cmd
G:\pnc.exe
G:\popo.exe
G:\ppinbnp9.exe
G:\prjydpe.cmd
%SystemDrive%\_@1D0.tmp
G:\px.bat
G:\pxbn6y.exe
G:\pytnmk.exe
G:\q.bat
G:\q.exe
O:\bt8vuaw.com
G:\q0rppr.exe
G:\q10js.exe
G:\q1pady.cmd
G:\q2.exe
G:\q2vl2fiy.com
%ProgramFiles%\aii4sd7vap\5df80bmbel.exe
%SystemDrive%\_@1D1.tmp
G:\q83iwmgf.bat
G:\qb1.exe
G:\qh.cmd
O:\bunip.bat
G:\qjatw9aj.exe
G:\qjfl.exe
G:\qkarc.exe
G:\qkolx.exe
G:\qngbvkhl.exe
G:\qotdyl.bat
G:\qpe6.com
%SystemDrive%\_@1E.tmp
G:\qr.exe
G:\qs6m.bat
O:\bxuup9r.bat
G:\qsid8g.exe
G:\r.com
G:\r.exe
G:\r120.bat
G:\r2mkn.exe
G:\r8wb.bat
G:\r9ghv9.com
G:\rcpi.exe
%SystemDrive%\_@1F.tmp
G:\rehsas.com
%temp%\taso*.exe
G:\resycled\boot.com
G:\rf.cmd
G:\rjiybg.exe
G:\rjx0.exe
G:\rmydqsiw.exe
G:\rn.exe
G:\rtnlpipu.com
G:\rv36m1f9.exe
G:\rwrte.exe
%SystemDrive%\_@2.tmp
O:\c.bat
G:\s2vgyp.exe
G:\s38k.exe
G:\s39tg.cmd
G:\s6.bat
G:\s6muem.cmd
G:\s8.exe
G:\s9l.exe
G:\SafeSys.exe
G:\sasyg1y8.com
G:\sdc.bat
O:\c.exe
%SystemDrive%\_@20.tmp
G:\se11.cmd
G:\server2010.exe
G:\ServerXp.exe
G:\sh.exe
G:\shadu.exe
G:\Shell.exe
G:\sie2v8.exe
G:\SiZhu.exe
G:\slphfx.bat
O:\cbpd.exe
G:\sm.exe
%SystemDrive%\_@21.tmp
G:\snaoc9i.exe
G:\SofwareUpdater.exe
G:\spkr9wou.bat
G:\SRCHost.exe
G:\SRCost.exe
G:\stwi.com
G:\suqfl.exe
G:\svchost.exe
M:\d.exe
O:\ccc.exe
G:\svchovst.EXE
G:\system.dll
%SystemDrive%\_@22.tmp
G:\systex.exe
G:\t.bat
G:\t.cmd
G:\t.exe
G:\t1xdgvq.exe
G:\t2f.exe
G:\t2jl.exe
O:\CD8IDOYL.COM
G:\t2ydo.exe
G:\t3.com
G:\t82e2v.cmd
%SystemDrive%\_@23.tmp
G:\tan3yt.bat
G:\tbhje.cmd
G:\tcburi.exe
G:\temp.exe
G:\temp28.exe
G:\tfa8rk6.com
O:\ceqfqp.bat
G:\tg.com
G:\tgtighg.cmd
G:\thghikva.exe
G:\tigi.cmd
%SystemDrive%\_@24.tmp
G:\tikett.exe
G:\tj8odymw.exe
G:\tlmjw.cmd
G:\tmd.exe
G:\tmf3w3g0.com
O:\cfv90h.com
G:\tmf3w3go.com
G:\tn.exe
G:\tn0k.exe
G:\ts6k.exe
G:\tt.com
%SystemDrive%\_@25.tmp
G:\tudqrfw.exe
G:\txfl1rhh.com
G:\tyfr.com
G:\tyvq.exe
O:\check.exe
G:\u.cmd
G:\u.exe
G:\u08.cmd
G:\u18vxqle.com
G:\u26ufgv.exe
G:\u2by.exe
%ProgramFiles%\Anti Trojan Elite\ATEPMon.sys
%SystemDrive%\_@26.tmp
G:\u3dsc.com
G:\u63urr.exe
O:\chlf9.exe
G:\u6k.cmd
G:\u82.exe
G:\u99.exe
G:\ud.exe
G:\ufwi6sq.exe
G:\uh.exe
G:\uh31.exe
G:\uhjqlk.exe
%SystemDrive%\_@27.tmp
G:\un_tc.exe
O:\cjrp8.com
G:\uorys.cmd
G:\up.exe
G:\up0ppxwr.com
G:\update220.exe
G:\update2201.exe
G:\updater697.exe
G:\UpdateThis.exe
G:\UpdateWindows.exe
G:\updds3.exe
%SystemDrive%\_@28.tmp
%Temp%\taso.exe
G:\ups.exe
G:\Ups3.exe
G:\upsf.exe
G:\uptes.exe
G:\upts3.exe
G:\uptsd.exe
G:\Upz.exe
G:\uqb0julr.bat
G:\us8amqf.exe
G:\ut.bat
O:\clc1al.com
%SystemDrive%\_@29.tmp
G:\ut9x.bat
G:\utcn8c63.exe
G:\uuhgt.bat
G:\uwlmj.com
G:\uxkktr.cmd
G:\uyfd9cck.cmd
G:\v0f8rqc.cmd
G:\v0vj.exe
G:\v2h3.exe
O:\clc3k.com
G:\v3pif.bat
%SystemDrive%\_@2A.tmp
G:\v86htgx.cmd
G:\v9l1l.com
G:\v9l8.exe
G:\v9ug2p2.com
G:\vcf0.exe
G:\vctio.com
G:\vd91t29.exe
G:\vdej3e.exe
M:\d218eht.exe
O:\clxam6r6.exe
G:\vkrg.exe
G:\vmhr.bat
%SystemDrive%\_@2B.tmp
G:\vnkucvv.com
G:\vp.exe
G:\vpqdgkx.com
G:\vt6e.cmd
G:\w.bat
G:\w.cmd
G:\w.exe
O:\cm0.com
G:\w2qagd.com
G:\w3dn9f.bat
G:\w6hikrv.com
%SystemDrive%\_@2DF.tmp
G:\w9fc.exe
G:\wdm.exe
G:\Webhost2.exe
G:\webhost4.exe
G:\Weeiivruved.exe
G:\weg6sp.com
O:\cmon.exe
G:\wehds63.exe
G:\wewt425.exe
G:\wewtf.exe
G:\wex.exe
%SystemDrive%\_@2E0.tmp
G:\wg0kpd.bat
G:\wg6jj0.exe
G:\wglplm6g.bat
G:\wgp.com
G:\Windows.exe
O:\cn.exe
G:\winhost.exe
G:\winser.exe
G:\wjlc.exe
G:\wkcay8u.cmd
G:\wpkx.bat
%SystemDrive%\_@3.tmp
G:\wstk.exe
G:\wuwu.exe
G:\wv.exe
G:\wycgb8.cmd
O:\co.com
G:\wyqrvts.exe
G:\wyzlo.exe
G:\x.bat
G:\x.cmd
G:\x1.cmd
G:\x1dg.exe
%SystemDrive%\_@3A.tmp
G:\x1o8uo.exe
G:\x63rnneh.exe
G:\xa8v8.exe
O:\copetttt.com
G:\xadeiect.com
G:\xc.exe
G:\xe9fdii1.cmd
G:\xedex.exe
G:\xene9.bat
G:\xievhrf.exe
G:\xjs.exe
%ProgramFiles%\Anti Trojan Elite\TERegPct.exe
%SystemDrive%\_@3B.tmp
G:\xjv.exe
O:\copy.exe
G:\xnfrqlvf.exe
G:\xppg3r6.exe
G:\xpq63xl.exe
G:\xqg0.exe
G:\xqyl68.exe
G:\xue.exe
G:\xv.com
G:\xwpehlv.com
G:\xyh.exe
%SystemDrive%\_@3C.tmp
O:\cp13cg.exe
G:\y.com
G:\y319s.exe
G:\y6u.bat
G:\y9rlqi.cmd
G:\ydmj.exe
G:\yfmqo.cmd
G:\yfpaoty.exe
G:\ygvtn.exe
G:\yh.bat
G:\yi9.exe
%temp%\taso0.dll
%SystemDrive%\_@3D.tmp
G:\yjkjfuo.cmd
G:\ymxf3q.exe
G:\yp.bat
G:\ypjq1.cmd
G:\yq.com
G:\yq00tht.exe
G:\yt8a.exe
G:\yv.exe
G:\yw6mmv0.exe
O:\cubp.bat
G:\zx.exe
%SystemDrive%\_@3E.tmp
H:\3.exe
H:\300y.cmd
H:\30c0e.cmd
H:\30ed3.exe
H:\31n3b2h.exe
H:\32o3.cmd
H:\35e.exe
H:\38s3i.exe
M:\d22xl.bat
O:\d.bat
H:\39ysi89.com
H:\3bo9tn.cmd
%SystemDrive%\_@3F.tmp
H:\3ce.exe
H:\3dohrt.com
H:\3ds.cmd
H:\3ehxs6.cmd
H:\3g3.exe
H:\3hihyi.exe
H:\3iugonx.com
O:\d.exe
H:\3jkka91.com
H:\3jkkdo.exe
H:\3o0fp.exe
%SystemDrive%\_@4.tmp
H:\3p9wj19.exe
H:\3r33c.CMD
H:\3vf9968r.exe
H:\3wmvmd.cmd
H:\3wy1vm.cmd
H:\3y.bat
O:\d218eht.exe
H:\3yr1.cmd
H:\535.exe
H:\6.bat
H:\6.exe
%SystemDrive%\_@41.tmp
H:\62oop0ak.bat
H:\63e.exe
H:\6hg.exe
H:\6j2j.com
H:\6o0.bat
O:\d22xl.bat
H:\6phx.com
H:\6qe.com
H:\6r3p.com
H:\6rq6.exe
H:\6vu680.com
%SystemDrive%\_@42.tmp
H:\6wqhah.exe
H:\6xdgw26.com
H:\806.com
H:\82.exe
O:\d3bn0j.exe
H:\82i.cmd
H:\82tgk9eg.exe
H:\8386nac.com
H:\8a.exe
H:\8ae2q.exe
H:\8b3.bat
%SystemDrive%\_@43.tmp
H:\8df.EXE
H:\8e.com
H:\8gidy.exe
O:\d6r6jmp.exe
H:\8h3hh3m.exe
H:\8iyqbsp1.exe
H:\8m08ty.com
H:\8mt8bm.exe
H:\8nlo1q.cmd
H:\8ot8y86.exe
H:\8oupido.bat
%SystemDrive%\_@4A0.tmp
H:\8ox61l6.cmd
H:\8q6h.exe
O:\d8ur3qs.bat
H:\8tss2gwq.bat
H:\8u.com
H:\8uot.exe
H:\8xlwbngd.exe
H:\90imhpnc.exe
H:\91.exe
H:\91m.COM
H:\92j11sm.com
%ProgramFiles%\Anti Trojan Elite\TJEnder.exe
%SystemDrive%\_@4A1.tmp
O:\dagd.exe
H:\96.com
H:\9b8kmipy.com
H:\9bid6bl.exe
H:\9dl.cmd
H:\9es.com
H:\9l66g8k1.com
H:\9o.exe
H:\9r8hh2f.exe
H:\9tb8ist.bat
H:\9yp8nyvg.exe
O:\dblnq.exe
%SystemDrive%\_@4A2.tmp
H:\a.bat
H:\a.exe
H:\a2r.exe
H:\a8qengab.exe
H:\ab.cmd
H:\abqk2c3i.bat
H:\adba2.exe
H:\af93gcf.exe
H:\af9rgm8h.bat
%ProgramFiles%\Common Files\11977387950.exe
H:\alt.exe
%SystemDrive%\_@4D.tmp
H:\aluj8r.exe
H:\anky8.exe
H:\aoutfq.exe
H:\ap.com
H:\atymi09.bat
H:\auto.exe
H:\auto.pif
H:\autorun.exe
M:\d3bn0j.exe
%temp%\taso1.dll
H:\autorun.inf
H:\autorunx.exe
%SystemDrive%\_@5.tmp
H:\autox.exe
H:\avmb.exe
H:\ay8p6v3.cmd
H:\b.bat
H:\b.cmd
H:\b.exe
H:\Backup.exe
O:\ddyikr.CMD
H:\baksql.bat
H:\Beanfun.exe
H:\bn0.bat
%SystemDrive%\_@5B.tmp
H:\BNB_029.exe
H:\bnkxy.exe
H:\bnmv.exe
H:\bplrl98.cmd
H:\bpvwvays.exe
H:\bpx9q3j.exe
O:\delshare.bat
H:\bqk.bat
H:\bs3ol8kd2.exe
H:\bsp.cmd
H:\bt8vuaw.com
%SystemDrive%\_@6.tmp
H:\bunip.bat
H:\bxuup9r.bat
H:\c.bat
H:\c.exe
H:\cbpd.exe
O:\dgf.exe
H:\ccc.exe
H:\CD8IDOYL.COM
H:\ceqfqp.bat
H:\cfv90h.com
H:\check.exe
%SystemDrive%\_@62.tmp
H:\chlf9.exe
H:\cjrp8.com
H:\clc1al.com
H:\clc3k.com
O:\dgkx.exe
H:\clxam6r6.exe
H:\cm0.com
H:\cmon.exe
H:\cn.exe
H:\co.com
H:\copetttt.com
%SystemDrive%\_@63.tmp
H:\copy.exe
H:\cp13cg.exe
H:\cubp.bat
O:\dh66ln.cmd
H:\d.bat
H:\d.exe
H:\d218eht.exe
H:\d22xl.bat
H:\d3bn0j.exe
H:\d6r6jmp.exe
H:\d8ur3qs.bat
%SystemDrive%\_@7.tmp
H:\dagd.exe
H:\dblnq.exe
O:\dhcore.exe
H:\ddyikr.CMD
H:\delshare.bat
H:\dgf.exe
H:\dgkx.exe
H:\dh66ln.cmd
H:\dhcore.exe
H:\di3su.exe
H:\diox3j.com
%SystemDrive%\_@74.tmp
H:\dmf.exe
O:\di3su.exe
H:\down.exe
H:\down2.bat
H:\dp.cmd
H:\dp.exe
H:\dpu1.exe
H:\dqi.exe
H:\ds.exe
H:\dsty.com
H:\dv6pp.exe
%ProgramFiles%\AntiMalware\antimalware.exe
O:\diox3j.com
%SystemDrive%\_@75.tmp
H:\dvhyi.exe
H:\dxv.bat
H:\dynrn6e.cmd
H:\dyr2j6mv.exe
H:\e.cmd
H:\e.exe
H:\e00233it.com
H:\e0t9n6.exe
H:\e6.com
O:\dmf.exe
H:\e619e.cmd
%SystemDrive%\_@8.tmp
H:\E6IEG.EXE
H:\e898.com
H:\eadf6s.exe
H:\eb9ehyh.exe
H:\ecn.com
H:\eeqt.exe
H:\eftwl.exe
H:\eg1.cmd
M:\d6r6jmp.exe
O:\down.exe
H:\eito.exe
H:\ejoq.exe
%SystemDrive%\_@9.tmp
H:\ek.com
H:\ell.exe
H:\erdeIect.com
H:\erjhni.exe
H:\ermvu8.cmd
H:\et.exe
H:\ewatr.cmd
%Temp%\TDSS564.tmp
H:\f.bat
H:\f.exe
H:\ff1q0gw.bat
%SystemDrive%\_@A.tmp
H:\fgj3lc8.exe
H:\find.exe
H:\fipgnfww.cmd
H:\fjb2.exe
H:\fp.exe
H:\fphj6j31.bat
O:\down2.bat
H:\fsdg.exe
H:\ft8.exe
H:\ftiduico.bat
H:\fufb6tq3.cmd
%SystemDrive%\_@B.tmp
H:\fvan.exe
H:\fvbk.exe
H:\g.exe
H:\g0.cmd
H:\g2p3s.exe
O:\dp.cmd
H:\g8rruyw.exe
H:\g9rv.exe
H:\gaagw.bat
H:\gabptk6d.bat
H:\gclwpivc.cmd
%SystemDrive%\_@C.tmp
H:\gdsag.exe
H:\ggkxgvf.bat
H:\ggl.cmd
H:\ggqn.exe
O:\dp.exe
H:\ghdf1.com
H:\gicchk2s.exe
H:\gmi1jxy.com
H:\gnc.bat
H:\gnwav.exe
H:\gnwwy.exe
%SystemDrive%\_@C9.tmp
H:\gplpn.exe
H:\gqsk.bat
H:\gswrij.exe
O:\dpu1.exe
H:\gsxlexd.cmd
H:\gx.bat
H:\gx.com
H:\gxul.com
H:\gymussy.bat
H:\h.bat
H:\h.CMD
%SystemDrive%\_@CBA.tmp
H:\h0j8w.exe
H:\h0ti1de.bat
O:\dqi.exe
H:\h2.com
H:\h2t6u.exe
H:\h3hi1k3.exe
H:\h8i.com
H:\hfap.exe
H:\higj2p.bat
H:\hn.cmd
H:\hnkvaa2.exe
%SystemDrive%\_@D.tmp
H:\home.exe
O:\ds.exe
H:\host.exe
H:\hovrflst.bat
H:\hpkq.cmd
H:\hqx292nu.exe
H:\hsi.com
H:\hsjnkj.exe
H:\htjtq8o.exe
H:\hupxj.bat
H:\hv8fv2.exe
%systemdrive%\_@D9.tmp
O:\dsty.com
H:\hvoxmq.exe
H:\hxbpamjb.cmd
H:\hxs.bat
H:\hyj2gunw.exe
H:\i.bat
H:\i2.com
H:\ib3qc3t.cmd
H:\if6ch9k6.bat
H:\ig.bat
H:\igcmrtjw.cmd
O:\dv6pp.exe
%ProgramFiles%\Antivirus 2009\av2009.exe
%systemdrive%\_@DB.tmp
H:\il0byu3h.com
H:\il6.exe
H:\iluqcwr.exe
H:\imt8.cmd
H:\iok.exe
H:\ipy.cmd
H:\iscwam2h.cmd
H:\it1d.exe
M:\d8ur3qs.bat
O:\dvhyi.exe
H:\iu.bat
H:\iw.bat
%SystemDrive%\_@E.tmp
H:\iwjj.com
H:\ixsla.exe
H:\j.bat
H:\j0.exe
H:\j0mpdkja.cmd
H:\j1.cmd
H:\j16dp6.exe
O:\dxv.bat
H:\j1rxka1n.exe
H:\j83uv.exe
H:\jatxgwcj.bat
%SystemDrive%\_@E0.tmp
H:\jc1r11.exe
H:\jcmmawa.bat
H:\jdt2ofp.exe
H:\jg.com
H:\jg6w3yx.com
H:\jhcqxax.exe
%Temp%\TDSS5a3.tmp
H:\jix9a.bat
H:\jj2.com
H:\jkxrox.exe
H:\jl.com
%SystemDrive%\_@E1.tmp
H:\jvu69.bat
H:\jy.exe
H:\k.com
H:\k08aww.bat
H:\k2.cmd
O:\dynrn6e.cmd
H:\k6wkwon2.exe
H:\k9cuos2q.exe
H:\ka1nk.bat
H:\karina///debeja.exe
H:\kdy.cmd
%SystemDrive%\_@E2.tmp
H:\kg18j.exe
H:\kgnkxc.exe
H:\kjibu.com
H:\kk.bat
O:\dyr2j6mv.exe
H:\kk36.exe
H:\kk38g1.exe
H:\kpvqk.exe
H:\kqsr.exe
H:\kuqskg2s.bat
H:\kuruna.exe
%SystemDrive%\_@EE2.tmp
H:\kya6l.bat
H:\l1.cmd
H:\l3v.exe
O:\e.cmd
H:\l6w2eaih.exe
H:\ldgybkp.bat
H:\lgcadwx.bat
H:\lgnaqil.exe
H:\lgrncie.bat
H:\lgvg8q.exe
H:\lhwdcgcb.bat
%SystemDrive%\_@EE3.tmp
H:\lj.exe
H:\lj6hdv.com
O:\e.exe
H:\ll.exe
H:\lp3c.bat
H:\lsfjg.com
H:\lsg6jj9.exe
H:\lskeqbfc.exe
H:\ltc.bat
H:\lulu.exe
H:\lwd.bat
%SystemDrive%\_@EE4.tmp
H:\lyhwcea.exe
O:\e00233it.com
H:\m.bat
H:\m.exe
H:\m6dqm2vd.exe
H:\m6n.com
H:\m8wafly.com
H:\m9as2c.cmd
H:\mayyuk9g.bat
H:\mbewb2n.exe
H:\mcmm.bat
%SystemDrive%\_@F.tmp
O:\e0t9n6.exe
H:\mka.bat
H:\mm6q.exe
H:\momo.exe
H:\motr.exe
H:\mpstxgx.exe
H:\mrghykh.exe
H:\mrsne.bat
H:\msbackup.exe
H:\msn.exe
H:\mt.com
O:\e6.com
%SystemDrive%\_@F8.tmp
H:\mt0.cmd
H:\mtlhieej.cmd
H:\n.com
H:\n.exe
H:\n1m.exe
H:\n1v93rqo.exe
H:\n6j6pc0.com
H:\n89f1d1w.exe
H:\nbke.exe
M:\3dohrt.com
%Temp%\97378
O:\e619e.cmd
H:\ncc.exe
%ProgramFile%\common files\services\svchost.exe
%ProgramFiles%\Antivirus System PRO\Antivirussystempro.exe
%SystemDrive%\~hha.tmp
H:\ndmego0f.cmd
H:\net.exe
H:\ngq6hva0.exe
H:\nmje9v6d.bat
H:\nncu6kk.com
H:\nooakkv.exe
O:\E6IEG.EXE
H:\np.exe
H:\nq.bat
H:\nqgcd.com
H:\nskmu.exe
%SystemDrive%\~lgpjds.tmp
H:\nsv.bat
H:\nt6ry3bn.cmd
H:\ntdeiect.com
H:\ntdelect.com
H:\NTDETECT.EXE
O:\e898.com
H:\ntnq.exe
H:\ntphyy.com
H:\nvrfc.bat
H:\nw.exe
H:\nw0t1l0d.exe
%SystemDrive%\~tlagif.tmp
H:\nxvhpc.exe
H:\ny36jjt.exe
H:\nyat.exe
H:\O.cmd
%Temp%\TDSSc723.tmp
H:\o.exe
H:\o6opnro.bat
H:\o6pq1n8.com
H:\o93ml8.bat
H:\o9o2.com
H:\o9o2u.bat
%SystemDrive%\017056bcacc9a780.dat
H:\oaljb6.exe
H:\obg.exe
H:\obtpf.bat
O:\eadf6s.exe
H:\oc.cmd
H:\ocbqsqj.bat
H:\Oeboyg.exe
H:\okelg.exe
H:\okhr.exe
H:\ol.exe
H:\om.cmd
%SystemDrive%\04a64900d636b856.dat
H:\om0.com
H:\op.bat
O:\eb9ehyh.exe
H:\ot.exe
H:\ot2.exe
H:\otf.cmd
H:\ox.cmd
H:\p.cmd
H:\p0sc9t.cmd
H:\p1t.bat
H:\p3r1ud.exe
%SystemDrive%\09fe46084be51e4c.dat
H:\p8ihdw.exe
O:\ecn.com
H:\p9.exe
H:\pamn.exe
H:\patp.exe
H:\pbwkwj.COM
H:\pchkh.cmd
H:\pjben6y.exe
H:\pjwtv.cmd
H:\pkxfkrki.bat
H:\pllq.exe
%SystemDrive%\0f244108581299cb.dat
O:\eeqt.exe
H:\pnc.exe
H:\popo.exe
H:\ppinbnp9.exe
H:\prjydpe.cmd
H:\px.bat
H:\pxbn6y.exe
H:\pytnmk.exe
H:\q.bat
H:\q.exe
H:\q0rppr.exe
O:\eftwl.exe
%SystemDrive%\1246000.dll
H:\q10js.exe
H:\q1pady.cmd
H:\q2.exe
H:\q2vl2fiy.com
H:\q83iwmgf.bat
H:\qb1.exe
H:\qh.cmd
H:\qjatw9aj.exe
H:\qjfl.exe
O:\eg1.cmd
H:\qkarc.exe
%SystemDrive%\1414400.dll
H:\qkolx.exe
H:\qngbvkhl.exe
H:\qotdyl.bat
H:\qpe6.com
H:\qr.exe
H:\qs6m.bat
H:\qsid8g.exe
H:\r.com
M:\dagd.exe
O:\eito.exe
H:\r.exe
H:\r120.bat
%SystemDrive%\1c5a43f0155e9c67.dat
H:\r2mkn.exe
H:\r8wb.bat
H:\r9ghv9.com
H:\rcpi.exe
H:\rehsas.com
H:\resycled\boot.com
H:\rf.cmd
O:\ejoq.exe
H:\rjiybg.exe
H:\rjx0.exe
H:\rmydqsiw.exe
%ProgramFiles%\Antivirus System PRO\conf.cfg
%SystemDrive%\2258000.dll
H:\rn.exe
H:\rtnlpipu.com
H:\rv36m1f9.exe
H:\rwrte.exe
H:\s2vgyp.exe
O:\ek.com
H:\s38k.exe
H:\s39tg.cmd
H:\s6.bat
H:\s6muem.cmd
H:\s8.exe
%SystemDrive%\2686100.dll
H:\s9l.exe
H:\SafeSys.exe
H:\sasyg1y8.com
H:\sdc.bat
O:\ell.exe
H:\se11.cmd
H:\server2010.exe
H:\ServerXp.exe
H:\sh.exe
H:\shadu.exe
H:\Shell.exe
%SystemDrive%\2765700.dll
H:\sie2v8.exe
H:\SiZhu.exe
H:\slphfx.bat
%Temp%\TDSSc772.tmp
H:\sm.exe
H:\snaoc9i.exe
H:\SofwareUpdater.exe
H:\spkr9wou.bat
H:\SRCHost.exe
H:\SRCost.exe
H:\stwi.com
%SystemDrive%\2921500.dll
H:\suqfl.exe
H:\svchost.exe
O:\erdeIect.com
H:\svchovst.EXE
H:\system.dll
H:\systex.exe
H:\t.bat
H:\t.cmd
H:\t.exe
H:\t1xdgvq.exe
H:\t2f.exe
%SystemDrive%\2946400.dll
H:\t2jl.exe
O:\erjhni.exe
H:\t2ydo.exe
H:\t3.com
H:\t82e2v.cmd
H:\tan3yt.bat
H:\tbhje.cmd
H:\tcburi.exe
H:\temp.exe
H:\temp28.exe
H:\tfa8rk6.com
%SystemDrive%\3122000.dll
O:\ermvu8.cmd
H:\tg.com
H:\tgtighg.cmd
H:\thghikva.exe
H:\tigi.cmd
H:\tikett.exe
H:\tj8odymw.exe
H:\tlmjw.cmd
H:\tmd.exe
H:\tmf3w3g0.com
H:\tmf3w3go.com
O:\et.exe
%SystemDrive%\3176600.dll
H:\tn.exe
H:\tn0k.exe
H:\ts6k.exe
H:\tt.com
H:\tudqrfw.exe
H:\txfl1rhh.com
H:\tyfr.com
H:\tyvq.exe
H:\u.cmd
O:\ewatr.cmd
H:\u.exe
%SystemDrive%\3207000.dll
H:\u08.cmd
H:\u18vxqle.com
H:\u26ufgv.exe
H:\u2by.exe
H:\u3dsc.com
H:\u63urr.exe
H:\u6k.cmd
H:\u82.exe
M:\dblnq.exe
O:\f.bat
H:\u99.exe
H:\ud.exe
%SystemDrive%\36000.dll
H:\ufwi6sq.exe
H:\uh.exe
H:\uh31.exe
H:\uhjqlk.exe
H:\un_tc.exe
H:\uorys.cmd
H:\up.exe
O:\f.exe
H:\up0ppxwr.com
H:\update220.exe
H:\update2201.exe
%SystemDrive%\53100.dll
H:\updater697.exe
H:\UpdateThis.exe
H:\UpdateWindows.exe
H:\updds3.exe
H:\ups.exe
H:\Ups3.exe
O:\ff1q0gw.bat
H:\upsf.exe
H:\uptes.exe
H:\upts3.exe
H:\uptsd.exe
%ProgramFiles%\Antivirus System PRO\mbase.vdb
%SystemDrive%\5329ed20cba38711.dat
H:\Upz.exe
H:\uqb0julr.bat
H:\us8amqf.exe
H:\ut.bat
O:\fgj3lc8.exe
H:\ut9x.bat
H:\utcn8c63.exe
H:\uuhgt.bat
H:\uwlmj.com
H:\uxkktr.cmd
H:\uyfd9cck.cmd
%SystemDrive%\5a9535a887186b1e.dat
H:\v0f8rqc.cmd
H:\v0vj.exe
H:\v2h3.exe
O:\find.exe
H:\v3pif.bat
H:\v86htgx.cmd
H:\v9l1l.com
H:\v9l8.exe
H:\v9ug2p2.com
H:\vcf0.exe
H:\vctio.com
%SystemDrive%\61cc9974b4cbd243.dat
H:\vd91t29.exe
H:\vdej3e.exe
%Temp%\TDSSc7c2.tmp
H:\vkrg.exe
H:\vmhr.bat
H:\vnkucvv.com
H:\vp.exe
H:\vpqdgkx.com
H:\vt6e.cmd
H:\w.bat
H:\w.cmd
%SystemDrive%\6bfec438f5fbcf47.dat
H:\w.exe
O:\fipgnfww.cmd
H:\w2qagd.com
H:\w3dn9f.bat
H:\w6hikrv.com
H:\w9fc.exe
H:\wdm.exe
H:\Webhost2.exe
H:\webhost4.exe
H:\Weeiivruved.exe
H:\weg6sp.com
%SystemDrive%\76a1c9a0cb088633.dat
O:\fjb2.exe
H:\wehds63.exe
H:\wewt425.exe
H:\wewtf.exe
H:\wex.exe
H:\wg0kpd.bat
H:\wg6jj0.exe
H:\wglplm6g.bat
H:\wgp.com
H:\Windows.exe
H:\winhost.exe
O:\fp.exe
%SystemDrive%\823bca4830c88d47.dat
H:\winser.exe
H:\wjlc.exe
H:\wkcay8u.cmd
H:\wpkx.bat
H:\wstk.exe
H:\wuwu.exe
H:\wv.exe
H:\wycgb8.cmd
H:\wyqrvts.exe
O:\fphj6j31.bat
H:\wyzlo.exe
%SystemDrive%\856200.dll
H:\x.bat
H:\x.cmd
H:\x1.cmd
H:\x1dg.exe
H:\x1o8uo.exe
H:\x63rnneh.exe
H:\xa8v8.exe
H:\xadeiect.com
M:\ddyikr.CMD
O:\fsdg.exe
H:\xc.exe
H:\xe9fdii1.cmd
%SystemDrive%\859600.dll
H:\xedex.exe
H:\xene9.bat
H:\xievhrf.exe
H:\xjs.exe
H:\xjv.exe
H:\xnfrqlvf.exe
H:\xppg3r6.exe
O:\ft8.exe
H:\xpq63xl.exe
H:\xqg0.exe
H:\xqyl68.exe
%SystemDrive%\8b1c3d14c902f43b.dat
H:\xue.exe
H:\xv.com
H:\xwpehlv.com
H:\xyh.exe
H:\y.com
H:\y319s.exe
O:\ftiduico.bat
H:\y6u.bat
H:\y9rlqi.cmd
H:\ydmj.exe
H:\yfmqo.cmd
%SystemDrive%\anyone360.exe
H:\yfpaoty.exe
H:\ygvtn.exe
H:\yh.bat
H:\yi9.exe
H:\yjkjfuo.cmd
O:\fufb6tq3.cmd
H:\ymxf3q.exe
H:\yp.bat
H:\ypjq1.cmd
H:\yq.com
H:\yq00tht.exe
%ProgramFiles%\Antivirus System PRO\quarantine.vdb
%SystemDrive%\asdfjlasdjf.dll
H:\yt8a.exe
H:\yv.exe
H:\yw6mmv0.exe
O:\fvan.exe
H:\zx.exe
I:\3.exe
I:\300y.cmd
I:\30c0e.cmd
I:\30ed3.exe
I:\31n3b2h.exe
I:\32o3.cmd
%SystemDrive%\cmdshell.dll
I:\35e.exe
I:\38s3i.exe
O:\fvbk.exe
I:\39ysi89.com
I:\3bo9tn.cmd
I:\3ce.exe
I:\3dohrt.com
I:\3ds.cmd
I:\3ehxs6.cmd
I:\3g3.exe
I:\3hihyi.exe
%SystemDrive%\comine.exe
I:\3iugonx.com
%Temp%\TDSSc8a9.tmp
I:\3jkka91.com
I:\3jkkdo.exe
I:\3o0fp.exe
I:\3p9wj19.exe
I:\3r33c.CMD
I:\3vf9968r.exe
I:\3wmvmd.cmd
I:\3wy1vm.cmd
I:\3y.bat
%SystemDrive%\d44906.1830391884.exe
O:\g.exe
I:\3yr1.cmd
I:\535.exe
I:\6.bat
I:\6.exe
I:\62oop0ak.bat
I:\63e.exe
I:\6hg.exe
I:\6j2j.com
I:\6o0.bat
I:\6phx.com
O:\g0.cmd
%SystemDrive%\d51613.2014718056.exe
I:\6qe.com
I:\6r3p.com
I:\6rq6.exe
I:\6vu680.com
I:\6wqhah.exe
I:\6xdgw26.com
I:\806.com
I:\82.exe
I:\82i.cmd
O:\g2p3s.exe
I:\82tgk9eg.exe
%SystemDrive%\daaacad85ed21fff.dat
I:\8386nac.com
I:\8a.exe
I:\8ae2q.exe
I:\8b3.bat
I:\8df.EXE
I:\8e.com
I:\8gidy.exe
I:\8h3hh3m.exe
M:\delshare.bat
O:\g8rruyw.exe
I:\8iyqbsp1.exe
I:\8m08ty.com
%SystemDrive%\dl_205490.exe
I:\8mt8bm.exe
I:\8nlo1q.cmd
I:\8ot8y86.exe
I:\8oupido.bat
I:\8ox61l6.cmd
I:\8q6h.exe
I:\8tss2gwq.bat
O:\g9rv.exe
I:\8u.com
I:\8uot.exe
I:\8xlwbngd.exe
%SystemDrive%\dntn.bak
I:\90imhpnc.exe
I:\91.exe
I:\91m.COM
I:\92j11sm.com
I:\96.com
I:\9b8kmipy.com
O:\gaagw.bat
I:\9bid6bl.exe
I:\9dl.cmd
I:\9es.com
I:\9l66g8k1.com
%SystemDrive%\DOCUME~1\LOCALS~1\APPLIC~1\LOCKSW~1\ScrDebugThat.exe
I:\9o.exe
I:\9r8hh2f.exe
I:\9tb8ist.bat
I:\9yp8nyvg.exe
I:\a.bat
O:\gabptk6d.bat
I:\a.exe
I:\a2r.exe
I:\a8qengab.exe
I:\ab.cmd
I:\abqk2c3i.bat
%SystemDrive%\Documents and Settings\10004.exe
I:\adba2.exe
I:\af93gcf.exe
I:\af9rgm8h.bat
I:\alt.exe
O:\gclwpivc.cmd
I:\aluj8r.exe
I:\anky8.exe
I:\aoutfq.exe
I:\ap.com
I:\atymi09.bat
I:\auto.exe
%ProgramFiles%\Antivirus System PRO\queue.vdb
%SystemDrive%\Documents and Settings\4.exe
I:\auto.pif
I:\autorun.exe
O:\gdsag.exe
I:\autorun.inf
I:\autorunx.exe
I:\autox.exe
I:\avmb.exe
I:\ay8p6v3.cmd
I:\b.bat
I:\b.cmd
I:\b.exe
%SystemDrive%\Documents and Settings\Administrator\「開始」功能表\程式集\啟動\1E0967.lnk
I:\Backup.exe
O:\ggkxgvf.bat
I:\baksql.bat
I:\Beanfun.exe
I:\bn0.bat
I:\BNB_029.exe
I:\bnkxy.exe
I:\bnmv.exe
I:\bplrl98.cmd
I:\bpvwvays.exe
I:\bpx9q3j.exe
%SystemDrive%\Documents and Settings\Administrator\「開始」功能表\程式集\啟動\D70895.lnk
%Temp%\Temp\RarSFX0\UnlockerDriver5.sys
I:\bqk.bat
I:\bs3ol8kd2.exe
I:\bsp.cmd
I:\bt8vuaw.com
I:\bunip.bat
I:\bxuup9r.bat
I:\c.bat
I:\c.exe
I:\cbpd.exe
I:\ccc.exe
O:\ggl.cmd
%SystemDrive%\Documents and Settings\Administrator\「開始」功能表\程式集\啟動\Seagate 註冊.lnk
I:\CD8IDOYL.COM
I:\ceqfqp.bat
I:\cfv90h.com
I:\check.exe
I:\chlf9.exe
I:\cjrp8.com
I:\clc1al.com
I:\clc3k.com
I:\clxam6r6.exe
O:\ggqn.exe
I:\cm0.com
%SystemDrive%\Documents and Settings\Administrator\Application Data\drivers\111wfs1intwq.sys
I:\cmon.exe
I:\cn.exe
I:\co.com
I:\copetttt.com
I:\copy.exe
I:\cp13cg.exe
I:\cubp.bat
I:\d.bat
M:\dgf.exe
O:\ghdf1.com
I:\d.exe
I:\d218eht.exe
%SystemDrive%\Documents and Settings\Administrator\Application Data\inst.exe
I:\d22xl.bat
I:\d3bn0j.exe
I:\d6r6jmp.exe
I:\d8ur3qs.bat
I:\dagd.exe
I:\dblnq.exe
I:\ddyikr.CMD
O:\gicchk2s.exe
I:\delshare.bat
I:\dgf.exe
I:\dgkx.exe
%SystemDrive%\Documents and Settings\Administrator\Application Data\seres.exe
I:\dh66ln.cmd
I:\dhcore.exe
I:\di3su.exe
I:\diox3j.com
I:\dmf.exe
I:\down.exe
O:\gmi1jxy.com
I:\down2.bat
I:\dp.cmd
I:\dp.exe
I:\dpu1.exe
%SystemDrive%\Documents and Settings\Administrator\Application Data\svcst.exe
I:\dqi.exe
I:\ds.exe
I:\dsty.com
I:\dv6pp.exe
I:\dvhyi.exe
O:\gnc.bat
I:\dxv.bat
I:\dynrn6e.cmd
I:\dyr2j6mv.exe
I:\e.cmd
I:\e.exe
%SystemDrive%\Documents and Settings\Administrator\cson.exe
I:\e00233it.com
I:\e0t9n6.exe
I:\e6.com
I:\e619e.cmd
O:\gnwav.exe
I:\E6IEG.EXE
I:\e898.com
I:\eadf6s.exe
I:\eb9ehyh.exe
I:\ecn.com
I:\eeqt.exe
%SystemDrive%\Documents and Settings\Administrator\delself.bat
I:\eftwl.exe
I:\eg1.cmd
I:\eito.exe
O:\gnwwy.exe
I:\ejoq.exe
I:\ek.com
I:\ell.exe
I:\erdeIect.com
I:\erjhni.exe
I:\ermvu8.cmd
I:\et.exe
%ProgramFiles%\AntivirusPro_2010\AntivirusPro_2010.exe
%SystemDrive%\Documents and Settings\Administrator\Local Settings\Application Data\~FileLockReboot.tmp
I:\ewatr.cmd
O:\gplpn.exe
I:\f.bat
I:\f.exe
I:\ff1q0gw.bat
I:\fgj3lc8.exe
I:\find.exe
I:\fipgnfww.cmd
I:\fjb2.exe
I:\fp.exe
I:\fphj6j31.bat
%SystemDrive%\Documents and Settings\Administrator\msword98.exe
O:\gqsk.bat
I:\fsdg.exe
I:\ft8.exe
I:\ftiduico.bat
I:\fufb6tq3.cmd
I:\fvan.exe
I:\fvbk.exe
I:\g.exe
I:\g0.cmd
I:\g2p3s.exe
I:\g8rruyw.exe
%Temp%\TempFile(1).exe
%SystemDrive%\Documents and Settings\Administrator\restorer64_a.exe
I:\g9rv.exe
I:\gaagw.bat
I:\gabptk6d.bat
I:\gclwpivc.cmd
I:\gdsag.exe
I:\ggkxgvf.bat
I:\ggl.cmd
I:\ggqn.exe
I:\ghdf1.com
O:\gswrij.exe
I:\gicchk2s.exe
%SystemDrive%\Documents and Settings\All Users.WINDOWS\「開始」功能表\程式集\啟動\d9wgrdiv1tfccbf40r.exe
I:\gmi1jxy.com
I:\gnc.bat
I:\gnwav.exe
I:\gnwwy.exe
I:\gplpn.exe
I:\gqsk.bat
I:\gswrij.exe
I:\gsxlexd.cmd
M:\dgkx.exe
O:\gsxlexd.cmd
I:\gx.bat
I:\gx.com
%SystemDrive%\Documents and Settings\All Users.WINDOWS\Application Data\18712304\18712304.exe
I:\gxul.com
I:\gymussy.bat
I:\h.bat
I:\h.CMD
I:\h0j8w.exe
I:\h0ti1de.bat
I:\h2.com
O:\gx.bat
I:\h2t6u.exe
I:\h3hi1k3.exe
I:\h8i.com
%SystemDrive%\Documents and Settings\All Users\「開始」功能表\程式集\啟動\1681.lnk
I:\hfap.exe
I:\higj2p.bat
I:\hn.cmd
I:\hnkvaa2.exe
I:\home.exe
I:\host.exe
O:\gx.com
I:\hovrflst.bat
I:\hpkq.cmd
I:\hqx292nu.exe
I:\hsi.com
%SystemDrive%\Documents and Settings\All Users\「開始」功能表\程式集\啟動\f2hipwscn0erog289s.exe
I:\hsjnkj.exe
I:\htjtq8o.exe
I:\hupxj.bat
I:\hv8fv2.exe
I:\hvoxmq.exe
O:\gxul.com
I:\hxbpamjb.cmd
I:\hxs.bat
I:\hyj2gunw.exe
I:\i.bat
I:\i2.com
%SystemDrive%\Documents and Settings\All Users\「開始」功能表\程式集\啟動\j0jnw3iri9s76qq.exe
I:\ib3qc3t.cmd
I:\if6ch9k6.bat
I:\ig.bat
I:\igcmrtjw.cmd
O:\gymussy.bat
I:\il0byu3h.com
I:\il6.exe
I:\iluqcwr.exe
I:\imt8.cmd
I:\iok.exe
I:\ipy.cmd
%SystemDrive%\Documents and Settings\All Users\「開始」功能表\程式集\啟動\k66xo6mv4s4uxn.exe
I:\iscwam2h.cmd
I:\it1d.exe
I:\iu.bat
O:\h.bat
I:\iw.bat
I:\iwjj.com
I:\ixsla.exe
I:\j.bat
I:\j0.exe
I:\j0mpdkja.cmd
I:\j1.cmd
%SystemDrive%\Documents and Settings\All Users\「開始」功能表\程式集\啟動\Kill Amcap.lnk
I:\j16dp6.exe
I:\j1rxka1n.exe
O:\h.CMD
I:\j83uv.exe
I:\jatxgwcj.bat
I:\jc1r11.exe
I:\jcmmawa.bat
I:\jdt2ofp.exe
I:\jg.com
I:\jg6w3yx.com
I:\jhcqxax.exe
%ProgramFiles%\AntivirusPro_2010\AVEngn.dll
%SystemDrive%\Documents and Settings\All Users\「開始」功能表\程式集\啟動\MDUQNR91.lnk.exe
O:\h0j8w.exe
I:\jix9a.bat
I:\jj2.com
I:\jkxrox.exe
I:\jl.com
I:\jvu69.bat
I:\jy.exe
I:\k.com
I:\k08aww.bat
I:\k2.cmd
I:\k6wkwon2.exe
O:\h0ti1de.bat
%SystemDrive%\Documents and Settings\All Users\「開始」功能表\程式集\啟動\msconfig32.lnk
I:\k9cuos2q.exe
I:\ka1nk.bat
I:\karina///debeja.exe
I:\kdy.cmd
I:\kg18j.exe
I:\kgnkxc.exe
I:\kjibu.com
I:\kk.bat
I:\kk36.exe
%Temp%\test.exe
I:\kk38g1.exe
%SystemDrive%\Documents and Settings\All Users\「開始」功能表\程式集\啟動\pew61qeftdgqocw.exe
I:\kpvqk.exe
I:\kqsr.exe
I:\kuqskg2s.bat
I:\kuruna.exe
I:\kya6l.bat
I:\l1.cmd
I:\l3v.exe
I:\l6w2eaih.exe
M:\dh66ln.cmd
O:\h2.com
I:\ldgybkp.bat
I:\lgcadwx.bat
%SystemDrive%\Documents and Settings\All Users\「開始」功能表\程式集\啟動\q0op3nq07mvd.bat
I:\lgnaqil.exe
I:\lgrncie.bat
I:\lgvg8q.exe
I:\lhwdcgcb.bat
I:\lj.exe
I:\lj6hdv.com
I:\ll.exe
O:\h2t6u.exe
I:\lp3c.bat
I:\lsfjg.com
I:\lsg6jj9.exe
%SystemDrive%\Documents and Settings\All Users\「開始」功能表\程式集\啟動\rynbdraef.exe
I:\lskeqbfc.exe
I:\ltc.bat
I:\lulu.exe
I:\lwd.bat
I:\lyhwcea.exe
I:\m.bat
O:\h3hi1k3.exe
I:\m.exe
I:\m6dqm2vd.exe
I:\m6n.com
I:\m8wafly.com
%SystemDrive%\Documents and Settings\All Users\「開始」功能表\程式集\啟動\U2372.lnk.exe
I:\m9as2c.cmd
I:\mayyuk9g.bat
I:\mbewb2n.exe
I:\mcmm.bat
I:\mka.bat
O:\h8i.com
I:\mm6q.exe
I:\momo.exe
I:\motr.exe
I:\mpstxgx.exe
I:\mrghykh.exe
%SystemDrive%\Documents and Settings\All Users\「開始」功能表\程式集\啟動\WY0QH7.lnk.exe
I:\mrsne.bat
I:\msbackup.exe
I:\msn.exe
I:\mt.com
O:\hfap.exe
I:\mt0.cmd
I:\mtlhieej.cmd
I:\n.com
I:\n.exe
I:\n1m.exe
I:\n1v93rqo.exe
%SystemDrive%\Documents and Settings\All Users\2.exe
I:\n6j6pc0.com
I:\n89f1d1w.exe
I:\nbke.exe
O:\higj2p.bat
I:\ncc.exe
I:\ndmego0f.cmd
I:\net.exe
I:\ngq6hva0.exe
I:\nmje9v6d.bat
I:\nncu6kk.com
I:\nooakkv.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\03863121.exe
I:\np.exe
I:\nq.bat
O:\hn.cmd
I:\nqgcd.com
I:\nskmu.exe
I:\nsv.bat
I:\nt6ry3bn.cmd
I:\ntdeiect.com
I:\ntdelect.com
I:\NTDETECT.EXE
I:\ntnq.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\15910934\15910934.exe
I:\ntphyy.com
O:\hnkvaa2.exe
I:\nvrfc.bat
I:\nw.exe
I:\nw0t1l0d.exe
I:\nxvhpc.exe
I:\ny36jjt.exe
I:\nyat.exe
I:\O.cmd
I:\o.exe
I:\o6opnro.bat
%ProgramFiles%\AntivirusPro_2010\htmlayout.dll
O:\home.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\16220144\16220144.exe
I:\o6pq1n8.com
I:\o93ml8.bat
I:\o9o2.com
I:\o9o2u.bat
I:\oaljb6.exe
I:\obg.exe
I:\obtpf.bat
I:\oc.cmd
I:\ocbqsqj.bat
O:\host.exe
I:\Oeboyg.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\17207825.exe
I:\okelg.exe
I:\okhr.exe
I:\ol.exe
I:\om.cmd
I:\om0.com
I:\op.bat
I:\ot.exe
I:\ot2.exe
M:\dhcore.exe
%ProgramFiles%\Common Files\1685932861400.exe
I:\otf.cmd
I:\ox.cmd
%SystemDrive%\Documents and Settings\All Users\Application Data\17207825\17207825.exe
I:\p.cmd
I:\p0sc9t.cmd
I:\p1t.bat
I:\p3r1ud.exe
I:\p8ihdw.exe
I:\p9.exe
I:\pamn.exe
%Temp%\tlso.exe
I:\patp.exe
I:\pbwkwj.COM
I:\pchkh.cmd
%SystemDrive%\Documents and Settings\All Users\Application Data\18303594\18303594.exe
I:\pjben6y.exe
I:\pjwtv.cmd
I:\pkxfkrki.bat
I:\pllq.exe
I:\pnc.exe
I:\popo.exe
O:\hovrflst.bat
I:\ppinbnp9.exe
I:\prjydpe.cmd
I:\px.bat
I:\pxbn6y.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\18874064\18874064.exe
I:\pytnmk.exe
I:\q.bat
I:\q.exe
I:\q0rppr.exe
I:\q10js.exe
O:\hpkq.cmd
I:\q1pady.cmd
I:\q2.exe
I:\q2vl2fiy.com
I:\q83iwmgf.bat
I:\qb1.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\19121874\19121874.exe
I:\qh.cmd
I:\qjatw9aj.exe
I:\qjfl.exe
I:\qkarc.exe
O:\hqx292nu.exe
I:\qkolx.exe
I:\qngbvkhl.exe
I:\qotdyl.bat
I:\qpe6.com
I:\qr.exe
I:\qs6m.bat
%SystemDrive%\Documents and Settings\All Users\Application Data\24yO5072.exe
I:\qsid8g.exe
I:\r.com
I:\r.exe
O:\hsi.com
I:\r120.bat
I:\r2mkn.exe
I:\r8wb.bat
I:\r9ghv9.com
I:\rcpi.exe
I:\rehsas.com
I:\resycled\boot.com
%SystemDrive%\Documents and Settings\All Users\Application Data\3DD93860C2.sys
I:\rf.cmd
I:\rjiybg.exe
O:\hsjnkj.exe
I:\rjx0.exe
I:\rmydqsiw.exe
I:\rn.exe
I:\rtnlpipu.com
I:\rv36m1f9.exe
I:\rwrte.exe
I:\s2vgyp.exe
I:\s38k.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\95920926\95920926.exe
I:\s39tg.cmd
O:\htjtq8o.exe
I:\s6.bat
I:\s6muem.cmd
I:\s8.exe
I:\s9l.exe
I:\SafeSys.exe
I:\sasyg1y8.com
I:\sdc.bat
I:\se11.cmd
I:\server2010.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\98313586\98313586.exe
O:\hupxj.bat
I:\ServerXp.exe
I:\sh.exe
I:\shadu.exe
I:\Shell.exe
I:\sie2v8.exe
I:\SiZhu.exe
I:\slphfx.bat
I:\sm.exe
I:\snaoc9i.exe
I:\SofwareUpdater.exe
O:\hv8fv2.exe
%ProgramFiles%\AntivirusPro_2010\pthreadVC2.dll
%SystemDrive%\Documents and Settings\All Users\Application Data\ABOUT TEAM INFO SECT\Extra Pure.exe
I:\spkr9wou.bat
I:\SRCHost.exe
I:\SRCost.exe
I:\stwi.com
I:\suqfl.exe
I:\svchost.exe
I:\svchovst.EXE
I:\system.dll
M:\di3su.exe
O:\hvoxmq.exe
I:\systex.exe
I:\t.bat
%SystemDrive%\Documents and Settings\All Users\Application Data\afecubi.exe
I:\t.cmd
I:\t.exe
I:\t1xdgvq.exe
I:\t2f.exe
I:\t2jl.exe
I:\t2ydo.exe
I:\t3.com
O:\hxbpamjb.cmd
I:\t82e2v.cmd
I:\tan3yt.bat
I:\tbhje.cmd
%SystemDrive%\Documents and Settings\All Users\Application Data\Application  Software\VTXDATxF.bat
I:\tcburi.exe
I:\temp.exe
I:\temp28.exe
I:\tfa8rk6.com
I:\tg.com
I:\tgtighg.cmd
%Temp%\tmp.tmp
I:\thghikva.exe
I:\tigi.cmd
I:\tikett.exe
I:\tj8odymw.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\B6727BDAC4.sys
I:\tlmjw.cmd
I:\tmd.exe
I:\tmf3w3g0.com
I:\tmf3w3go.com
I:\tn.exe
O:\hxs.bat
I:\tn0k.exe
I:\ts6k.exe
I:\tt.com
I:\tudqrfw.exe
I:\txfl1rhh.com
%SystemDrive%\Documents and Settings\All Users\Application Data\bike bold move shim\ante dale.exe
I:\tyfr.com
I:\tyvq.exe
I:\u.cmd
I:\u.exe
O:\hyj2gunw.exe
I:\u08.cmd
I:\u18vxqle.com
I:\u26ufgv.exe
I:\u2by.exe
I:\u3dsc.com
I:\u63urr.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\burn download defy inside\mail pile.exe
I:\u6k.cmd
I:\u82.exe
I:\u99.exe
O:\i.bat
I:\ud.exe
I:\ufwi6sq.exe
I:\uh.exe
I:\uh31.exe
I:\uhjqlk.exe
I:\un_tc.exe
I:\uorys.cmd
%SystemDrive%\Documents and Settings\All Users\Application Data\burn download defy inside\Safe Browse.exe
I:\up.exe
I:\up0ppxwr.com
O:\i2.com
I:\update220.exe
I:\update2201.exe
I:\updater697.exe
I:\UpdateThis.exe
I:\UpdateWindows.exe
I:\updds3.exe
I:\ups.exe
I:\Ups3.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\cast dale way math\browse vga.exe
I:\upsf.exe
O:\ib3qc3t.cmd
I:\uptes.exe
I:\upts3.exe
I:\uptsd.exe
I:\Upz.exe
I:\uqb0julr.bat
I:\us8amqf.exe
I:\ut.bat
I:\ut9x.bat
I:\utcn8c63.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\does dog two city\MEDIA WAVE.exe
O:\if6ch9k6.bat
I:\uuhgt.bat
I:\uwlmj.com
I:\uxkktr.cmd
I:\uyfd9cck.cmd
I:\v0f8rqc.cmd
I:\v0vj.exe
I:\v2h3.exe
I:\v3pif.bat
I:\v86htgx.cmd
I:\v9l1l.com
O:\ig.bat
%SystemDrive%\Documents and Settings\All Users\Application Data\ehem.com
I:\v9l8.exe
I:\v9ug2p2.com
I:\vcf0.exe
I:\vctio.com
I:\vd91t29.exe
I:\vdej3e.exe
I:\vkrg.exe
I:\vmhr.bat
I:\vnkucvv.com
M:\3ds.cmd
M:\diox3j.com
O:\igcmrtjw.cmd
I:\vp.exe
%ProgramFiles%\AntivirusPro_2010\Uninstall.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\LPK.DLL
I:\vpqdgkx.com
I:\vt6e.cmd
I:\w.bat
I:\w.cmd
I:\w.exe
I:\w2qagd.com
I:\w3dn9f.bat
O:\il0byu3h.com
I:\w6hikrv.com
I:\w9fc.exe
I:\wdm.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\flag ace stupid data\Love info.exe
I:\Webhost2.exe
I:\webhost4.exe
I:\Weeiivruved.exe
I:\weg6sp.com
I:\wehds63.exe
I:\wewt425.exe
O:\il6.exe
I:\wewtf.exe
I:\wex.exe
I:\wg0kpd.bat
I:\wg6jj0.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\fypexudim.sys
I:\wglplm6g.bat
I:\wgp.com
I:\Windows.exe
I:\winhost.exe
I:\winser.exe
%Temp%\tmp25.tmp
I:\wjlc.exe
I:\wkcay8u.cmd
I:\wpkx.bat
I:\wstk.exe
I:\wuwu.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\ihav.com
I:\wv.exe
I:\wycgb8.cmd
I:\wyqrvts.exe
I:\wyzlo.exe
O:\iluqcwr.exe
I:\x.bat
I:\x.cmd
I:\x1.cmd
I:\x1dg.exe
I:\x1o8uo.exe
I:\x63rnneh.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\ihitusix.sys
I:\xa8v8.exe
I:\xadeiect.com
I:\xc.exe
O:\imt8.cmd
I:\xe9fdii1.cmd
I:\xedex.exe
I:\xene9.bat
I:\xievhrf.exe
I:\xjs.exe
I:\xjv.exe
I:\xnfrqlvf.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\ityt.exe
I:\xppg3r6.exe
I:\xpq63xl.exe
O:\iok.exe
I:\xqg0.exe
I:\xqyl68.exe
I:\xue.exe
I:\xv.com
I:\xwpehlv.com
I:\xyh.exe
I:\y.com
I:\y319s.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
I:\y6u.bat
O:\ipy.cmd
I:\y9rlqi.cmd
I:\ydmj.exe
I:\yfmqo.cmd
I:\yfpaoty.exe
I:\ygvtn.exe
I:\yh.bat
I:\yi9.exe
I:\yjkjfuo.cmd
I:\ymxf3q.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\KrMS5wpauYa.exe
O:\iscwam2h.cmd
I:\yp.bat
I:\ypjq1.cmd
I:\yq.com
I:\yq00tht.exe
I:\yt8a.exe
I:\yv.exe
I:\yw6mmv0.exe
I:\zx.exe
J:\3.exe
J:\300y.cmd
O:\it1d.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\lanmao.exe
J:\30c0e.cmd
J:\30ed3.exe
J:\31n3b2h.exe
J:\32o3.cmd
J:\35e.exe
J:\38s3i.exe
J:\39ysi89.com
J:\3bo9tn.cmd
J:\3ce.exe
%Temp%\a.exe
O:\iu.bat
J:\3dohrt.com
%SystemDrive%\Documents and Settings\All Users\Application Data\mahefo.bat
J:\3ds.cmd
J:\3ehxs6.cmd
J:\3g3.exe
J:\3hihyi.exe
J:\3iugonx.com
J:\3jkka91.com
J:\3jkkdo.exe
J:\3o0fp.exe
O:\iw.bat
J:\3p9wj19.exe
J:\3r33c.CMD
%ProgramFile%\Common Files\SysLive.exe
%ProgramFiles%\AntivirusPro2009\AntivirusPro2009.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\cpush.exe
J:\3vf9968r.exe
J:\3wmvmd.cmd
J:\3wy1vm.cmd
J:\3y.bat
J:\3yr1.cmd
O:\iwjj.com
J:\535.exe
J:\6.bat
J:\6.exe
J:\62oop0ak.bat
J:\63e.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\YiqilaiLyrics_2001.exe
J:\6hg.exe
J:\6j2j.com
J:\6o0.bat
J:\6phx.com
O:\ixsla.exe
J:\6qe.com
J:\6r3p.com
J:\6rq6.exe
J:\6vu680.com
J:\6wqhah.exe
J:\6xdgw26.com
%SystemDrive%\Documents and Settings\All Users\Application Data\Microsoft\Media Player\obj\09.sys
J:\806.com
J:\82.exe
J:\82i.cmd
%Temp%\tmp27.tmp
J:\82tgk9eg.exe
J:\8386nac.com
J:\8a.exe
J:\8ae2q.exe
J:\8b3.bat
J:\8df.EXE
J:\8e.com
%SystemDrive%\Documents and Settings\All Users\Application Data\Microsoft\Media Player\obj\wmpobj.sys
J:\8gidy.exe
J:\8h3hh3m.exe
O:\j.bat
J:\8iyqbsp1.exe
J:\8m08ty.com
J:\8mt8bm.exe
J:\8nlo1q.cmd
J:\8ot8y86.exe
J:\8oupido.bat
J:\8ox61l6.cmd
J:\8q6h.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\Microsoft\Media Player\wmp\mtlrd.sys
J:\8tss2gwq.bat
O:\j0.exe
J:\8u.com
J:\8uot.exe
J:\8xlwbngd.exe
J:\90imhpnc.exe
J:\91.exe
J:\91m.COM
J:\92j11sm.com
J:\96.com
J:\9b8kmipy.com
%SystemDrive%\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\SYSTEM\5IrxH6iGlR_2263.exe
O:\j0mpdkja.cmd
J:\9bid6bl.exe
J:\9dl.cmd
J:\9es.com
J:\9l66g8k1.com
J:\9o.exe
J:\9r8hh2f.exe
J:\9tb8ist.bat
J:\9yp8nyvg.exe
J:\a.bat
J:\a.exe
O:\j1.cmd
%SystemDrive%\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\SYSTEM\9LKh3oIFUJ_2234.exe
J:\a2r.exe
J:\a8qengab.exe
J:\ab.cmd
J:\abqk2c3i.bat
J:\adba2.exe
J:\af93gcf.exe
J:\af9rgm8h.bat
J:\alt.exe
J:\aluj8r.exe
O:\j16dp6.exe
J:\anky8.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\F5IItB3EvY_2234.dll
J:\aoutfq.exe
J:\ap.com
J:\atymi09.bat
J:\auto.exe
J:\auto.pif
J:\autorun.exe
J:\autorun.inf
J:\autorunx.exe
M:\dmf.exe
O:\j1rxka1n.exe
J:\autox.exe
J:\avmb.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\Microsoft\Office\USERDATA\NSz9oybUiI.dll
J:\ay8p6v3.cmd
J:\b.bat
J:\b.cmd
J:\b.exe
J:\Backup.exe
J:\baksql.bat
J:\Beanfun.exe
O:\j83uv.exe
J:\bn0.bat
J:\BNB_029.exe
J:\bnkxy.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\USERDATA\webbrowser_2263.dll
J:\bnmv.exe
J:\bplrl98.cmd
J:\bpvwvays.exe
J:\bpx9q3j.exe
J:\bqk.bat
J:\bs3ol8kd2.exe
O:\jatxgwcj.bat
J:\bsp.cmd
J:\bt8vuaw.com
J:\bunip.bat
J:\bxuup9r.bat
%ProgramFiles%\antiviruspro2009\avengn.dll
%SystemDrive%\Documents and Settings\All Users\Application Data\nBwhGyYIndfV.exe
J:\c.bat
J:\c.exe
J:\cbpd.exe
J:\ccc.exe
O:\jc1r11.exe
J:\CD8IDOYL.COM
J:\ceqfqp.bat
J:\cfv90h.com
J:\check.exe
J:\chlf9.exe
J:\cjrp8.com
%SystemDrive%\Documents and Settings\All Users\Application Data\noti.sys
J:\clc1al.com
J:\clc3k.com
J:\clxam6r6.exe
O:\jcmmawa.bat
J:\cm0.com
J:\cmon.exe
J:\cn.exe
J:\co.com
J:\copetttt.com
J:\copy.exe
J:\cp13cg.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\NRmq1l44p.exe
J:\cubp.bat
J:\d.bat
%Temp%\tmp31.tmp
J:\d.exe
J:\d218eht.exe
J:\d22xl.bat
J:\d3bn0j.exe
J:\d6r6jmp.exe
J:\d8ur3qs.bat
J:\dagd.exe
J:\dblnq.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\oUrVPuPddVDgXoF.exe
J:\ddyikr.CMD
O:\jdt2ofp.exe
J:\delshare.bat
J:\dgf.exe
J:\dgkx.exe
J:\dh66ln.cmd
J:\dhcore.exe
J:\di3su.exe
J:\diox3j.com
J:\dmf.exe
J:\down.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\qtrTdkRFQkQo.dll
O:\jg.com
J:\down2.bat
J:\dp.cmd
J:\dp.exe
J:\dpu1.exe
J:\dqi.exe
J:\ds.exe
J:\dsty.com
J:\dv6pp.exe
J:\dvhyi.exe
J:\dxv.bat
O:\jg6w3yx.com
%SystemDrive%\Documents and Settings\All Users\Application Data\sBiLfGvINagxmit.exe
J:\dynrn6e.cmd
J:\dyr2j6mv.exe
J:\e.cmd
J:\e.exe
J:\e00233it.com
J:\e0t9n6.exe
J:\e6.com
J:\e619e.cmd
J:\E6IEG.EXE
O:\jhcqxax.exe
J:\e898.com
%SystemDrive%\Documents and Settings\All Users\Application Data\STORE LESS JUGS SURF\HIDE DEAF.exe
J:\eadf6s.exe
J:\eb9ehyh.exe
J:\ecn.com
J:\eeqt.exe
J:\eftwl.exe
J:\eg1.cmd
J:\eito.exe
J:\ejoq.exe
M:\down.exe
O:\jix9a.bat
J:\ek.com
J:\ell.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\t2jDx9PgC.exe
J:\erdeIect.com
J:\erjhni.exe
J:\ermvu8.cmd
J:\et.exe
J:\ewatr.cmd
J:\f.bat
J:\f.exe
O:\jj2.com
J:\ff1q0gw.bat
J:\fgj3lc8.exe
J:\find.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\taskmgr.exe
J:\fipgnfww.cmd
J:\fjb2.exe
J:\fp.exe
J:\fphj6j31.bat
J:\fsdg.exe
J:\ft8.exe
O:\jkxrox.exe
J:\ftiduico.bat
J:\fufb6tq3.cmd
J:\fvan.exe
J:\fvbk.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\Tick Find Close Surf\grid show.exe
J:\g.exe
J:\g0.cmd
J:\g2p3s.exe
J:\g8rruyw.exe
J:\g9rv.exe
O:\jl.com
J:\gaagw.bat
J:\gabptk6d.bat
J:\gclwpivc.cmd
J:\gdsag.exe
J:\ggkxgvf.bat
%ProgramFiles%\antiviruspro2009\htmlayout.dll
%SystemDrive%\Documents and Settings\All Users\Application Data\ufoz.bat
J:\ggl.cmd
J:\ggqn.exe
J:\ghdf1.com
O:\jvu69.bat
J:\gicchk2s.exe
J:\gmi1jxy.com
J:\gnc.bat
J:\gnwav.exe
J:\gnwwy.exe
J:\gplpn.exe
J:\gqsk.bat
%SystemDrive%\Documents and Settings\All Users\Application Data\urawofyje.exe
J:\gswrij.exe
J:\gsxlexd.cmd
O:\jy.exe
J:\gx.bat
J:\gx.com
J:\gxul.com
J:\gymussy.bat
J:\h.bat
J:\h.CMD
J:\h0j8w.exe
J:\h0ti1de.bat
%SystemDrive%\Documents and Settings\All Users\Application Data\wd\kswbc.dll
J:\h2.com
%Temp%\tmp3F.tmp
J:\h2t6u.exe
J:\h3hi1k3.exe
J:\h8i.com
J:\hfap.exe
J:\higj2p.bat
J:\hn.cmd
J:\hnkvaa2.exe
J:\home.exe
J:\host.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\wd\kswebshield.dll
O:\k.com
J:\hovrflst.bat
J:\hpkq.cmd
J:\hqx292nu.exe
J:\hsi.com
J:\hsjnkj.exe
J:\htjtq8o.exe
J:\hupxj.bat
J:\hv8fv2.exe
J:\hvoxmq.exe
J:\hxbpamjb.cmd
O:\k08aww.bat
%SystemDrive%\Documents and Settings\All Users\Application Data\wd\KSWebShield.exe
J:\hxs.bat
J:\hyj2gunw.exe
J:\i.bat
J:\i2.com
J:\ib3qc3t.cmd
J:\if6ch9k6.bat
J:\ig.bat
J:\igcmrtjw.cmd
J:\il0byu3h.com
O:\k2.cmd
J:\il6.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\wd\kwssp.dll
J:\iluqcwr.exe
J:\imt8.cmd
J:\iok.exe
J:\ipy.cmd
J:\iscwam2h.cmd
J:\it1d.exe
J:\iu.bat
J:\iw.bat
M:\down2.bat
O:\k6wkwon2.exe
J:\iwjj.com
J:\ixsla.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\wd\kwsui.dll
J:\j.bat
J:\j0.exe
J:\j0mpdkja.cmd
J:\j1.cmd
J:\j16dp6.exe
J:\j1rxka1n.exe
J:\j83uv.exe
O:\k9cuos2q.exe
J:\jatxgwcj.bat
J:\jc1r11.exe
J:\jcmmawa.bat
%SystemDrive%\Documents and Settings\All Users\application data\weemi\weemi129.exe
J:\jdt2ofp.exe
J:\jg.com
J:\jg6w3yx.com
J:\jhcqxax.exe
J:\jix9a.bat
J:\jj2.com
O:\ka1nk.bat
J:\jkxrox.exe
J:\jl.com
J:\jvu69.bat
J:\jy.exe
%SystemDrive%\Documents and Settings\All Users\Application Data\YRUvoXXeDU.exe
J:\k.com
J:\k08aww.bat
J:\k2.cmd
J:\k6wkwon2.exe
J:\k9cuos2q.exe
O:\karina///debeja.exe
J:\ka1nk.bat
J:\karina///debeja.exe
J:\kdy.cmd
J:\kg18j.exe
J:\kgnkxc.exe
%SystemDrive%\Documents and Settings\All Users\Documents\Fun.exe
J:\kjibu.com
J:\kk.bat
J:\kk36.exe
J:\kk38g1.exe
O:\kdy.cmd
J:\kpvqk.exe
J:\kqsr.exe
J:\kuqskg2s.bat
J:\kuruna.exe
J:\kya6l.bat
J:\l1.cmd
%ProgramFiles%\AntivirusPro2009\Microsoft.VC80.CRT\msvcm80.dll
%SystemDrive%\Documents and Settings\All Users\Documents\gxcdue.exe
J:\l3v.exe
J:\l6w2eaih.exe
O:\kg18j.exe
J:\ldgybkp.bat
J:\lgcadwx.bat
J:\lgnaqil.exe
J:\lgrncie.bat
J:\lgvg8q.exe
J:\lhwdcgcb.bat
J:\lj.exe
J:\lj6hdv.com
%SystemDrive%\Documents and Settings\All Users\Documents\inugalav.sys
J:\ll.exe
O:\kgnkxc.exe
J:\lp3c.bat
J:\lsfjg.com
J:\lsg6jj9.exe
J:\lskeqbfc.exe
J:\ltc.bat
J:\lulu.exe
J:\lwd.bat
J:\lyhwcea.exe
J:\m.bat
%SystemDrive%\Documents and Settings\All Users\Documents\iwomivig.com
%temp%\tuvWqNFy.dll
J:\m.exe
J:\m6dqm2vd.exe
J:\m6n.com
J:\m8wafly.com
J:\m9as2c.cmd
J:\mayyuk9g.bat
J:\mbewb2n.exe
J:\mcmm.bat
J:\mka.bat
J:\mm6q.exe
O:\kjibu.com
%SystemDrive%\Documents and Settings\All Users\Documents\jepi.com
J:\momo.exe
J:\motr.exe
J:\mpstxgx.exe
J:\mrghykh.exe
J:\mrsne.bat
J:\msbackup.exe
J:\msn.exe
J:\mt.com
J:\mt0.cmd
O:\kk.bat
J:\mtlhieej.cmd
%SystemDrive%\Documents and Settings\All Users\Documents\kelemygij.bat
J:\n.com
J:\n.exe
J:\n1m.exe
J:\n1v93rqo.exe
J:\n6j6pc0.com
J:\n89f1d1w.exe
J:\nbke.exe
J:\ncc.exe
M:\dp.cmd
O:\kk36.exe
J:\ndmego0f.cmd
J:\net.exe
%SystemDrive%\Documents and Settings\All Users\Documents\lytavib.com
J:\ngq6hva0.exe
J:\nmje9v6d.bat
J:\nncu6kk.com
J:\nooakkv.exe
J:\np.exe
J:\nq.bat
J:\nqgcd.com
O:\kk38g1.exe
J:\nskmu.exe
J:\nsv.bat
J:\nt6ry3bn.cmd
%SystemDrive%\Documents and Settings\All Users\Documents\odosoco.sys
J:\ntdeiect.com
J:\ntdelect.com
J:\NTDETECT.EXE
J:\ntnq.exe
J:\ntphyy.com
J:\nvrfc.bat
O:\kpvqk.exe
J:\nw.exe
J:\nw0t1l0d.exe
J:\nxvhpc.exe
J:\ny36jjt.exe
%SystemDrive%\Documents and Settings\All Users\Documents\poviqaxi.com
J:\nyat.exe
J:\O.cmd
J:\o.exe
J:\o6opnro.bat
J:\o6pq1n8.com
O:\kqsr.exe
J:\o93ml8.bat
J:\o9o2.com
J:\o9o2u.bat
J:\oaljb6.exe
J:\obg.exe
%SystemDrive%\Documents and Settings\All Users\Documents\rude.bat
J:\obtpf.bat
J:\oc.cmd
J:\ocbqsqj.bat
J:\Oeboyg.exe
O:\kuqskg2s.bat
J:\okelg.exe
J:\okhr.exe
J:\ol.exe
J:\om.cmd
J:\om0.com
J:\op.bat
%SystemDrive%\Documents and Settings\All Users\Documents\ryrusipeh.dll
J:\ot.exe
J:\ot2.exe
J:\otf.cmd
O:\kuruna.exe
J:\ox.cmd
J:\p.cmd
J:\p0sc9t.cmd
J:\p1t.bat
J:\p3r1ud.exe
J:\p8ihdw.exe
J:\p9.exe
%ProgramFiles%\AntivirusPro2009\Microsoft.VC80.CRT\msvcp80.dll
%SystemDrive%\Documents and Settings\All Users\Documents\tidado.bat
J:\pamn.exe
O:\kya6l.bat
J:\patp.exe
J:\pbwkwj.COM
J:\pchkh.cmd
J:\pjben6y.exe
J:\pjwtv.cmd
J:\pkxfkrki.bat
J:\pllq.exe
J:\pnc.exe
J:\popo.exe
%SystemDrive%\Documents and Settings\All Users\Documents\vibimigid.bat
O:\l1.cmd
J:\ppinbnp9.exe
J:\prjydpe.cmd
J:\px.bat
J:\pxbn6y.exe
J:\pytnmk.exe
J:\q.bat
J:\q.exe
J:\q0rppr.exe
J:\q10js.exe
J:\q1pady.cmd
%Temp%\UAC1e1c.tmp
%SystemDrive%\Documents and Settings\All Users\Documents\ycuworud.dll
J:\q2.exe
J:\q2vl2fiy.com
J:\q83iwmgf.bat
J:\qb1.exe
J:\qh.cmd
J:\qjatw9aj.exe
J:\qjfl.exe
J:\qkarc.exe
J:\qkolx.exe
O:\l3v.exe
J:\qngbvkhl.exe
%SystemDrive%\Documents and Settings\All Users\Documents\zakiq.bat
J:\qotdyl.bat
J:\qpe6.com
J:\qr.exe
J:\qs6m.bat
J:\qsid8g.exe
J:\r.com
J:\r.exe
J:\r120.bat
M:\dp.exe
O:\l6w2eaih.exe
J:\r2mkn.exe
J:\r8wb.bat
%SystemDrive%\documents and settings\cpa.dll
J:\r9ghv9.com
J:\rcpi.exe
J:\rehsas.com
J:\resycled\boot.com
J:\rf.cmd
J:\rjiybg.exe
J:\rjx0.exe
O:\ldgybkp.bat
J:\rmydqsiw.exe
J:\rn.exe
J:\rtnlpipu.com
%SystemDrive%\Documents and Settings\cpa.exe
J:\rv36m1f9.exe
J:\rwrte.exe
J:\s2vgyp.exe
J:\s38k.exe
J:\s39tg.cmd
J:\s6.bat
O:\lgcadwx.bat
J:\s6muem.cmd
J:\s8.exe
J:\s9l.exe
J:\SafeSys.exe
%SystemDrive%\Documents and Settings\Default User\「開始」功能表\程式集\啟動\cmd.cmd
J:\sasyg1y8.com
J:\sdc.bat
J:\se11.cmd
J:\server2010.exe
J:\ServerXp.exe
O:\lgnaqil.exe
J:\sh.exe
J:\shadu.exe
J:\Shell.exe
J:\sie2v8.exe
J:\SiZhu.exe
%SystemDrive%\Documents and Settings\Default User\「開始」功能表\程式集\啟動\dflljy.exe
J:\slphfx.bat
J:\sm.exe
J:\snaoc9i.exe
J:\SofwareUpdater.exe
O:\lgrncie.bat
J:\spkr9wou.bat
J:\SRCHost.exe
J:\SRCost.exe
J:\stwi.com
J:\suqfl.exe
J:\svchost.exe
%SystemDrive%\Documents and Settings\iexplorer.exe
J:\svchovst.EXE
J:\system.dll
J:\systex.exe
O:\lgvg8q.exe
J:\t.bat
J:\t.cmd
J:\t.exe
J:\t1xdgvq.exe
J:\t2f.exe
J:\t2jl.exe
J:\t2ydo.exe
%SystemDrive%\Documents AND Settings\Local Qf\NATzyc.dll
J:\t3.com
J:\t82e2v.cmd
O:\lhwdcgcb.bat
J:\tan3yt.bat
J:\tbhje.cmd
J:\tcburi.exe
J:\temp.exe
J:\temp28.exe
J:\tfa8rk6.com
J:\tg.com
J:\tgtighg.cmd
%ProgramFiles%\AntivirusPro2009\Microsoft.VC80.CRT\msvcr80.dll
%SystemDrive%\Documents and Settings\Local User\QQpinyin.dll
O:\lj.exe
J:\thghikva.exe
J:\tigi.cmd
J:\tikett.exe
J:\tj8odymw.exe
J:\tlmjw.cmd
J:\tmd.exe
J:\tmf3w3g0.com
J:\tmf3w3go.com
J:\tn.exe
J:\tn0k.exe
O:\lj6hdv.com
%SystemDrive%\Documents and Settings\Local User\windmad.dll
J:\ts6k.exe
J:\tt.com
J:\tudqrfw.exe
J:\txfl1rhh.com
J:\tyfr.com
J:\tyvq.exe
J:\u.cmd
J:\u.exe
J:\u08.cmd
%Temp%\UAC3dd.tmp
J:\u18vxqle.com
%SystemDrive%\Documents and Settings\LocalService\Application Data\Dbg16.Sys
J:\u26ufgv.exe
J:\u2by.exe
J:\u3dsc.com
J:\u63urr.exe
J:\u6k.cmd
J:\u82.exe
J:\u99.exe
J:\ud.exe
M:\dpu1.exe
O:\ll.exe
J:\ufwi6sq.exe
J:\uh.exe
%SystemDrive%\Documents and Settings\LocalService\Application Data\Dna.sys
J:\uh31.exe
J:\uhjqlk.exe
J:\un_tc.exe
J:\uorys.cmd
J:\up.exe
J:\up0ppxwr.com
J:\update220.exe
O:\lp3c.bat
J:\update2201.exe
J:\updater697.exe
J:\UpdateThis.exe
%SystemDrive%\Documents and Settings\LocalService\Application Data\lizkavd.exe
J:\UpdateWindows.exe
J:\updds3.exe
J:\ups.exe
J:\Ups3.exe
J:\upsf.exe
J:\uptes.exe
O:\lsfjg.com
J:\upts3.exe
J:\uptsd.exe
J:\Upz.exe
J:\uqb0julr.bat
%SystemDrive%\Documents and Settings\LocalService\Application Data\Microsoft\defy.exe
J:\us8amqf.exe
J:\ut.bat
J:\ut9x.bat
J:\utcn8c63.exe
J:\uuhgt.bat
O:\lsg6jj9.exe
J:\uwlmj.com
J:\uxkktr.cmd
J:\uyfd9cck.cmd
J:\v0f8rqc.cmd
J:\v0vj.exe
%SystemDrive%\documents and settings\Update.exe
J:\v2h3.exe
J:\v3pif.bat
J:\v86htgx.cmd
J:\v9l1l.com
O:\lskeqbfc.exe
J:\v9l8.exe
J:\v9ug2p2.com
J:\vcf0.exe
J:\vctio.com
J:\vd91t29.exe
J:\vdej3e.exe
%SystemDrive%\Downloads\BFSDRV.sys
J:\vkrg.exe
J:\vmhr.bat
J:\vnkucvv.com
O:\ltc.bat
J:\vp.exe
J:\vpqdgkx.com
J:\vt6e.cmd
J:\w.bat
J:\w.cmd
J:\w.exe
J:\w2qagd.com
%SystemDrive%\downloads\dl_205490.exe
J:\w3dn9f.bat
J:\w6hikrv.com
O:\lulu.exe
J:\w9fc.exe
J:\wdm.exe
J:\Webhost2.exe
J:\webhost4.exe
J:\Weeiivruved.exe
J:\weg6sp.com
J:\wehds63.exe
J:\wewt425.exe
%SystemDrive%\downloads\er.exe
J:\wewtf.exe
O:\lwd.bat
J:\wex.exe
J:\wg0kpd.bat
J:\wg6jj0.exe
J:\wglplm6g.bat
J:\wgp.com
J:\Windows.exe
J:\winhost.exe
J:\winser.exe
J:\wjlc.exe
%ProgramFiles%\antiviruspro2009\pthreadVC2.dll
O:\lyhwcea.exe
%SystemDrive%\downloads\ngokwl0px1y6t.exe
J:\wkcay8u.cmd
J:\wpkx.bat
J:\wstk.exe
J:\wuwu.exe
J:\wv.exe
J:\wycgb8.cmd
J:\wyqrvts.exe
J:\wyzlo.exe
J:\x.bat
O:\m.bat
J:\x.cmd
%SystemDrive%\downloads\ozyace8q0vq.exe
J:\x1.cmd
J:\x1dg.exe
J:\x1o8uo.exe
J:\x63rnneh.exe
J:\xa8v8.exe
J:\xadeiect.com
J:\xc.exe
J:\xe9fdii1.cmd
M:\dqi.exe
%Temp%\ucyc.dll
J:\xedex.exe
J:\xene9.bat
%SystemDrive%\e4e5db6004258cf9.dat
J:\xievhrf.exe
J:\xjs.exe
J:\xjv.exe
J:\xnfrqlvf.exe
J:\xppg3r6.exe
J:\xpq63xl.exe
J:\xqg0.exe
O:\m.exe
J:\xqyl68.exe
J:\xue.exe
J:\xv.com
%SystemDrive%\error.exe
J:\xwpehlv.com
J:\xyh.exe
J:\y.com
J:\y319s.exe
J:\y6u.bat
J:\y9rlqi.cmd
O:\m6dqm2vd.exe
J:\ydmj.exe
J:\yfmqo.cmd
J:\yfpaoty.exe
J:\ygvtn.exe
%SystemDrive%\f6f429501b983062.dat
J:\yh.bat
J:\yi9.exe
J:\yjkjfuo.cmd
J:\ymxf3q.exe
J:\yp.bat
O:\m6n.com
J:\ypjq1.cmd
J:\yq.com
J:\yq00tht.exe
J:\yt8a.exe
J:\yv.exe
%SystemDrive%\fmsr.bak
J:\yw6mmv0.exe
J:\zx.exe
K:\3.exe
K:\300y.cmd
O:\m8wafly.com
K:\30c0e.cmd
K:\30ed3.exe
K:\31n3b2h.exe
K:\32o3.cmd
K:\35e.exe
K:\38s3i.exe
%SystemDrive%\fsrs.bak
K:\39ysi89.com
K:\3bo9tn.cmd
K:\3ce.exe
O:\m9as2c.cmd
K:\3dohrt.com
K:\3ds.cmd
K:\3ehxs6.cmd
K:\3g3.exe
K:\3hihyi.exe
K:\3iugonx.com
K:\3jkka91.com
%SystemDrive%\gckb.bak
K:\3jkkdo.exe
K:\3o0fp.exe
O:\mayyuk9g.bat
K:\3p9wj19.exe
K:\3r33c.CMD
K:\3vf9968r.exe
K:\3wmvmd.cmd
K:\3wy1vm.cmd
K:\3y.bat
K:\3yr1.cmd
K:\535.exe
%SystemDrive%\gdjj.bak
K:\6.bat
O:\mbewb2n.exe
K:\6.exe
K:\62oop0ak.bat
K:\63e.exe
K:\6hg.exe
K:\6j2j.com
K:\6o0.bat
K:\6phx.com
K:\6qe.com
K:\6r3p.com
%SystemDrive%\gnbk.bak
O:\mcmm.bat
K:\6rq6.exe
K:\6vu680.com
K:\6wqhah.exe
K:\6xdgw26.com
K:\806.com
K:\82.exe
K:\82i.cmd
K:\82tgk9eg.exe
K:\8386nac.com
K:\8a.exe
O:\mka.bat
%ProgramFiles%\Applications\FreeApp.exe
%SystemDrive%\gvcm.bak
K:\8ae2q.exe
K:\8b3.bat
K:\8df.EXE
K:\8e.com
K:\8gidy.exe
K:\8h3hh3m.exe
K:\8iyqbsp1.exe
K:\8m08ty.com
M:\ds.exe
O:\mm6q.exe
K:\8mt8bm.exe
K:\8nlo1q.cmd
%SystemDrive%\hlgr.bak
K:\8ot8y86.exe
K:\8oupido.bat
K:\8ox61l6.cmd
K:\8q6h.exe
K:\8tss2gwq.bat
K:\8u.com
K:\8uot.exe
%ProgramFiles%\Common Files\1696752819875.exe
K:\8xlwbngd.exe
K:\90imhpnc.exe
K:\91.exe
%SystemDrive%\huadio.tmp
K:\91m.COM
K:\92j11sm.com
K:\96.com
K:\9b8kmipy.com
K:\9bid6bl.exe
K:\9dl.cmd
%Temp%\UIUCU.EXE
K:\9es.com
K:\9l66g8k1.com
K:\9o.exe
K:\9r8hh2f.exe
%SystemDrive%\ifep.bak
K:\9tb8ist.bat
K:\9yp8nyvg.exe
K:\a.bat
K:\a.exe
K:\a2r.exe
O:\momo.exe
K:\a8qengab.exe
K:\ab.cmd
K:\abqk2c3i.bat
K:\adba2.exe
K:\af93gcf.exe
%SystemDrive%\jj2.com.suspicious
K:\af9rgm8h.bat
K:\alt.exe
K:\aluj8r.exe
K:\anky8.exe
O:\motr.exe
K:\aoutfq.exe
K:\ap.com
K:\atymi09.bat
K:\auto.exe
K:\auto.pif
K:\autorun.exe
%SystemDrive%\kbtq.bak
K:\autorun.inf
K:\autorunx.exe
K:\autox.exe
O:\mpstxgx.exe
K:\avmb.exe
K:\ay8p6v3.cmd
K:\b.bat
K:\b.cmd
K:\b.exe
K:\Backup.exe
K:\baksql.bat
%SystemDrive%\khga.bak
K:\Beanfun.exe
K:\bn0.bat
O:\mrghykh.exe
K:\BNB_029.exe
K:\bnkxy.exe
K:\bnmv.exe
K:\bplrl98.cmd
K:\bpvwvays.exe
K:\bpx9q3j.exe
K:\bqk.bat
K:\bs3ol8kd2.exe
%SystemDrive%\kire.pif
K:\bsp.cmd
O:\mrsne.bat
K:\bt8vuaw.com
K:\bunip.bat
K:\bxuup9r.bat
K:\c.bat
K:\c.exe
K:\cbpd.exe
K:\ccc.exe
K:\CD8IDOYL.COM
K:\ceqfqp.bat
%SystemDrive%\kurund.exe
O:\msbackup.exe
K:\cfv90h.com
K:\check.exe
K:\chlf9.exe
K:\cjrp8.com
K:\clc1al.com
K:\clc3k.com
K:\clxam6r6.exe
K:\cm0.com
K:\cmon.exe
K:\cn.exe
O:\msn.exe
%SystemDrive%\KYOGTS.SYS
K:\co.com
K:\copetttt.com
K:\copy.exe
K:\cp13cg.exe
K:\cubp.bat
K:\d.bat
K:\d.exe
K:\d218eht.exe
K:\d22xl.bat
M:\3ehxs6.cmd
M:\dsty.com
O:\mt.com
K:\d3bn0j.exe
%ProgramFiles%\Applications\iebr.dll
%SystemDrive%\KYOGTSD.SYS
K:\d6r6jmp.exe
K:\d8ur3qs.bat
K:\dagd.exe
K:\dblnq.exe
K:\ddyikr.CMD
K:\delshare.bat
K:\dgf.exe
O:\mt0.cmd
K:\dgkx.exe
K:\dh66ln.cmd
K:\dhcore.exe
%SystemDrive%\lass.exe
K:\di3su.exe
K:\diox3j.com
K:\dmf.exe
K:\down.exe
K:\down2.bat
K:\dp.cmd
O:\mtlhieej.cmd
K:\dp.exe
K:\dpu1.exe
K:\dqi.exe
K:\ds.exe
%SystemDrive%\lsass.exe
K:\dsty.com
K:\dv6pp.exe
K:\dvhyi.exe
K:\dxv.bat
K:\dynrn6e.cmd
%Temp%\unz5A.tmp
K:\dyr2j6mv.exe
K:\e.cmd
K:\e.exe
K:\e00233it.com
K:\e0t9n6.exe
%SystemDrive%\md.dll
K:\e6.com
K:\e619e.cmd
K:\E6IEG.EXE
K:\e898.com
O:\n.com
K:\eadf6s.exe
K:\eb9ehyh.exe
K:\ecn.com
K:\eeqt.exe
K:\eftwl.exe
K:\eg1.cmd
%SystemDrive%\micss.pif
K:\eito.exe
K:\ejoq.exe
K:\ek.com
O:\n.exe
K:\ell.exe
K:\erdeIect.com
K:\erjhni.exe
K:\ermvu8.cmd
K:\et.exe
K:\ewatr.cmd
K:\f.bat
%SystemDrive%\mmwm.bak
K:\f.exe
K:\ff1q0gw.bat
O:\n1m.exe
K:\fgj3lc8.exe
K:\find.exe
K:\fipgnfww.cmd
K:\fjb2.exe
K:\fp.exe
K:\fphj6j31.bat
K:\fsdg.exe
K:\ft8.exe
%SystemDrive%\mon.exe
K:\ftiduico.bat
O:\n1v93rqo.exe
K:\fufb6tq3.cmd
K:\fvan.exe
K:\fvbk.exe
K:\g.exe
K:\g0.cmd
K:\g2p3s.exe
K:\g8rruyw.exe
K:\g9rv.exe
K:\gaagw.bat
%SystemDrive%\negr.bak
O:\n6j6pc0.com
K:\gabptk6d.bat
K:\gclwpivc.cmd
K:\gdsag.exe
K:\ggkxgvf.bat
K:\ggl.cmd
K:\ggqn.exe
K:\ghdf1.com
K:\gicchk2s.exe
K:\gmi1jxy.com
K:\gnc.bat
O:\n89f1d1w.exe
%SystemDrive%\Notepad.exe
K:\gnwav.exe
K:\gnwwy.exe
K:\gplpn.exe
K:\gqsk.bat
K:\gswrij.exe
K:\gsxlexd.cmd
K:\gx.bat
K:\gx.com
K:\gxul.com
M:\dv6pp.exe
O:\nbke.exe
K:\gymussy.bat
%SystemDrive%\nrgj.bak
K:\h.bat
K:\h.CMD
K:\h0j8w.exe
K:\h0ti1de.bat
K:\h2.com
K:\h2t6u.exe
K:\h3hi1k3.exe
K:\h8i.com
O:\ncc.exe
K:\hfap.exe
K:\higj2p.bat
%ProgramFiles%\Applications\iebt.dll
%SystemDrive%\ohid.bak
K:\hn.cmd
K:\hnkvaa2.exe
K:\home.exe
K:\host.exe
K:\hovrflst.bat
K:\hpkq.cmd
O:\ndmego0f.cmd
K:\hqx292nu.exe
K:\hsi.com
K:\hsjnkj.exe
K:\htjtq8o.exe
%SystemDrive%\oosoldls.exe
K:\hupxj.bat
K:\hv8fv2.exe
K:\hvoxmq.exe
K:\hxbpamjb.cmd
K:\hxs.bat
O:\net.exe
K:\hyj2gunw.exe
K:\i.bat
K:\i2.com
K:\ib3qc3t.cmd
K:\if6ch9k6.bat
%SystemDrive%\ouildls.exe
K:\ig.bat
K:\igcmrtjw.cmd
K:\il0byu3h.com
K:\il6.exe
%Temp%\unz5A.tmp\FramePkg.exe
K:\iluqcwr.exe
K:\imt8.cmd
K:\iok.exe
K:\ipy.cmd
K:\iscwam2h.cmd
K:\it1d.exe
%SystemDrive%\ownd.bak
K:\iu.bat
K:\iw.bat
K:\iwjj.com
O:\ngq6hva0.exe
K:\ixsla.exe
K:\j.bat
K:\j0.exe
K:\j0mpdkja.cmd
K:\j1.cmd
K:\j16dp6.exe
K:\j1rxka1n.exe
%SystemDrive%\pfle.bak
K:\j83uv.exe
K:\jatxgwcj.bat
O:\nmje9v6d.bat
K:\jc1r11.exe
K:\jcmmawa.bat
K:\jdt2ofp.exe
K:\jg.com
K:\jg6w3yx.com
K:\jhcqxax.exe
K:\jix9a.bat
K:\jj2.com
%SystemDrive%\ppso.bak
K:\jkxrox.exe
O:\nncu6kk.com
K:\jl.com
K:\jvu69.bat
K:\jy.exe
K:\k.com
K:\k08aww.bat
K:\k2.cmd
K:\k6wkwon2.exe
K:\k9cuos2q.exe
K:\ka1nk.bat
%SystemDrive%\progra~1\micros~1.net\lvbyad.dll
O:\nooakkv.exe
K:\karina///debeja.exe
K:\kdy.cmd
K:\kg18j.exe
K:\kgnkxc.exe
K:\kjibu.com
K:\kk.bat
K:\kk36.exe
K:\kk38g1.exe
K:\kpvqk.exe
K:\kqsr.exe
O:\np.exe
%SystemDrive%\ProgramData\hezos\betoas\velevs.dll
K:\kuqskg2s.bat
K:\kuruna.exe
K:\kya6l.bat
K:\l1.cmd
K:\l3v.exe
K:\l6w2eaih.exe
K:\ldgybkp.bat
K:\lgcadwx.bat
K:\lgnaqil.exe
%Temp%\a1.exe
O:\nq.bat
K:\lgrncie.bat
%SystemDrive%\ProgramData\hezos\betoas\vevfs.dll
K:\lgvg8q.exe
K:\lhwdcgcb.bat
K:\lj.exe
K:\lj6hdv.com
K:\ll.exe
K:\lp3c.bat
K:\lsfjg.com
K:\lsg6jj9.exe
O:\nqgcd.com
K:\lskeqbfc.exe
K:\ltc.bat
%SystemDrive%\ProgramData\hezos\lisvus.exe
K:\lulu.exe
K:\lwd.bat
K:\lyhwcea.exe
K:\m.bat
K:\m.exe
K:\m6dqm2vd.exe
K:\m6n.com
O:\nskmu.exe
K:\m8wafly.com
K:\m9as2c.cmd
K:\mayyuk9g.bat
%ProgramFile%\Common Files\uiui8.dll
%ProgramFiles%\Applications\iebtm.exe
%SystemDrive%\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\system.ink
K:\mbewb2n.exe
K:\mcmm.bat
K:\mka.bat
K:\mm6q.exe
O:\nsv.bat
K:\momo.exe
K:\motr.exe
K:\mpstxgx.exe
K:\mrghykh.exe
K:\mrsne.bat
K:\msbackup.exe
%SystemDrive%\qshb.dll
K:\msn.exe
K:\mt.com
K:\mt0.cmd
O:\nt6ry3bn.cmd
K:\mtlhieej.cmd
K:\n.com
K:\n.exe
K:\n1m.exe
K:\n1v93rqo.exe
K:\n6j6pc0.com
K:\n89f1d1w.exe
%SystemDrive%\rcdr.bak
K:\nbke.exe
K:\ncc.exe
%Temp%\ur.dll
K:\ndmego0f.cmd
K:\net.exe
K:\ngq6hva0.exe
K:\nmje9v6d.bat
K:\nncu6kk.com
K:\nooakkv.exe
K:\np.exe
K:\nq.bat
%SystemDrive%\Recycled\Dc38.dll
K:\nqgcd.com
O:\ntdeiect.com
K:\nskmu.exe
K:\nsv.bat
K:\nt6ry3bn.cmd
K:\ntdeiect.com
K:\ntdelect.com
K:\NTDETECT.EXE
K:\ntnq.exe
K:\ntphyy.com
K:\nvrfc.bat
%SystemDrive%\RECYCLER\NPROTECT\00754595.exe
O:\ntdelect.com
K:\nw.exe
K:\nw0t1l0d.exe
K:\nxvhpc.exe
K:\ny36jjt.exe
K:\nyat.exe
K:\O.cmd
K:\o.exe
K:\o6opnro.bat
K:\o6pq1n8.com
K:\o93ml8.bat
O:\NTDETECT.EXE
%SystemDrive%\RECYCLER\prosafe.sys
K:\o9o2.com
K:\o9o2u.bat
K:\oaljb6.exe
K:\obg.exe
K:\obtpf.bat
K:\oc.cmd
K:\ocbqsqj.bat
K:\Oeboyg.exe
K:\okelg.exe
O:\ntnq.exe
K:\okhr.exe
%SystemDrive%\RECYCLER\regsafe.sys
K:\ol.exe
K:\om.cmd
K:\om0.com
K:\op.bat
K:\ot.exe
K:\ot2.exe
K:\otf.cmd
K:\ox.cmd
M:\dvhyi.exe
O:\ntphyy.com
K:\p.cmd
K:\p0sc9t.cmd
%SystemDrive%\RECYCLER\S-1-5-21-0741592583-3169784988-554878328-2857\nissan.exe
K:\p1t.bat
K:\p3r1ud.exe
K:\p8ihdw.exe
K:\p9.exe
K:\pamn.exe
K:\patp.exe
K:\pbwkwj.COM
O:\nvrfc.bat
K:\pchkh.cmd
K:\pjben6y.exe
K:\pjwtv.cmd
%SystemDrive%\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\winse32.exe
K:\pkxfkrki.bat
K:\pllq.exe
K:\pnc.exe
K:\popo.exe
K:\ppinbnp9.exe
K:\prjydpe.cmd
O:\nw.exe
K:\px.bat
K:\pxbn6y.exe
K:\pytnmk.exe
K:\q.bat
%SystemDrive%\RECYCLER\svclost.exe
K:\q.exe
K:\q0rppr.exe
K:\q10js.exe
K:\q1pady.cmd
K:\q2.exe
O:\nw0t1l0d.exe
K:\q2vl2fiy.com
K:\q83iwmgf.bat
K:\qb1.exe
K:\qh.cmd
K:\qjatw9aj.exe
%ProgramFiles%\Applications\iebtmm.exe
%SystemDrive%\rjcx.bak
K:\qjfl.exe
K:\qkarc.exe
K:\qkolx.exe
O:\nxvhpc.exe
K:\qngbvkhl.exe
K:\qotdyl.bat
K:\qpe6.com
K:\qr.exe
K:\qs6m.bat
K:\qsid8g.exe
K:\r.com
%SystemDrive%\sigq.bak
K:\r.exe
K:\r120.bat
O:\ny36jjt.exe
K:\r2mkn.exe
K:\r8wb.bat
K:\r9ghv9.com
K:\rcpi.exe
K:\rehsas.com
K:\resycled\boot.com
K:\rf.cmd
K:\rjiybg.exe
%SystemDrive%\slkn.bak
K:\rjx0.exe
%Temp%\uret463.exe
K:\rmydqsiw.exe
K:\rn.exe
K:\rtnlpipu.com
K:\rv36m1f9.exe
K:\rwrte.exe
K:\s2vgyp.exe
K:\s38k.exe
K:\s39tg.cmd
K:\s6.bat
%SystemDrive%\sysdll.dll
O:\nyat.exe
K:\s6muem.cmd
K:\s8.exe
K:\s9l.exe
K:\SafeSys.exe
K:\sasyg1y8.com
K:\sdc.bat
K:\se11.cmd
K:\server2010.exe
K:\ServerXp.exe
K:\sh.exe
O:\O.cmd
%SystemDrive%\sysinit.dat
K:\shadu.exe
K:\Shell.exe
K:\sie2v8.exe
K:\SiZhu.exe
K:\slphfx.bat
K:\sm.exe
K:\snaoc9i.exe
K:\SofwareUpdater.exe
K:\spkr9wou.bat
O:\o.exe
K:\SRCHost.exe
%SystemDrive%\system.dll
K:\SRCost.exe
K:\stwi.com
K:\suqfl.exe
K:\svchost.exe
K:\svchovst.EXE
K:\system.dll
K:\systex.exe
K:\t.bat
M:\dxv.bat
O:\o6opnro.bat
K:\t.cmd
K:\t.exe
%SystemDrive%\Temp\Server.exe
K:\t1xdgvq.exe
K:\t2f.exe
K:\t2jl.exe
K:\t2ydo.exe
K:\t3.com
K:\t82e2v.cmd
K:\tan3yt.bat
O:\o6pq1n8.com
K:\tbhje.cmd
K:\tcburi.exe
K:\temp.exe
%SystemDrive%\tempjunk1531.tmp
K:\temp28.exe
K:\tfa8rk6.com
K:\tg.com
K:\tgtighg.cmd
K:\thghikva.exe
K:\tigi.cmd
O:\o93ml8.bat
K:\tikett.exe
K:\tj8odymw.exe
K:\tlmjw.cmd
K:\tmd.exe
%SystemDrive%\tempjunk2330.tmp
K:\tmf3w3g0.com
K:\tmf3w3go.com
K:\tn.exe
K:\tn0k.exe
K:\ts6k.exe
O:\o9o2.com
K:\tt.com
K:\tudqrfw.exe
K:\txfl1rhh.com
K:\tyfr.com
K:\tyvq.exe
%SystemDrive%\tempjunk3342.tmp
K:\u.cmd
K:\u.exe
K:\u08.cmd
K:\u18vxqle.com
O:\o9o2u.bat
K:\u26ufgv.exe
K:\u2by.exe
K:\u3dsc.com
K:\u63urr.exe
K:\u6k.cmd
K:\u82.exe
%ProgramFiles%\Applications\iebtu.exe
%SystemDrive%\tempjunk7200.tmp
K:\u99.exe
K:\ud.exe
O:\oaljb6.exe
K:\ufwi6sq.exe
K:\uh.exe
K:\uh31.exe
K:\uhjqlk.exe
K:\un_tc.exe
K:\uorys.cmd
K:\up.exe
K:\up0ppxwr.com
%SystemDrive%\tmoglti.dll
K:\update220.exe
O:\obg.exe
K:\update2201.exe
K:\updater697.exe
K:\UpdateThis.exe
K:\UpdateWindows.exe
K:\updds3.exe
K:\ups.exe
K:\Ups3.exe
K:\upsf.exe
K:\uptes.exe
%SystemDrive%\txqg.bak
%temp%\vmnat.exe
K:\upts3.exe
K:\uptsd.exe
K:\Upz.exe
K:\uqb0julr.bat
K:\us8amqf.exe
K:\ut.bat
K:\ut9x.bat
K:\utcn8c63.exe
K:\uuhgt.bat
K:\uwlmj.com
O:\obtpf.bat
%SystemDrive%\Users\Administrator\AppData\Roaming\drivers\111wfs1intwq.sys
K:\uxkktr.cmd
K:\uyfd9cck.cmd
K:\v0f8rqc.cmd
K:\v0vj.exe
K:\v2h3.exe
K:\v3pif.bat
K:\v86htgx.cmd
K:\v9l1l.com
K:\v9l8.exe
O:\oc.cmd
K:\v9ug2p2.com
%SystemDrive%\Users\Administrator\AppData\Roaming\drivers\11s11ro1s1a2.sys
K:\vcf0.exe
K:\vctio.com
K:\vd91t29.exe
K:\vdej3e.exe
K:\vkrg.exe
K:\vmhr.bat
K:\vnkucvv.com
K:\vp.exe
M:\dynrn6e.cmd
O:\ocbqsqj.bat
K:\vpqdgkx.com
K:\vt6e.cmd
%SystemDrive%\vdkb.bak
K:\w.bat
K:\w.cmd
K:\w.exe
K:\w2qagd.com
K:\w3dn9f.bat
K:\w6hikrv.com
K:\w9fc.exe
O:\Oeboyg.exe
K:\wdm.exe
K:\Webhost2.exe
K:\webhost4.exe
%SystemDrive%\vgai.bak
K:\Weeiivruved.exe
K:\weg6sp.com
K:\wehds63.exe
K:\wewt425.exe
K:\wewtf.exe
K:\wex.exe
O:\okelg.exe
K:\wg0kpd.bat
K:\wg6jj0.exe
K:\wglplm6g.bat
K:\wgp.com
%SystemDrive%\vywe.bak
K:\Windows.exe
K:\winhost.exe
K:\winser.exe
K:\wjlc.exe
K:\wkcay8u.cmd
O:\okhr.exe
K:\wpkx.bat
K:\wstk.exe
K:\wuwu.exe
K:\wv.exe
K:\wycgb8.cmd
%SystemDrive%\windows.exe
K:\wyqrvts.exe
K:\wyzlo.exe
K:\x.bat
K:\x.cmd
O:\ol.exe
K:\x1.cmd
K:\x1dg.exe
K:\x1o8uo.exe
K:\x63rnneh.exe
K:\xa8v8.exe
K:\xadeiect.com
%SystemDrive%\windows32\lj.exe
K:\xc.exe
K:\xe9fdii1.cmd
K:\xedex.exe
O:\om.cmd
K:\xene9.bat
K:\xievhrf.exe
K:\xjs.exe
K:\xjv.exe
K:\xnfrqlvf.exe
K:\xppg3r6.exe
K:\xpq63xl.exe
%ProgramFiles%\Applications\iebu.exe
%SystemDrive%\windows32\xmloder.exe
K:\xqg0.exe
O:\om0.com
K:\xqyl68.exe
K:\xue.exe
K:\xv.com
K:\xwpehlv.com
K:\xyh.exe
K:\y.com
K:\y319s.exe
K:\y6u.bat
K:\y9rlqi.cmd
%SystemDrive%\WindowsMediaUpdate.exe
O:\op.bat
K:\ydmj.exe
K:\yfmqo.cmd
K:\yfpaoty.exe
K:\ygvtn.exe
K:\yh.bat
K:\yi9.exe
K:\yjkjfuo.cmd
K:\ymxf3q.exe
K:\yp.bat
K:\ypjq1.cmd
%Temp%\w8m.dll
%SystemDrive%\winser.exe
K:\yq.com
K:\yq00tht.exe
K:\yt8a.exe
K:\yv.exe
K:\yw6mmv0.exe
K:\zx.exe
L:\3.exe
L:\300y.cmd
L:\30c0e.cmd
O:\ot.exe
L:\30ed3.exe
%SystemDrive%\xfgg.bak
L:\31n3b2h.exe
L:\32o3.cmd
L:\35e.exe
L:\38s3i.exe
L:\39ysi89.com
L:\3bo9tn.cmd
L:\3ce.exe
L:\3dohrt.com
M:\dyr2j6mv.exe
O:\ot2.exe
L:\3ds.cmd
L:\3ehxs6.cmd
%SystemDrive%\ybhn.bak
L:\3g3.exe
L:\3hihyi.exe
L:\3iugonx.com
L:\3jkka91.com
L:\3jkkdo.exe
L:\3o0fp.exe
L:\3p9wj19.exe
O:\otf.cmd
L:\3r33c.CMD
L:\3vf9968r.exe
L:\3wmvmd.cmd
%SystemDrive%\yhrx.bak
L:\3wy1vm.cmd
L:\3y.bat
L:\3yr1.cmd
L:\535.exe
L:\6.bat
L:\6.exe
O:\ox.cmd
L:\62oop0ak.bat
L:\63e.exe
L:\6hg.exe
L:\6j2j.com
%SystemDrive%\yrjl.bak
L:\6o0.bat
L:\6phx.com
L:\6qe.com
L:\6r3p.com
L:\6rq6.exe
O:\p.cmd
L:\6vu680.com
L:\6wqhah.exe
L:\6xdgw26.com
L:\806.com
L:\82.exe
%SystemDrive%\yxec.bak
L:\82i.cmd
L:\82tgk9eg.exe
L:\8386nac.com
L:\8a.exe
O:\p0sc9t.cmd
L:\8ae2q.exe
L:\8b3.bat
L:\8df.EXE
L:\8e.com
L:\8gidy.exe
L:\8h3hh3m.exe
%SystemDrive%\z1.tmp
L:\8iyqbsp1.exe
L:\8m08ty.com
L:\8mt8bm.exe
O:\p1t.bat
L:\8nlo1q.cmd
L:\8ot8y86.exe
L:\8oupido.bat
L:\8ox61l6.cmd
L:\8q6h.exe
L:\8tss2gwq.bat
L:\8u.com
%SystemDrive%\z8g5q3d3n2s9.exe
L:\8uot.exe
L:\8xlwbngd.exe
O:\p3r1ud.exe
L:\90imhpnc.exe
L:\91.exe
L:\91m.COM
L:\92j11sm.com
L:\96.com
L:\9b8kmipy.com
L:\9bid6bl.exe
L:\9dl.cmd
%ProgramFiles%\Applications\wcs.exe
%Temp%\_is1.exe
O:\p8ihdw.exe
L:\9es.com
L:\9l66g8k1.com
L:\9o.exe
L:\9r8hh2f.exe
L:\9tb8ist.bat
L:\9yp8nyvg.exe
L:\a.bat
L:\a.exe
L:\a2r.exe
L:\a8qengab.exe
O:\p9.exe
%Temp%\_is2.exe
L:\ab.cmd
L:\abqk2c3i.bat
L:\adba2.exe
L:\af93gcf.exe
L:\af9rgm8h.bat
L:\alt.exe
L:\aluj8r.exe
L:\anky8.exe
L:\aoutfq.exe
%Temp%\wauclt.exe
L:\ap.com
%Temp%\_is31.exe
L:\atymi09.bat
L:\auto.exe
L:\auto.pif
L:\autorun.exe
L:\autorun.inf
L:\autorunx.exe
L:\autox.exe
L:\avmb.exe
M:\e.cmd
O:\pamn.exe
L:\ay8p6v3.cmd
L:\b.bat
%Temp%\_is32.exe
L:\b.cmd
L:\b.exe
L:\Backup.exe
L:\baksql.bat
L:\Beanfun.exe
L:\bn0.bat
L:\BNB_029.exe
O:\patp.exe
L:\bnkxy.exe
L:\bnmv.exe
L:\bplrl98.cmd
%Temp%\_is33.exe
L:\bpvwvays.exe
L:\bpx9q3j.exe
L:\bqk.bat
L:\bs3ol8kd2.exe
L:\bsp.cmd
L:\bt8vuaw.com
O:\pbwkwj.COM
L:\bunip.bat
L:\bxuup9r.bat
L:\c.bat
L:\c.exe
%Temp%\_is34.exe
L:\cbpd.exe
L:\ccc.exe
L:\CD8IDOYL.COM
L:\ceqfqp.bat
L:\cfv90h.com
O:\pchkh.cmd
L:\check.exe
L:\chlf9.exe
L:\cjrp8.com
L:\clc1al.com
L:\clc3k.com
%Temp%\_is4D.exe
L:\clxam6r6.exe
L:\cm0.com
L:\cmon.exe
L:\cn.exe
O:\pjben6y.exe
L:\co.com
L:\copetttt.com
L:\copy.exe
L:\cp13cg.exe
L:\cubp.bat
L:\d.bat
%Temp%\_is86.exe
L:\d.exe
L:\d218eht.exe
L:\d22xl.bat
O:\pjwtv.cmd
L:\d3bn0j.exe
L:\d6r6jmp.exe
L:\d8ur3qs.bat
L:\dagd.exe
L:\dblnq.exe
L:\ddyikr.CMD
L:\delshare.bat
%Temp%\_is87.exe
L:\dgf.exe
L:\dgkx.exe
O:\pkxfkrki.bat
L:\dh66ln.cmd
L:\dhcore.exe
L:\di3su.exe
L:\diox3j.com
L:\dmf.exe
L:\down.exe
L:\down2.bat
L:\dp.cmd
%Temp%\_is88.exe
L:\dp.exe
O:\pllq.exe
L:\dpu1.exe
L:\dqi.exe
L:\ds.exe
L:\dsty.com
L:\dv6pp.exe
L:\dvhyi.exe
L:\dxv.bat
L:\dynrn6e.cmd
L:\dyr2j6mv.exe
%ProgramFiles%\Applications\wcu.exe
O:\pnc.exe
%Temp%\_is8D.exe
L:\e.cmd
L:\e.exe
L:\e00233it.com
L:\e0t9n6.exe
L:\e6.com
L:\e619e.cmd
L:\E6IEG.EXE
L:\e898.com
L:\eadf6s.exe
O:\popo.exe
L:\eb9ehyh.exe
%Temp%\_is92.exe
L:\ecn.com
L:\eeqt.exe
L:\eftwl.exe
L:\eg1.cmd
L:\eito.exe
L:\ejoq.exe
L:\ek.com
L:\ell.exe
M:\e.exe
%Temp%\wdso.exe
L:\erdeIect.com
L:\erjhni.exe
%Temp%\_isAD.exe
L:\ermvu8.cmd
L:\et.exe
L:\ewatr.cmd
L:\f.bat
L:\f.exe
L:\ff1q0gw.bat
L:\fgj3lc8.exe
O:\ppinbnp9.exe
L:\find.exe
L:\fipgnfww.cmd
L:\fjb2.exe
%Temp%\_isAE.exe
L:\fp.exe
L:\fphj6j31.bat
L:\fsdg.exe
L:\ft8.exe
L:\ftiduico.bat
L:\fufb6tq3.cmd
O:\prjydpe.cmd
L:\fvan.exe
L:\fvbk.exe
L:\g.exe
L:\g0.cmd
%Temp%\_isEF.exe
L:\g2p3s.exe
L:\g8rruyw.exe
L:\g9rv.exe
L:\gaagw.bat
L:\gabptk6d.bat
O:\px.bat
L:\gclwpivc.cmd
L:\gdsag.exe
L:\ggkxgvf.bat
L:\ggl.cmd
L:\ggqn.exe
%Temp%\_mei832\_hashlib.pyd
L:\ghdf1.com
L:\gicchk2s.exe
L:\gmi1jxy.com
L:\gnc.bat
O:\pxbn6y.exe
L:\gnwav.exe
L:\gnwwy.exe
L:\gplpn.exe
L:\gqsk.bat
L:\gswrij.exe
L:\gsxlexd.cmd
%Temp%\_mei832\_socket.pyd
L:\gx.bat
L:\gx.com
L:\gxul.com
O:\pytnmk.exe
L:\gymussy.bat
L:\h.bat
L:\h.CMD
L:\h0j8w.exe
L:\h0ti1de.bat
L:\h2.com
L:\h2t6u.exe
%Temp%\_mei832\_ssl.pyd
L:\h3hi1k3.exe
L:\h8i.com
O:\q.bat
L:\hfap.exe
L:\higj2p.bat
L:\hn.cmd
L:\hnkvaa2.exe
L:\home.exe
L:\host.exe
L:\hovrflst.bat
L:\hpkq.cmd
%Temp%\_mei832\wx._controls_.pyd
L:\hqx292nu.exe
O:\q.exe
L:\hsi.com
L:\hsjnkj.exe
L:\htjtq8o.exe
L:\hupxj.bat
L:\hv8fv2.exe
L:\hvoxmq.exe
L:\hxbpamjb.cmd
L:\hxs.bat
L:\hyj2gunw.exe
%Temp%\_mei832\wx._core_.pyd
O:\q0rppr.exe
L:\i.bat
L:\i2.com
L:\ib3qc3t.cmd
L:\if6ch9k6.bat
L:\ig.bat
L:\igcmrtjw.cmd
L:\il0byu3h.com
L:\il6.exe
L:\iluqcwr.exe
L:\imt8.cmd
O:\q10js.exe
%ProgramFiles%\aurn.inf
%Temp%\_mei832\wx._gdi_.pyd
L:\iok.exe
L:\ipy.cmd
L:\iscwam2h.cmd
L:\it1d.exe
L:\iu.bat
L:\iw.bat
L:\iwjj.com
L:\ixsla.exe
M:\e00233it.com
O:\q1pady.cmd
L:\j.bat
L:\j0.exe
%Temp%\_mei832\wx._misc_.pyd
L:\j0mpdkja.cmd
L:\j1.cmd
L:\j16dp6.exe
L:\j1rxka1n.exe
L:\j83uv.exe
L:\jatxgwcj.bat
L:\jc1r11.exe
%Temp%\wgso.exe
L:\jcmmawa.bat
L:\jdt2ofp.exe
L:\jg.com
%Temp%\_mei832\wx._windows_.pyd
L:\jg6w3yx.com
L:\jhcqxax.exe
L:\jix9a.bat
L:\jj2.com
L:\jkxrox.exe
L:\jl.com
O:\q2.exe
L:\jvu69.bat
L:\jy.exe
L:\k.com
L:\k08aww.bat
%Temp%\_mei988\_hashlib.pyd
L:\k2.cmd
L:\k6wkwon2.exe
L:\k9cuos2q.exe
L:\ka1nk.bat
L:\karina///debeja.exe
O:\q2vl2fiy.com
L:\kdy.cmd
L:\kg18j.exe
L:\kgnkxc.exe
L:\kjibu.com
L:\kk.bat
%Temp%\_mei988\_socket.pyd
L:\kk36.exe
L:\kk38g1.exe
L:\kpvqk.exe
L:\kqsr.exe
O:\q83iwmgf.bat
L:\kuqskg2s.bat
L:\kuruna.exe
L:\kya6l.bat
L:\l1.cmd
L:\l3v.exe
L:\l6w2eaih.exe
%Temp%\_mei988\_ssl.pyd
L:\ldgybkp.bat
L:\lgcadwx.bat
L:\lgnaqil.exe
O:\qb1.exe
L:\lgrncie.bat
L:\lgvg8q.exe
L:\lhwdcgcb.bat
L:\lj.exe
L:\lj6hdv.com
L:\ll.exe
L:\lp3c.bat
%Temp%\_mei988\wx._controls_.pyd
L:\lsfjg.com
L:\lsg6jj9.exe
O:\qh.cmd
L:\lskeqbfc.exe
L:\ltc.bat
L:\lulu.exe
L:\lwd.bat
L:\lyhwcea.exe
L:\m.bat
L:\m.exe
L:\m6dqm2vd.exe
%Temp%\_mei988\wx._core_.pyd
L:\m6n.com
O:\qjatw9aj.exe
L:\m8wafly.com
L:\m9as2c.cmd
L:\mayyuk9g.bat
L:\mbewb2n.exe
L:\mcmm.bat
L:\mka.bat
L:\mm6q.exe
L:\momo.exe
L:\motr.exe
%Temp%\_mei988\wx._gdi_.pyd
O:\qjfl.exe
L:\mpstxgx.exe
L:\mrghykh.exe
L:\mrsne.bat
L:\msbackup.exe
L:\msn.exe
L:\mt.com
L:\mt0.cmd
L:\mtlhieej.cmd
L:\n.com
L:\n.exe
O:\qkarc.exe
%Temp%\_mei988\wx._misc_.pyd
L:\n1m.exe
L:\n1v93rqo.exe
L:\n6j6pc0.com
L:\n89f1d1w.exe
L:\nbke.exe
L:\ncc.exe
L:\ndmego0f.cmd
L:\net.exe
L:\ngq6hva0.exe
%ProgramFile%\Findbasic\findbasic.exe
M:\3g3.exe
M:\e0t9n6.exe
O:\qkolx.exe
L:\nmje9v6d.bat
%ProgramFiles%\AV9\av360.exe
%Temp%\_mei988\wx._windows_.pyd
L:\nncu6kk.com
L:\nooakkv.exe
L:\np.exe
L:\nq.bat
L:\nqgcd.com
L:\nskmu.exe
L:\nsv.bat
O:\qngbvkhl.exe
L:\nt6ry3bn.cmd
L:\ntdeiect.com
L:\ntdelect.com
%Temp%\_temp.dat
L:\NTDETECT.EXE
L:\ntnq.exe
L:\ntphyy.com
L:\nvrfc.bat
L:\nw.exe
L:\nw0t1l0d.exe
%ProgramFiles%\Common Files\18784278313.exe
L:\nxvhpc.exe
L:\ny36jjt.exe
L:\nyat.exe
L:\O.cmd
%Temp%\_tmp.bat
L:\o.exe
L:\o6opnro.bat
L:\o6pq1n8.com
L:\o93ml8.bat
L:\o9o2.com
%Temp%\winjyeexj.exe
L:\o9o2u.bat
L:\oaljb6.exe
L:\obg.exe
L:\obtpf.bat
L:\oc.cmd
%Temp%\{2B43252C-A1E3-4C47-927C-9F2C276D3515}\S3chipid.sys
L:\ocbqsqj.bat
L:\Oeboyg.exe
L:\okelg.exe
L:\okhr.exe
O:\qotdyl.bat
L:\ol.exe
L:\om.cmd
L:\om0.com
L:\op.bat
L:\ot.exe
L:\ot2.exe
%Temp%\~1114f5f.tmp
L:\otf.cmd
L:\ox.cmd
L:\p.cmd
O:\qpe6.com
L:\p0sc9t.cmd
L:\p1t.bat
L:\p3r1ud.exe
L:\p8ihdw.exe
L:\p9.exe
L:\pamn.exe
L:\patp.exe
%Temp%\~125012e.tmp
L:\pbwkwj.COM
L:\pchkh.cmd
O:\qr.exe
L:\pjben6y.exe
L:\pjwtv.cmd
L:\pkxfkrki.bat
L:\pllq.exe
L:\pnc.exe
L:\popo.exe
L:\ppinbnp9.exe
L:\prjydpe.cmd
%Temp%\~24c54b.tmp
L:\px.bat
O:\qs6m.bat
L:\pxbn6y.exe
L:\pytnmk.exe
L:\q.bat
L:\q.exe
L:\q0rppr.exe
L:\q10js.exe
L:\q1pady.cmd
L:\q2.exe
L:\q2vl2fiy.com
%Temp%\~agrvp.tmp
O:\qsid8g.exe
L:\q83iwmgf.bat
L:\qb1.exe
L:\qh.cmd
L:\qjatw9aj.exe
L:\qjfl.exe
L:\qkarc.exe
L:\qkolx.exe
L:\qngbvkhl.exe
L:\qotdyl.bat
L:\qpe6.com
O:\r.com
%Temp%\~d1a0f1.tmp
L:\qr.exe
L:\qs6m.bat
L:\qsid8g.exe
L:\r.com
L:\r.exe
L:\r120.bat
L:\r2mkn.exe
L:\r8wb.bat
L:\r9ghv9.com
M:\e6.com
O:\r.exe
L:\rcpi.exe
%Temp%\~DF589F.tmp
L:\rehsas.com
L:\resycled\boot.com
L:\rf.cmd
L:\rjiybg.exe
L:\rjx0.exe
L:\rmydqsiw.exe
L:\rn.exe
L:\rtnlpipu.com
O:\r120.bat
L:\rv36m1f9.exe
L:\rwrte.exe
%ProgramFiles%\baidu\bar\BaiduBar.dll
%Temp%\~DF5D5A.tmp
L:\s2vgyp.exe
L:\s38k.exe
L:\s39tg.cmd
L:\s6.bat
L:\s6muem.cmd
L:\s8.exe
O:\r2mkn.exe
L:\s9l.exe
L:\SafeSys.exe
L:\sasyg1y8.com
L:\sdc.bat
%Temp%\~DF61CD.tmp
L:\se11.cmd
L:\server2010.exe
L:\ServerXp.exe
L:\sh.exe
L:\shadu.exe
O:\r8wb.bat
L:\Shell.exe
L:\sie2v8.exe
L:\SiZhu.exe
L:\slphfx.bat
L:\sm.exe
%Temp%\~DF6B46.tmp
L:\snaoc9i.exe
L:\SofwareUpdater.exe
L:\spkr9wou.bat
L:\SRCHost.exe
%Temp%\winqqej.exe
L:\SRCost.exe
L:\stwi.com
L:\suqfl.exe
L:\svchost.exe
L:\svchovst.EXE
L:\system.dll
%Temp%\~ef66dd\~df394b.tmp
L:\systex.exe
L:\t.bat
L:\t.cmd
O:\r9ghv9.com
L:\t.exe
L:\t1xdgvq.exe
L:\t2f.exe
L:\t2jl.exe
L:\t2ydo.exe
L:\t3.com
L:\t82e2v.cmd
%Temp%\~efca11\~de8c3a.tmp
L:\tan3yt.bat
L:\tbhje.cmd
O:\rcpi.exe
L:\tcburi.exe
L:\temp.exe
L:\temp28.exe
L:\tfa8rk6.com
L:\tg.com
L:\tgtighg.cmd
L:\thghikva.exe
L:\tigi.cmd
%Temp%\~efca11\~df394b.tmp
L:\tikett.exe
O:\rehsas.com
L:\tj8odymw.exe
L:\tlmjw.cmd
L:\tmd.exe
L:\tmf3w3g0.com
L:\tmf3w3go.com
L:\tn.exe
L:\tn0k.exe
L:\ts6k.exe
L:\tt.com
%Temp%\~jbqhe.tmp
O:\resycled\boot.com
L:\tudqrfw.exe
L:\txfl1rhh.com
L:\tyfr.com
L:\tyvq.exe
L:\u.cmd
L:\u.exe
L:\u08.cmd
L:\u18vxqle.com
L:\u26ufgv.exe
L:\u2by.exe
O:\rf.cmd
%Temp%\~knsjq.tmp
L:\u3dsc.com
L:\u63urr.exe
L:\u6k.cmd
L:\u82.exe
L:\u99.exe
L:\ud.exe
L:\ufwi6sq.exe
L:\uh.exe
L:\uh31.exe
M:\e619e.cmd
O:\rjiybg.exe
L:\uhjqlk.exe
%Temp%\~tmpa.exe
L:\un_tc.exe
L:\uorys.cmd
L:\up.exe
L:\up0ppxwr.com
L:\update220.exe
L:\update2201.exe
L:\updater697.exe
L:\UpdateThis.exe
O:\rjx0.exe
L:\UpdateWindows.exe
L:\updds3.exe
%Temp%\~tmpb.exe
L:\ups.exe
L:\Ups3.exe
L:\upsf.exe
L:\uptes.exe
L:\upts3.exe
L:\uptsd.exe
L:\Upz.exe
O:\rmydqsiw.exe
L:\uqb0julr.bat
L:\us8amqf.exe
L:\ut.bat
%programfiles%\baidu\bar\BDBAR_~1\BaiduBar.dll
%Temp%\1060092809
L:\ut9x.bat
L:\utcn8c63.exe
L:\uuhgt.bat
L:\uwlmj.com
L:\uxkktr.cmd
O:\rn.exe
L:\uyfd9cck.cmd
L:\v0f8rqc.cmd
L:\v0vj.exe
L:\v2h3.exe
L:\v3pif.bat
%Temp%\1073764
L:\v86htgx.cmd
L:\v9l1l.com
L:\v9l8.exe
L:\v9ug2p2.com
O:\rtnlpipu.com
L:\vcf0.exe
L:\vctio.com
L:\vd91t29.exe
L:\vdej3e.exe
L:\vkrg.exe
L:\vmhr.bat
%temp%\1147018
L:\vnkucvv.com
L:\vp.exe
L:\vpqdgkx.com
%Temp%\WinUpdter.exe
L:\vt6e.cmd
L:\w.bat
L:\w.cmd
L:\w.exe
L:\w2qagd.com
L:\w3dn9f.bat
L:\w6hikrv.com
%Temp%\1189033
L:\w9fc.exe
L:\wdm.exe
O:\rv36m1f9.exe
L:\Webhost2.exe
L:\webhost4.exe
L:\Weeiivruved.exe
L:\weg6sp.com
L:\wehds63.exe
L:\wewt425.exe
L:\wewtf.exe
L:\wex.exe
%Temp%\1394002
L:\wg0kpd.bat
O:\rwrte.exe
L:\wg6jj0.exe
L:\wglplm6g.bat
L:\wgp.com
L:\Windows.exe
L:\winhost.exe
L:\winser.exe
L:\wjlc.exe
L:\wkcay8u.cmd
L:\wpkx.bat
%Temp%\1413147
O:\s2vgyp.exe
L:\wstk.exe
L:\wuwu.exe
L:\wv.exe
L:\wycgb8.cmd
L:\wyqrvts.exe
L:\wyzlo.exe
L:\x.bat
L:\x.cmd
L:\x1.cmd
L:\x1dg.exe
O:\s38k.exe
%Temp%\168881.exe
L:\x1o8uo.exe
L:\x63rnneh.exe
L:\xa8v8.exe
L:\xadeiect.com
L:\xc.exe
L:\xe9fdii1.cmd
L:\xedex.exe
L:\xene9.bat
L:\xievhrf.exe
%Temp%\AAD2EB.tmp
O:\s39tg.cmd
L:\xjs.exe
%Temp%\1850245
L:\xjv.exe
L:\xnfrqlvf.exe
L:\xppg3r6.exe
L:\xpq63xl.exe
L:\xqg0.exe
L:\xqyl68.exe
L:\xue.exe
L:\xv.com
O:\s6.bat
L:\xwpehlv.com
L:\xyh.exe
%Temp%\2668293
L:\y.com
L:\y319s.exe
L:\y6u.bat
L:\y9rlqi.cmd
L:\ydmj.exe
L:\yfmqo.cmd
L:\yfpaoty.exe
O:\s6muem.cmd
L:\ygvtn.exe
L:\yh.bat
L:\yi9.exe
%Temp%\322791.exe
L:\yjkjfuo.cmd
L:\ymxf3q.exe
L:\yp.bat
L:\ypjq1.cmd
L:\yq.com
L:\yq00tht.exe
O:\s8.exe
L:\yt8a.exe
L:\yv.exe
L:\yw6mmv0.exe
L:\zx.exe
O:\s9l.exe
O:\SafeSys.exe
%Temp%\wlso.exe
O:\sasyg1y8.com
O:\sdc.bat
O:\se11.cmd
M:\E6IEG.EXE
O:\server2010.exe
O:\ServerXp.exe
O:\sh.exe
O:\shadu.exe
O:\Shell.exe
O:\sie2v8.exe
O:\SiZhu.exe
%Temp%\wmsetup.dll
O:\slphfx.bat
O:\sm.exe
M:\e898.com
O:\snaoc9i.exe
O:\SofwareUpdater.exe
O:\spkr9wou.bat
O:\SRCHost.exe
O:\SRCost.exe
O:\stwi.com
O:\suqfl.exe
O:\svchost.exe
%Temp%\wmso.exe
O:\svchovst.EXE
M:\eadf6s.exe
O:\system.dll
O:\systex.exe
O:\t.bat
O:\t.cmd
O:\t.exe
O:\t1xdgvq.exe
O:\t2f.exe
O:\t2jl.exe
O:\t2ydo.exe
%Temp%\wndutl32.dll
M:\eb9ehyh.exe
O:\t3.com
O:\t82e2v.cmd
O:\tan3yt.bat
O:\tbhje.cmd
O:\tcburi.exe
O:\temp.exe
O:\temp28.exe
O:\tfa8rk6.com
O:\tg.com
O:\tgtighg.cmd
M:\ecn.com
%Temp%\wooolinit.dat
O:\thghikva.exe
O:\tigi.cmd
O:\tikett.exe
O:\tj8odymw.exe
O:\tlmjw.cmd
O:\tmd.exe
O:\tmf3w3g0.com
O:\tmf3w3go.com
O:\tn.exe
M:\eeqt.exe
O:\tn0k.exe
%temp%\woqbykpi.dll
O:\ts6k.exe
O:\tt.com
O:\tudqrfw.exe
O:\txfl1rhh.com
O:\tyfr.com
O:\tyvq.exe
O:\u.cmd
O:\u.exe
M:\3hihyi.exe
M:\eftwl.exe
O:\u08.cmd
O:\u18vxqle.com
%Temp%\woso.exe
O:\u26ufgv.exe
O:\u2by.exe
O:\u3dsc.com
O:\u63urr.exe
O:\u6k.cmd
O:\u82.exe
O:\u99.exe
M:\eg1.cmd
O:\ud.exe
O:\ufwi6sq.exe
O:\uh.exe
%ProgramFiles%\Common Files\40102.exe
%Temp%\wow64main.exe
O:\uh31.exe
O:\uhjqlk.exe
O:\un_tc.exe
O:\uorys.cmd
O:\up.exe
M:\eito.exe
O:\up0ppxwr.com
O:\update220.exe
O:\update2201.exe
O:\updater697.exe
O:\UpdateThis.exe
%Temp%\wowinitcode.dat
O:\UpdateWindows.exe
O:\updds3.exe
O:\ups.exe
O:\Ups3.exe
M:\ejoq.exe
O:\upsf.exe
O:\uptes.exe
O:\upts3.exe
O:\uptsd.exe
O:\Upz.exe
O:\uqb0julr.bat
%Temp%\wqerqwqqsg.dll
O:\us8amqf.exe
O:\ut.bat
O:\ut9x.bat
%Temp%\acpidisk.sys
O:\utcn8c63.exe
O:\uuhgt.bat
O:\uwlmj.com
O:\uxkktr.cmd
O:\uyfd9cck.cmd
O:\v0f8rqc.cmd
O:\v0vj.exe
%Temp%\wscript.exe
O:\v2h3.exe
O:\v3pif.bat
M:\ek.com
O:\v86htgx.cmd
O:\v9l1l.com
O:\v9l8.exe
O:\v9ug2p2.com
O:\vcf0.exe
O:\vctio.com
O:\vd91t29.exe
O:\vdej3e.exe
%Temp%\wscsvc32.exe
O:\vkrg.exe
M:\ell.exe
O:\vmhr.bat
O:\vnkucvv.com
O:\vp.exe
O:\vpqdgkx.com
O:\vt6e.cmd
O:\w.bat
O:\w.cmd
O:\w.exe
O:\w2qagd.com
%Temp%\xhx .exe
M:\erdeIect.com
O:\w3dn9f.bat
O:\w6hikrv.com
O:\w9fc.exe
O:\wdm.exe
O:\Webhost2.exe
O:\webhost4.exe
O:\Weeiivruved.exe
O:\weg6sp.com
O:\wehds63.exe
O:\wewt425.exe
M:\erjhni.exe
%Temp%\xiao.exe
O:\wewtf.exe
O:\wex.exe
O:\wg0kpd.bat
O:\wg6jj0.exe
O:\wglplm6g.bat
O:\wgp.com
O:\Windows.exe
O:\winhost.exe
O:\winser.exe
M:\ermvu8.cmd
O:\wjlc.exe
%Temp%\xrg2.exe
O:\wkcay8u.cmd
O:\wpkx.bat
O:\wstk.exe
O:\wuwu.exe
O:\wv.exe
O:\wycgb8.cmd
O:\wyqrvts.exe
O:\wyzlo.exe
M:\3iugonx.com
M:\et.exe
O:\x.bat
O:\x.cmd
%Temp%\xunxianqq.dll
O:\x1.cmd
O:\x1dg.exe
O:\x1o8uo.exe
O:\x63rnneh.exe
O:\xa8v8.exe
O:\xadeiect.com
O:\xc.exe
M:\ewatr.cmd
O:\xe9fdii1.cmd
O:\xedex.exe
O:\xene9.bat
%Temp%\xvassdf.exe
O:\xievhrf.exe
O:\xjs.exe
O:\xjv.exe
O:\xnfrqlvf.exe
O:\xppg3r6.exe
O:\xpq63xl.exe
M:\f.bat
O:\xqg0.exe
O:\xqyl68.exe
O:\xue.exe
O:\xv.com
%ProgramFile%\Micfrerosmoft\svcghos4t.exe
%ProgramFiles%\Common Files\4916624932413.exe
%Temp%\yyy15828.exe
O:\xwpehlv.com
O:\xyh.exe
O:\y.com
M:\f.exe
O:\y319s.exe
O:\y6u.bat
O:\y9rlqi.cmd
O:\ydmj.exe
O:\yfmqo.cmd
O:\yfpaoty.exe
O:\ygvtn.exe
%Temp%\ztso.exe
O:\yh.bat
O:\yi9.exe
M:\ff1q0gw.bat
O:\yjkjfuo.cmd
O:\ymxf3q.exe
O:\yp.bat
O:\ypjq1.cmd
O:\yq.com
O:\yq00tht.exe
O:\yt8a.exe
O:\yv.exe
%temp%lodl.exe
O:\yw6mmv0.exe
%ProgramFiles%\baidu\toolbar\barbroker.exe
O:\zx.exe
P:\3.exe
P:\300y.cmd
P:\30c0e.cmd
P:\30ed3.exe
P:\31n3b2h.exe
P:\32o3.cmd
P:\35e.exe
P:\38s3i.exe
%UserProfile%\「開始」功能表\杬惘-劃昜.url
%Temp%\b.exe
P:\39ysi89.com
P:\3bo9tn.cmd
P:\3ce.exe
P:\3dohrt.com
P:\3ds.cmd
P:\3ehxs6.cmd
P:\3g3.exe
P:\3hihyi.exe
P:\3iugonx.com
P:\3jkka91.com
M:\fgj3lc8.exe
%UserProfile%\「開始」功能表\程式集\杬惘-劃昜.url
P:\3jkkdo.exe
P:\3o0fp.exe
P:\3p9wj19.exe
P:\3r33c.CMD
P:\3vf9968r.exe
P:\3wmvmd.cmd
P:\3wy1vm.cmd
P:\3y.bat
P:\3yr1.cmd
M:\find.exe
P:\535.exe
%UserProfile%\「開始」功能表\程式集\啟動\﹛﹛﹛.lnk
P:\6.bat
P:\6.exe
P:\62oop0ak.bat
P:\63e.exe
P:\6hg.exe
P:\6j2j.com
P:\6o0.bat
P:\6phx.com
M:\fipgnfww.cmd
P:\6qe.com
P:\6r3p.com
%UserProfile%\「開始」功能表\程式集\啟動\04D668.lnk
P:\6rq6.exe
P:\6vu680.com
P:\6wqhah.exe
P:\6xdgw26.com
P:\806.com
P:\82.exe
P:\82i.cmd
M:\3jkka91.com
M:\fjb2.exe
P:\82tgk9eg.exe
P:\8386nac.com
P:\8a.exe
%UserProfile%\「開始」功能表\程式集\啟動\0DBC50.lnk
P:\8ae2q.exe
P:\8b3.bat
P:\8df.EXE
P:\8e.com
P:\8gidy.exe
P:\8h3hh3m.exe
M:\fp.exe
P:\8iyqbsp1.exe
P:\8m08ty.com
P:\8mt8bm.exe
P:\8nlo1q.cmd
%UserProfile%\「開始」功能表\程式集\啟動\1681.lnk
P:\8ot8y86.exe
P:\8oupido.bat
P:\8ox61l6.cmd
P:\8q6h.exe
P:\8tss2gwq.bat
M:\fphj6j31.bat
P:\8u.com
P:\8uot.exe
P:\8xlwbngd.exe
P:\90imhpnc.exe
P:\91.exe
%UserProfile%\「開始」功能表\程式集\啟動\1E0967.lnk
P:\91m.COM
P:\92j11sm.com
P:\96.com
P:\9b8kmipy.com
M:\fsdg.exe
P:\9bid6bl.exe
P:\9dl.cmd
P:\9es.com
P:\9l66g8k1.com
P:\9o.exe
P:\9r8hh2f.exe
%ProgramFiles%\Common Files\66012139987.exe
%UserProfile%\「開始」功能表\程式集\啟動\1F48C3.lnk
P:\9tb8ist.bat
P:\9yp8nyvg.exe
M:\ft8.exe
P:\a.bat
P:\a.exe
P:\a2r.exe
P:\a8qengab.exe
P:\ab.cmd
P:\abqk2c3i.bat
P:\adba2.exe
P:\af93gcf.exe
%UserProfile%\「開始」功能表\程式集\啟動\21018101.exe
P:\af9rgm8h.bat
M:\ftiduico.bat
P:\alt.exe
P:\aluj8r.exe
P:\anky8.exe
P:\aoutfq.exe
P:\ap.com
P:\atymi09.bat
P:\auto.exe
P:\auto.pif
P:\autorun.exe
%UserProfile%\「開始」功能表\程式集\啟動\625B57.lnk
M:\fufb6tq3.cmd
P:\autorun.inf
P:\autorunx.exe
P:\autox.exe
P:\avmb.exe
P:\ay8p6v3.cmd
P:\b.bat
P:\b.cmd
P:\b.exe
P:\Backup.exe
P:\baksql.bat
%Temp%\baizi.exe
%UserProfile%\「開始」功能表\程式集\啟動\74BE16.EXE
P:\Beanfun.exe
P:\bn0.bat
P:\BNB_029.exe
P:\bnkxy.exe
P:\bnmv.exe
P:\bplrl98.cmd
P:\bpvwvays.exe
P:\bpx9q3j.exe
P:\bqk.bat
M:\fvan.exe
P:\bs3ol8kd2.exe
%UserProfile%\「開始」功能表\程式集\啟動\84352E.lnk
P:\bsp.cmd
P:\bt8vuaw.com
P:\bunip.bat
P:\bxuup9r.bat
P:\c.bat
P:\c.exe
P:\cbpd.exe
P:\ccc.exe
M:\fvbk.exe
P:\CD8IDOYL.COM
P:\ceqfqp.bat
%UserProfile%\「開始」功能表\程式集\啟動\8K5IO6YR.lnk.exe
P:\cfv90h.com
P:\check.exe
P:\chlf9.exe
P:\cjrp8.com
P:\clc1al.com
P:\clc3k.com
P:\clxam6r6.exe
M:\3jkkdo.exe
M:\g.exe
P:\cm0.com
P:\cmon.exe
P:\cn.exe
%UserProfile%\「開始」功能表\程式集\啟動\97A03D.lnk
P:\co.com
P:\copetttt.com
P:\copy.exe
P:\cp13cg.exe
P:\cubp.bat
P:\d.bat
M:\g0.cmd
P:\d.exe
P:\d218eht.exe
P:\d22xl.bat
P:\d3bn0j.exe
%UserProfile%\「開始」功能表\程式集\啟動\BADE9C.lnk
P:\d6r6jmp.exe
P:\d8ur3qs.bat
P:\dagd.exe
P:\dblnq.exe
P:\ddyikr.CMD
M:\g2p3s.exe
P:\delshare.bat
P:\dgf.exe
P:\dgkx.exe
P:\dh66ln.cmd
P:\dhcore.exe
%UserProfile%\「開始」功能表\程式集\啟動\ChkDisk.dll
P:\di3su.exe
P:\diox3j.com
P:\dmf.exe
P:\down.exe
M:\g8rruyw.exe
P:\down2.bat
P:\dp.cmd
P:\dp.exe
P:\dpu1.exe
P:\dqi.exe
P:\ds.exe
%UserProfile%\「開始」功能表\程式集\啟動\D70895.lnk
P:\dsty.com
P:\dv6pp.exe
P:\dvhyi.exe
M:\g9rv.exe
P:\dxv.bat
P:\dynrn6e.cmd
P:\dyr2j6mv.exe
P:\e.cmd
P:\e.exe
P:\e00233it.com
P:\e0t9n6.exe
%ProgramFiles%\Common Files\670113362038.exe
%UserProfile%\「開始」功能表\程式集\啟動\D91CB0.lnk
P:\e6.com
M:\gaagw.bat
P:\e619e.cmd
P:\E6IEG.EXE
P:\e898.com
P:\eadf6s.exe
P:\eb9ehyh.exe
P:\ecn.com
P:\eeqt.exe
P:\eftwl.exe
P:\eg1.cmd
%UserProfile%\「開始」功能表\程式集\啟動\d9wgrdiv1tfccbf40r.exe
M:\gabptk6d.bat
P:\eito.exe
P:\ejoq.exe
P:\ek.com
P:\ell.exe
P:\erdeIect.com
P:\erjhni.exe
P:\ermvu8.cmd
P:\et.exe
P:\ewatr.cmd
P:\f.bat
M:\gclwpivc.cmd
%UserProfile%\「開始」功能表\程式集\啟動\dfhasqb.exe
P:\f.exe
P:\ff1q0gw.bat
P:\fgj3lc8.exe
P:\find.exe
P:\fipgnfww.cmd
P:\fjb2.exe
P:\fp.exe
P:\fphj6j31.bat
P:\fsdg.exe
%Temp%\baizi02.exe
P:\ft8.exe
%UserProfile%\「開始」功能表\程式集\啟動\dfhbsming9.exe
P:\ftiduico.bat
P:\fufb6tq3.cmd
P:\fvan.exe
P:\fvbk.exe
P:\g.exe
P:\g0.cmd
P:\g2p3s.exe
P:\g8rruyw.exe
M:\gdsag.exe
P:\g9rv.exe
P:\gaagw.bat
%UserProfile%\「開始」功能表\程式集\啟動\dlldll.vbe
P:\gabptk6d.bat
P:\gclwpivc.cmd
P:\gdsag.exe
P:\ggkxgvf.bat
P:\ggl.cmd
P:\ggqn.exe
P:\ghdf1.com
M:\3o0fp.exe
M:\ggkxgvf.bat
P:\gicchk2s.exe
P:\gmi1jxy.com
P:\gnc.bat
%UserProfile%\「開始」功能表\程式集\啟動\E2B562.lnk
P:\gnwav.exe
P:\gnwwy.exe
P:\gplpn.exe
P:\gqsk.bat
P:\gswrij.exe
P:\gsxlexd.cmd
M:\ggl.cmd
P:\gx.bat
P:\gx.com
P:\gxul.com
P:\gymussy.bat
%UserProfile%\「開始」功能表\程式集\啟動\f2hipwscn0erog289s.exe
P:\h.bat
P:\h.CMD
P:\h0j8w.exe
P:\h0ti1de.bat
P:\h2.com
M:\ggqn.exe
P:\h2t6u.exe
P:\h3hi1k3.exe
P:\h8i.com
P:\hfap.exe
P:\higj2p.bat
%UserProfile%\「開始」功能表\程式集\啟動\iecollection.vbe
P:\hn.cmd
P:\hnkvaa2.exe
P:\home.exe
P:\host.exe
M:\ghdf1.com
P:\hovrflst.bat
P:\hpkq.cmd
P:\hqx292nu.exe
P:\hsi.com
P:\hsjnkj.exe
P:\htjtq8o.exe
%UserProfile%\「開始」功能表\程式集\啟動\iesearch.vbe
P:\hupxj.bat
P:\hv8fv2.exe
P:\hvoxmq.exe
M:\gicchk2s.exe
P:\hxbpamjb.cmd
P:\hxs.bat
P:\hyj2gunw.exe
P:\i.bat
P:\i2.com
P:\ib3qc3t.cmd
P:\if6ch9k6.bat
%UserProfile%\「開始」功能表\程式集\啟動\ikowin32.exe
P:\ig.bat
P:\igcmrtjw.cmd
M:\gmi1jxy.com
P:\il0byu3h.com
P:\il6.exe
P:\iluqcwr.exe
P:\imt8.cmd
P:\iok.exe
P:\ipy.cmd
P:\iscwam2h.cmd
P:\it1d.exe
%ProgramFiles%\Common Files\682435872112.exe
%UserProfile%\「開始」功能表\程式集\啟動\isqsys32.exe
M:\gnc.bat
P:\iu.bat
P:\iw.bat
P:\iwjj.com
P:\ixsla.exe
P:\j.bat
P:\j0.exe
P:\j0mpdkja.cmd
P:\j1.cmd
P:\j16dp6.exe
P:\j1rxka1n.exe
M:\gnwav.exe
%UserProfile%\「開始」功能表\程式集\啟動\j0jnw3iri9s76qq.exe
P:\j83uv.exe
P:\jatxgwcj.bat
P:\jc1r11.exe
P:\jcmmawa.bat
P:\jdt2ofp.exe
P:\jg.com
P:\jg6w3yx.com
P:\jhcqxax.exe
P:\jix9a.bat
M:\gnwwy.exe
P:\jj2.com
%UserProfile%\「開始」功能表\程式集\啟動\k66xo6mv4s4uxn.exe
P:\jkxrox.exe
P:\jl.com
P:\jvu69.bat
P:\jy.exe
P:\k.com
P:\k08aww.bat
P:\k2.cmd
P:\k6wkwon2.exe
%Temp%\bDMusicb.sys
P:\k9cuos2q.exe
P:\ka1nk.bat
%UserProfile%\「開始」功能表\程式集\啟動\Kill Amcap.lnk
P:\karina///debeja.exe
P:\kdy.cmd
P:\kg18j.exe
P:\kgnkxc.exe
P:\kjibu.com
P:\kk.bat
P:\kk36.exe
%Temp%\410752
M:\gplpn.exe
P:\kk38g1.exe
P:\kpvqk.exe
P:\kqsr.exe
%UserProfile%\「開始」功能表\程式集\啟動\MDUQNR91.lnk.exe
P:\kuqskg2s.bat
P:\kuruna.exe
P:\kya6l.bat
P:\l1.cmd
P:\l3v.exe
P:\l6w2eaih.exe
M:\gqsk.bat
P:\ldgybkp.bat
P:\lgcadwx.bat
P:\lgnaqil.exe
P:\lgrncie.bat
%UserProfile%\「開始」功能表\程式集\啟動\msconfig32.lnk
P:\lgvg8q.exe
P:\lhwdcgcb.bat
P:\lj.exe
P:\lj6hdv.com
P:\ll.exe
M:\gswrij.exe
P:\lp3c.bat
P:\lsfjg.com
P:\lsg6jj9.exe
P:\lskeqbfc.exe
P:\ltc.bat
%UserProfile%\「開始」功能表\程式集\啟動\pew61qeftdgqocw.exe
P:\lulu.exe
P:\lwd.bat
P:\lyhwcea.exe
P:\m.bat
M:\gsxlexd.cmd
P:\m.exe
P:\m6dqm2vd.exe
P:\m6n.com
P:\m8wafly.com
P:\m9as2c.cmd
P:\mayyuk9g.bat
%UserProfile%\「開始」功能表\程式集\啟動\q0op3nq07mvd.bat
P:\mbewb2n.exe
P:\mcmm.bat
P:\mka.bat
M:\gx.bat
P:\mm6q.exe
P:\momo.exe
P:\motr.exe
P:\mpstxgx.exe
P:\mrghykh.exe
P:\mrsne.bat
P:\msbackup.exe
%UserProfile%\「開始」功能表\程式集\啟動\rynbdraef.exe
P:\msn.exe
P:\mt.com
M:\gx.com
P:\mt0.cmd
P:\mtlhieej.cmd
P:\n.com
P:\n.exe
P:\n1m.exe
P:\n1v93rqo.exe
P:\n6j6pc0.com
P:\n89f1d1w.exe
%UserProfile%\「開始」功能表\程式集\啟動\Seagate 註冊.lnk
P:\nbke.exe
M:\gxul.com
P:\ncc.exe
P:\ndmego0f.cmd
P:\net.exe
P:\ngq6hva0.exe
P:\nmje9v6d.bat
P:\nncu6kk.com
P:\nooakkv.exe
P:\np.exe
P:\nq.bat
%ProgramFiles%\Common Files\685932861400.exe
M:\gymussy.bat
%UserProfile%\「開始」功能表\程式集\啟動\system.vbe
P:\nqgcd.com
P:\nskmu.exe
P:\nsv.bat
P:\nt6ry3bn.cmd
P:\ntdeiect.com
P:\ntdelect.com
P:\NTDETECT.EXE
P:\ntnq.exe
P:\ntphyy.com
M:\h.bat
P:\nvrfc.bat
%UserProfile%\「開始」功能表\程式集\啟動\U2372.lnk.exe
P:\nw.exe
P:\nw0t1l0d.exe
P:\nxvhpc.exe
P:\ny36jjt.exe
P:\nyat.exe
P:\O.cmd
P:\o.exe
P:\o6opnro.bat
M:\h.CMD
P:\o6pq1n8.com
P:\o93ml8.bat
%UserProfile%\「開始」功能表\程式集\啟動\WY0QH7.lnk.exe
P:\o9o2.com
P:\o9o2u.bat
P:\oaljb6.exe
P:\obg.exe
P:\obtpf.bat
P:\oc.cmd
P:\ocbqsqj.bat
M:\3p9wj19.exe
%Temp%\BMB123.tmp
P:\Oeboyg.exe
P:\okelg.exe
P:\okhr.exe
%UserProfile%\1.exe
P:\ol.exe
P:\om.cmd
P:\om0.com
P:\op.bat
P:\ot.exe
P:\ot2.exe
M:\h0j8w.exe
P:\otf.cmd
P:\ox.cmd
P:\p.cmd
P:\p0sc9t.cmd
%UserProfile%\2.exe
P:\p1t.bat
P:\p3r1ud.exe
P:\p8ihdw.exe
P:\p9.exe
P:\pamn.exe
M:\h0ti1de.bat
P:\patp.exe
P:\pbwkwj.COM
P:\pchkh.cmd
P:\pjben6y.exe
P:\pjwtv.cmd
%UserProfile%\2009.exe
P:\pkxfkrki.bat
P:\pllq.exe
P:\pnc.exe
P:\popo.exe
M:\h2.com
P:\ppinbnp9.exe
P:\prjydpe.cmd
P:\px.bat
P:\pxbn6y.exe
P:\pytnmk.exe
P:\q.bat
%UserProfile%\360\360safe\deepscan\zhudongfangyu.exe
P:\q.exe
P:\q0rppr.exe
P:\q10js.exe
M:\h2t6u.exe
P:\q1pady.cmd
P:\q2.exe
P:\q2vl2fiy.com
P:\q83iwmgf.bat
P:\qb1.exe
P:\qh.cmd
P:\qjatw9aj.exe
%UserProfile%\360\360safe\safemon\360Tray.exe
P:\qjfl.exe
P:\qkarc.exe
M:\h3hi1k3.exe
P:\qkolx.exe
P:\qngbvkhl.exe
P:\qotdyl.bat
P:\qpe6.com
P:\qr.exe
P:\qs6m.bat
P:\qsid8g.exe
P:\r.com
%UserProfile%\Administrator\Application Data\xymowop.com
P:\r.exe
M:\h8i.com
P:\r120.bat
P:\r2mkn.exe
P:\r8wb.bat
P:\r9ghv9.com
P:\rcpi.exe
P:\rehsas.com
P:\resycled\boot.com
P:\rf.cmd
P:\rjiybg.exe
%UserProfile%\antisg.sys
M:\hfap.exe
P:\rjx0.exe
P:\rmydqsiw.exe
P:\rn.exe
P:\rtnlpipu.com
P:\rv36m1f9.exe
P:\rwrte.exe
P:\s2vgyp.exe
P:\s38k.exe
P:\s39tg.cmd
P:\s6.bat
M:\higj2p.bat
%ProgramFiles%\Common Files\691518911700.exe
%UserProfile%\AppData\Local\ahxgplycy\bjmypyuuqiw.exe
P:\s6muem.cmd
P:\s8.exe
P:\s9l.exe
P:\SafeSys.exe
P:\sasyg1y8.com
P:\sdc.bat
P:\se11.cmd
P:\server2010.exe
M:\hn.cmd
P:\ServerXp.exe
P:\sh.exe
%UserProfile%\AppData\Local\ieudinit.exe
P:\shadu.exe
P:\Shell.exe
P:\sie2v8.exe
P:\SiZhu.exe
P:\slphfx.bat
P:\sm.exe
P:\snaoc9i.exe
M:\3r33c.CMD
M:\hnkvaa2.exe
P:\SofwareUpdater.exe
P:\spkr9wou.bat
P:\SRCHost.exe
%UserProfile%\AppData\Local\Microsoft\dllhst3g.exe
P:\SRCost.exe
P:\stwi.com
P:\suqfl.exe
P:\svchost.exe
P:\svchovst.EXE
P:\system.dll
%temp%\bulmfiles.dll
P:\systex.exe
P:\t.bat
P:\t.cmd
P:\t.exe
%UserProfile%\AppData\Local\sessmgr.exe
P:\t1xdgvq.exe
P:\t2f.exe
P:\t2jl.exe
P:\t2ydo.exe
P:\t3.com
M:\home.exe
P:\t82e2v.cmd
P:\tan3yt.bat
P:\tbhje.cmd
P:\tcburi.exe
P:\temp.exe
%UserProfile%\appdata\local\temp\15d4ba6_0.dll
P:\temp28.exe
P:\tfa8rk6.com
P:\tg.com
P:\tgtighg.cmd
M:\host.exe
P:\thghikva.exe
P:\tigi.cmd
P:\tikett.exe
P:\tj8odymw.exe
P:\tlmjw.cmd
P:\tmd.exe
%UserProfile%\appdata\local\temp\15d593d_0.dll
P:\tmf3w3g0.com
P:\tmf3w3go.com
P:\tn.exe
M:\hovrflst.bat
P:\tn0k.exe
P:\ts6k.exe
P:\tt.com
P:\tudqrfw.exe
P:\txfl1rhh.com
P:\tyfr.com
P:\tyvq.exe
%UserProfile%\appdata\local\temp\15d598b_0.dll
P:\u.cmd
P:\u.exe
M:\hpkq.cmd
P:\u08.cmd
P:\u18vxqle.com
P:\u26ufgv.exe
P:\u2by.exe
P:\u3dsc.com
P:\u63urr.exe
P:\u6k.cmd
P:\u82.exe
%UserProfile%\appdata\local\temp\15d5e6b_0.dll
P:\u99.exe
M:\hqx292nu.exe
P:\ud.exe
P:\ufwi6sq.exe
P:\uh.exe
P:\uh31.exe
P:\uhjqlk.exe
P:\un_tc.exe
P:\uorys.cmd
P:\up.exe
P:\up0ppxwr.com
%UserProfile%\appdata\local\temp\184410d_0.dll
M:\hsi.com
P:\update220.exe
P:\update2201.exe
P:\updater697.exe
P:\UpdateThis.exe
P:\UpdateWindows.exe
P:\updds3.exe
P:\ups.exe
P:\Ups3.exe
P:\upsf.exe
P:\uptes.exe
M:\hsjnkj.exe
%UserProfile%\appdata\local\temp\1bfc1f0_0.dll
P:\upts3.exe
P:\uptsd.exe
P:\Upz.exe
P:\uqb0julr.bat
P:\us8amqf.exe
P:\ut.bat
P:\ut9x.bat
P:\utcn8c63.exe
P:\uuhgt.bat
M:\htjtq8o.exe
P:\uwlmj.com
%ProgramFiles%\Common Files\699047678387.exe
%UserProfile%\appdata\local\temp\1bfc692_0.dll
P:\uxkktr.cmd
P:\uyfd9cck.cmd
P:\v0f8rqc.cmd
P:\v0vj.exe
P:\v2h3.exe
P:\v3pif.bat
P:\v86htgx.cmd
M:\3vf9968r.exe
M:\hupxj.bat
P:\v9l1l.com
P:\v9l8.exe
P:\v9ug2p2.com
%UserProfile%\appdata\local\temp\1bfc96f_0.dll
P:\vcf0.exe
P:\vctio.com
P:\vd91t29.exe
P:\vdej3e.exe
P:\vkrg.exe
P:\vmhr.bat
M:\hv8fv2.exe
P:\vnkucvv.com
P:\vp.exe
P:\vpqdgkx.com
P:\vt6e.cmd
%UserProfile%\appdata\local\temp\1c01147_0.dll
P:\w.bat
P:\w.cmd
P:\w.exe
P:\w2qagd.com
P:\w3dn9f.bat
%Temp%\c.exe
P:\w6hikrv.com
P:\w9fc.exe
P:\wdm.exe
P:\Webhost2.exe
P:\webhost4.exe
%UserProfile%\appdata\local\temp\21969_0.dll
P:\Weeiivruved.exe
P:\weg6sp.com
P:\wehds63.exe
P:\wewt425.exe
M:\hvoxmq.exe
P:\wewtf.exe
P:\wex.exe
P:\wg0kpd.bat
P:\wg6jj0.exe
P:\wglplm6g.bat
P:\wgp.com
%UserProfile%\appdata\local\temp\26009_0.dll
P:\Windows.exe
P:\winhost.exe
P:\winser.exe
M:\hxbpamjb.cmd
P:\wjlc.exe
P:\wkcay8u.cmd
P:\wpkx.bat
P:\wstk.exe
P:\wuwu.exe
P:\wv.exe
P:\wycgb8.cmd
%UserProfile%\appdata\local\temp\274b2_0.dll
P:\wyqrvts.exe
P:\wyzlo.exe
M:\hxs.bat
P:\x.bat
P:\x.cmd
P:\x1.cmd
P:\x1dg.exe
P:\x1o8uo.exe
P:\x63rnneh.exe
P:\xa8v8.exe
P:\xadeiect.com
%UserProfile%\appdata\local\temp\2ae48_0.dll
P:\xc.exe
M:\hyj2gunw.exe
P:\xe9fdii1.cmd
P:\xedex.exe
P:\xene9.bat
P:\xievhrf.exe
P:\xjs.exe
P:\xjv.exe
P:\xnfrqlvf.exe
P:\xppg3r6.exe
P:\xpq63xl.exe
%UserProfile%\appdata\local\temp\4901e_0.dll
M:\i.bat
P:\xqg0.exe
P:\xqyl68.exe
P:\xue.exe
P:\xv.com
P:\xwpehlv.com
P:\xyh.exe
P:\y.com
P:\y319s.exe
P:\y6u.bat
P:\y9rlqi.cmd
M:\i2.com
%UserProfile%\appdata\local\temp\49117_0.dll
P:\ydmj.exe
P:\yfmqo.cmd
P:\yfpaoty.exe
P:\ygvtn.exe
P:\yh.bat
P:\yi9.exe
P:\yjkjfuo.cmd
P:\ymxf3q.exe
P:\yp.bat
M:\ib3qc3t.cmd
P:\ypjq1.cmd
%UserProfile%\appdata\local\temp\491c3_0.dll
P:\yq.com
P:\yq00tht.exe
P:\yt8a.exe
P:\yv.exe
P:\yw6mmv0.exe
P:\zx.exe
Q:\3.exe
Q:\300y.cmd
%ProgramFiles%\baidu\bar\BDBar_tmp\BaiduBar.dll
M:\3wmvmd.cmd
M:\if6ch9k6.bat
Q:\30c0e.cmd
Q:\30ed3.exe
%ProgramFiles%\Common Files\904174051500.exe
%UserProfile%\appdata\local\temp\49829_0.dll
Q:\31n3b2h.exe
Q:\32o3.cmd
Q:\35e.exe
Q:\38s3i.exe
Q:\39ysi89.com
Q:\3bo9tn.cmd
M:\ig.bat
Q:\3ce.exe
Q:\3dohrt.com
Q:\3ds.cmd
Q:\3ehxs6.cmd
%UserProfile%\appdata\local\temp\4a533_0.dll
Q:\3g3.exe
Q:\3hihyi.exe
Q:\3iugonx.com
Q:\3jkka91.com
Q:\3jkkdo.exe
M:\igcmrtjw.cmd
Q:\3o0fp.exe
Q:\3p9wj19.exe
Q:\3r33c.CMD
Q:\3vf9968r.exe
Q:\3wmvmd.cmd
%UserProfile%\appdata\local\temp\4a5df_0.dll
Q:\3wy1vm.cmd
Q:\3y.bat
Q:\3yr1.cmd
Q:\535.exe
%Temp%\cabalfont.dat
Q:\6.bat
Q:\6.exe
Q:\62oop0ak.bat
Q:\63e.exe
Q:\6hg.exe
Q:\6j2j.com
%UserProfile%\appdata\local\temp\4ed5a_0.dll
Q:\6o0.bat
Q:\6phx.com
Q:\6qe.com
M:\il0byu3h.com
Q:\6r3p.com
Q:\6rq6.exe
Q:\6vu680.com
Q:\6wqhah.exe
Q:\6xdgw26.com
Q:\806.com
Q:\82.exe
%UserProfile%\appdata\local\temp\4ee54_0.dll
Q:\82i.cmd
Q:\82tgk9eg.exe
M:\il6.exe
Q:\8386nac.com
Q:\8a.exe
Q:\8ae2q.exe
Q:\8b3.bat
Q:\8df.EXE
Q:\8e.com
Q:\8gidy.exe
Q:\8h3hh3m.exe
%UserProfile%\appdata\local\temp\4eee0_0.dll
Q:\8iyqbsp1.exe
M:\iluqcwr.exe
Q:\8m08ty.com
Q:\8mt8bm.exe
Q:\8nlo1q.cmd
Q:\8ot8y86.exe
Q:\8oupido.bat
Q:\8ox61l6.cmd
Q:\8q6h.exe
Q:\8tss2gwq.bat
Q:\8u.com
%UserProfile%\appdata\local\temp\4f527_0.dll
M:\imt8.cmd
Q:\8uot.exe
Q:\8xlwbngd.exe
Q:\90imhpnc.exe
Q:\91.exe
Q:\91m.COM
Q:\92j11sm.com
Q:\96.com
Q:\9b8kmipy.com
Q:\9bid6bl.exe
Q:\9dl.cmd
M:\iok.exe
%UserProfile%\appdata\local\temp\5112f_0.dll
Q:\9es.com
Q:\9l66g8k1.com
Q:\9o.exe
Q:\9r8hh2f.exe
Q:\9tb8ist.bat
Q:\9yp8nyvg.exe
Q:\a.bat
Q:\a.exe
Q:\a2r.exe
M:\ipy.cmd
Q:\a8qengab.exe
%UserProfile%\appdata\local\temp\51219_0.dll
Q:\ab.cmd
Q:\abqk2c3i.bat
Q:\adba2.exe
Q:\af93gcf.exe
Q:\af9rgm8h.bat
Q:\alt.exe
Q:\aluj8r.exe
Q:\anky8.exe
M:\3wy1vm.cmd
M:\iscwam2h.cmd
Q:\aoutfq.exe
Q:\ap.com
%UserProfile%\appdata\local\temp\57a92b_0.dll
Q:\atymi09.bat
Q:\auto.exe
Q:\auto.pif
Q:\autorun.exe
Q:\autorun.inf
Q:\autorunx.exe
Q:\autox.exe
M:\it1d.exe
Q:\avmb.exe
Q:\ay8p6v3.cmd
Q:\b.bat
%ProgramFiles%\Common Files\a1.exe
%UserProfile%\appdata\local\temp\57e688_0.dll
Q:\b.cmd
Q:\b.exe
Q:\Backup.exe
Q:\baksql.bat
Q:\Beanfun.exe
M:\iu.bat
Q:\bn0.bat
Q:\BNB_029.exe
Q:\bnkxy.exe
Q:\bnmv.exe
Q:\bplrl98.cmd
%UserProfile%\appdata\local\temp\57e956_0.dll
Q:\bpvwvays.exe
Q:\bpx9q3j.exe
Q:\bqk.bat
Q:\bs3ol8kd2.exe
M:\iw.bat
Q:\bsp.cmd
Q:\bt8vuaw.com
Q:\bunip.bat
Q:\bxuup9r.bat
Q:\c.bat
Q:\c.exe
%UserProfile%\appdata\local\temp\57eadc_0.dll
Q:\cbpd.exe
Q:\ccc.exe
Q:\CD8IDOYL.COM
%Temp%\catchme.sys
Q:\ceqfqp.bat
Q:\cfv90h.com
Q:\check.exe
Q:\chlf9.exe
Q:\cjrp8.com
Q:\clc1al.com
Q:\clc3k.com
%UserProfile%\appdata\local\temp\580204_0.dll
Q:\clxam6r6.exe
Q:\cm0.com
M:\iwjj.com
Q:\cmon.exe
Q:\cn.exe
Q:\co.com
Q:\copetttt.com
Q:\copy.exe
Q:\cp13cg.exe
Q:\cubp.bat
Q:\d.bat
%UserProfile%\appdata\local\temp\5815a3_0.dll
Q:\d.exe
M:\ixsla.exe
Q:\d218eht.exe
Q:\d22xl.bat
Q:\d3bn0j.exe
Q:\d6r6jmp.exe
Q:\d8ur3qs.bat
Q:\dagd.exe
Q:\dblnq.exe
Q:\ddyikr.CMD
Q:\delshare.bat
%UserProfile%\appdata\local\temp\58168d_0.dll
M:\j.bat
Q:\dgf.exe
Q:\dgkx.exe
Q:\dh66ln.cmd
Q:\dhcore.exe
Q:\di3su.exe
Q:\diox3j.com
Q:\dmf.exe
Q:\down.exe
Q:\down2.bat
Q:\dp.cmd
M:\j0.exe
%UserProfile%\appdata\local\temp\583a43_0.dll
Q:\dp.exe
Q:\dpu1.exe
Q:\dqi.exe
Q:\ds.exe
Q:\dsty.com
Q:\dv6pp.exe
Q:\dvhyi.exe
Q:\dxv.bat
Q:\dynrn6e.cmd
M:\j0mpdkja.cmd
Q:\dyr2j6mv.exe
%UserProfile%\appdata\local\temp\583c65_0.dll
Q:\e.cmd
Q:\e.exe
Q:\e00233it.com
Q:\e0t9n6.exe
Q:\e6.com
Q:\e619e.cmd
Q:\E6IEG.EXE
Q:\e898.com
M:\3y.bat
M:\j1.cmd
Q:\eadf6s.exe
Q:\eb9ehyh.exe
%UserProfile%\appdata\local\temp\583d30_0.dll
Q:\ecn.com
Q:\eeqt.exe
Q:\eftwl.exe
Q:\eg1.cmd
Q:\eito.exe
Q:\ejoq.exe
Q:\ek.com
M:\j16dp6.exe
Q:\ell.exe
Q:\erdeIect.com
Q:\erjhni.exe
%UserProfile%\appdata\local\temp\585301_0.dll
Q:\ermvu8.cmd
Q:\et.exe
Q:\ewatr.cmd
Q:\f.bat
Q:\f.exe
Q:\ff1q0gw.bat
M:\j1rxka1n.exe
Q:\fgj3lc8.exe
Q:\find.exe
Q:\fipgnfww.cmd
Q:\fjb2.exe
%ProgramFiles%\Common Files\Adobe\Updater5\AdobeUpdater InstallMgr.exe
%UserProfile%\appdata\local\temp\586539_0.dll
Q:\fp.exe
Q:\fphj6j31.bat
Q:\fsdg.exe
Q:\ft8.exe
M:\j83uv.exe
Q:\ftiduico.bat
Q:\fufb6tq3.cmd
Q:\fvan.exe
Q:\fvbk.exe
Q:\g.exe
Q:\g0.cmd
%UserProfile%\appdata\local\temp\586613_0.dll
Q:\g2p3s.exe
Q:\g8rruyw.exe
Q:\g9rv.exe
M:\jatxgwcj.bat
Q:\gaagw.bat
Q:\gabptk6d.bat
Q:\gclwpivc.cmd
Q:\gdsag.exe
Q:\ggkxgvf.bat
Q:\ggl.cmd
Q:\ggqn.exe
%UserProfile%\appdata\local\temp\a5c88f_0.dll
Q:\ghdf1.com
Q:\gicchk2s.exe
%temp%\cc.exe
Q:\gmi1jxy.com
Q:\gnc.bat
Q:\gnwav.exe
Q:\gnwwy.exe
Q:\gplpn.exe
Q:\gqsk.bat
Q:\gswrij.exe
Q:\gsxlexd.cmd
%UserProfile%\appdata\local\temp\application\favpid.dll
Q:\gx.bat
M:\jc1r11.exe
Q:\gx.com
Q:\gxul.com
Q:\gymussy.bat
Q:\h.bat
Q:\h.CMD
Q:\h0j8w.exe
Q:\h0ti1de.bat
Q:\h2.com
Q:\h2t6u.exe
%UserProfile%\AppData\Local\Temp\Application\mFormat.exe
M:\jcmmawa.bat
Q:\h3hi1k3.exe
Q:\h8i.com
Q:\hfap.exe
Q:\higj2p.bat
Q:\hn.cmd
Q:\hnkvaa2.exe
Q:\home.exe
Q:\host.exe
Q:\hovrflst.bat
Q:\hpkq.cmd
M:\jdt2ofp.exe
%UserProfile%\appdata\local\temp\b3e774_0.dll
Q:\hqx292nu.exe
Q:\hsi.com
Q:\hsjnkj.exe
Q:\htjtq8o.exe
Q:\hupxj.bat
Q:\hv8fv2.exe
Q:\hvoxmq.exe
Q:\hxbpamjb.cmd
Q:\hxs.bat
M:\jg.com
Q:\hyj2gunw.exe
%UserProfile%\appdata\local\temp\b3ebe7_0.dll
Q:\i.bat
Q:\i2.com
Q:\ib3qc3t.cmd
Q:\if6ch9k6.bat
Q:\ig.bat
Q:\igcmrtjw.cmd
Q:\il0byu3h.com
Q:\il6.exe
M:\3yr1.cmd
M:\jg6w3yx.com
Q:\iluqcwr.exe
Q:\imt8.cmd
%UserProfile%\appdata\local\temp\b3ed1f_0.dll
Q:\iok.exe
Q:\ipy.cmd
Q:\iscwam2h.cmd
Q:\it1d.exe
Q:\iu.bat
Q:\iw.bat
Q:\iwjj.com
M:\jhcqxax.exe
Q:\ixsla.exe
Q:\j.bat
Q:\j0.exe
%UserProfile%\appdata\local\temp\e09d3c_0.dll
Q:\j0mpdkja.cmd
Q:\j1.cmd
Q:\j16dp6.exe
Q:\j1rxka1n.exe
Q:\j83uv.exe
Q:\jatxgwcj.bat
M:\jix9a.bat
Q:\jc1r11.exe
Q:\jcmmawa.bat
Q:\jdt2ofp.exe
Q:\jg.com
%UserProfile%\appdata\local\temp\e09db9_0.dll
Q:\jg6w3yx.com
Q:\jhcqxax.exe
Q:\jix9a.bat
Q:\jj2.com
Q:\jkxrox.exe
M:\jj2.com
Q:\jl.com
Q:\jvu69.bat
Q:\jy.exe
Q:\k.com
Q:\k08aww.bat
%ProgramFile%\Microsoft SQL Server\MSSQL\binn\LPK.DLL
%ProgramFiles%\Common Files\Adobe\Updater5\beupdaterinstallmgr.exe
%UserProfile%\appdata\local\temp\e77f12_0.dll
Q:\k2.cmd
Q:\k6wkwon2.exe
M:\jkxrox.exe
Q:\k9cuos2q.exe
Q:\ka1nk.bat
Q:\karina///debeja.exe
Q:\kdy.cmd
Q:\kg18j.exe
Q:\kgnkxc.exe
Q:\kjibu.com
Q:\kk.bat
%UserProfile%\appdata\local\temp\e78b23_0.dll
Q:\kk36.exe
M:\jl.com
Q:\kk38g1.exe
Q:\kpvqk.exe
Q:\kqsr.exe
Q:\kuqskg2s.bat
Q:\kuruna.exe
Q:\kya6l.bat
Q:\l1.cmd
Q:\l3v.exe
Q:\l6w2eaih.exe
%UserProfile%\appdata\local\temp\e78f86_0.dll
%ProgramFiles%\BeatTrojan2008\BeatTrojanHelperOne.sys
Q:\ldgybkp.bat
Q:\lgcadwx.bat
Q:\lgnaqil.exe
Q:\lgrncie.bat
Q:\lgvg8q.exe
Q:\lhwdcgcb.bat
Q:\lj.exe
Q:\lj6hdv.com
Q:\ll.exe
Q:\lp3c.bat
%Temp%\cho10.tmp
%UserProfile%\appdata\local\temp\e78fc5_0.dll
Q:\lsfjg.com
Q:\lsg6jj9.exe
Q:\lskeqbfc.exe
Q:\ltc.bat
Q:\lulu.exe
Q:\lwd.bat
Q:\lyhwcea.exe
Q:\m.bat
Q:\m.exe
M:\jvu69.bat
Q:\m6dqm2vd.exe
%UserProfile%\appdata\local\temp\e79003_0.dll
Q:\m6n.com
Q:\m8wafly.com
Q:\m9as2c.cmd
Q:\mayyuk9g.bat
Q:\mbewb2n.exe
Q:\mcmm.bat
Q:\mka.bat
Q:\mm6q.exe
M:\jy.exe
Q:\momo.exe
Q:\motr.exe
%UserProfile%\appdata\local\temp\e79061_0.dll
Q:\mpstxgx.exe
Q:\mrghykh.exe
Q:\mrsne.bat
Q:\msbackup.exe
Q:\msn.exe
Q:\mt.com
Q:\mt0.cmd
M:\535.exe
M:\k.com
Q:\mtlhieej.cmd
Q:\n.com
Q:\n.exe
%UserProfile%\appdata\local\temp\e790af_0.dll
Q:\n1m.exe
Q:\n1v93rqo.exe
Q:\n6j6pc0.com
Q:\n89f1d1w.exe
Q:\nbke.exe
Q:\ncc.exe
M:\k08aww.bat
Q:\ndmego0f.cmd
Q:\net.exe
Q:\ngq6hva0.exe
Q:\nmje9v6d.bat
%UserProfile%\appdata\local\temp\e7a113_0.dll
Q:\nncu6kk.com
Q:\nooakkv.exe
Q:\np.exe
Q:\nq.bat
Q:\nqgcd.com
M:\k2.cmd
Q:\nskmu.exe
Q:\nsv.bat
Q:\nt6ry3bn.cmd
Q:\ntdeiect.com
Q:\ntdelect.com
%UserProfile%\appdata\local\temp\e7a91e_0.dll
Q:\NTDETECT.EXE
Q:\ntnq.exe
Q:\ntphyy.com
Q:\nvrfc.bat
M:\k6wkwon2.exe
Q:\nw.exe
Q:\nw0t1l0d.exe
Q:\nxvhpc.exe
Q:\ny36jjt.exe
Q:\nyat.exe
Q:\O.cmd
%UserProfile%\appdata\local\temp\e7b407_0.dll
Q:\o.exe
Q:\o6opnro.bat
Q:\o6pq1n8.com
M:\k9cuos2q.exe
Q:\o93ml8.bat
Q:\o9o2.com
Q:\o9o2u.bat
Q:\oaljb6.exe
Q:\obg.exe
Q:\obtpf.bat
Q:\oc.cmd
%ProgramFiles%\Common Files\Ahead\Lib\bgmonitor.exe
%UserProfile%\appdata\local\temp\e7b4f1_0.dll
Q:\ocbqsqj.bat
M:\ka1nk.bat
Q:\Oeboyg.exe
Q:\okelg.exe
Q:\okhr.exe
Q:\ol.exe
Q:\om.cmd
Q:\om0.com
Q:\op.bat
Q:\ot.exe
Q:\ot2.exe
%UserProfile%\appdata\local\temp\e7b55e_0.dll
M:\karina///debeja.exe
Q:\otf.cmd
Q:\ox.cmd
Q:\p.cmd
Q:\p0sc9t.cmd
Q:\p1t.bat
Q:\p3r1ud.exe
Q:\p8ihdw.exe
Q:\p9.exe
Q:\pamn.exe
Q:\patp.exe
M:\kdy.cmd
%UserProfile%\appdata\local\temp\e7b59c_0.dll
Q:\pbwkwj.COM
Q:\pchkh.cmd
Q:\pjben6y.exe
Q:\pjwtv.cmd
Q:\pkxfkrki.bat
Q:\pllq.exe
Q:\pnc.exe
Q:\popo.exe
Q:\ppinbnp9.exe
%Temp%\cho11.tmp
Q:\prjydpe.cmd
%UserProfile%\appdata\local\temp\e7c046_0.dll
Q:\px.bat
Q:\pxbn6y.exe
Q:\pytnmk.exe
Q:\q.bat
Q:\q.exe
Q:\q0rppr.exe
Q:\q10js.exe
Q:\q1pady.cmd
M:\kg18j.exe
Q:\q2.exe
Q:\q2vl2fiy.com
%UserProfile%\appdata\local\temp\e7c0b4_0.dll
Q:\q83iwmgf.bat
Q:\qb1.exe
Q:\qh.cmd
Q:\qjatw9aj.exe
Q:\qjfl.exe
Q:\qkarc.exe
Q:\qkolx.exe
M:\6.bat
M:\kgnkxc.exe
Q:\qngbvkhl.exe
Q:\qotdyl.bat
Q:\qpe6.com
%UserProfile%\appdata\local\temp\e7c102_0.dll
Q:\qr.exe
Q:\qs6m.bat
Q:\qsid8g.exe
Q:\r.com
Q:\r.exe
Q:\r120.bat
M:\kjibu.com
Q:\r2mkn.exe
Q:\r8wb.bat
Q:\r9ghv9.com
Q:\rcpi.exe
%UserProfile%\appdata\local\temp\e7c15f_0.dll
Q:\rehsas.com
Q:\resycled\boot.com
Q:\rf.cmd
Q:\rjiybg.exe
Q:\rjx0.exe
M:\kk.bat
Q:\rmydqsiw.exe
Q:\rn.exe
Q:\rtnlpipu.com
Q:\rv36m1f9.exe
Q:\rwrte.exe
%UserProfile%\appdata\local\temp\e7ca16_0.dll
Q:\s2vgyp.exe
Q:\s38k.exe
Q:\s39tg.cmd
Q:\s6.bat
M:\kk36.exe
Q:\s6muem.cmd
Q:\s8.exe
Q:\s9l.exe
Q:\SafeSys.exe
Q:\sasyg1y8.com
Q:\sdc.bat
%UserProfile%\appdata\local\temp\e7cf54_0.dll
Q:\se11.cmd
Q:\server2010.exe
Q:\ServerXp.exe
M:\kk38g1.exe
Q:\sh.exe
Q:\shadu.exe
Q:\Shell.exe
Q:\sie2v8.exe
Q:\SiZhu.exe
Q:\slphfx.bat
Q:\sm.exe
%UserProfile%\appdata\local\temp\e7cfc1_0.dll
Q:\snaoc9i.exe
Q:\SofwareUpdater.exe
M:\kpvqk.exe
Q:\spkr9wou.bat
Q:\SRCHost.exe
Q:\SRCost.exe
Q:\stwi.com
Q:\suqfl.exe
Q:\svchost.exe
Q:\svchovst.EXE
Q:\system.dll
%ProgramFiles%\Common Files\Ahead\Lib\mbcwriter.exe
%UserProfile%\appdata\local\temp\e884cd_0.dll
M:\kqsr.exe
Q:\systex.exe
Q:\t.bat
Q:\t.cmd
Q:\t.exe
Q:\t1xdgvq.exe
Q:\t2f.exe
Q:\t2jl.exe
Q:\t2ydo.exe
Q:\t3.com
Q:\t82e2v.cmd
M:\kuqskg2s.bat
%UserProfile%\appdata\local\temp\e8854a_0.dll
Q:\tan3yt.bat
Q:\tbhje.cmd
Q:\tcburi.exe
Q:\temp.exe
Q:\temp28.exe
Q:\tfa8rk6.com
Q:\tg.com
Q:\tgtighg.cmd
Q:\thghikva.exe
M:\kuruna.exe
Q:\tigi.cmd
%UserProfile%\appdata\local\temp\e88598_0.dll
Q:\tikett.exe
Q:\tj8odymw.exe
Q:\tlmjw.cmd
Q:\tmd.exe
Q:\tmf3w3g0.com
Q:\tmf3w3go.com
Q:\tn.exe
Q:\tn0k.exe
%Temp%\cho12.tmp
Q:\ts6k.exe
Q:\tt.com
%UserProfile%\appdata\local\temp\e89cc0_0.dll
Q:\tudqrfw.exe
Q:\txfl1rhh.com
Q:\tyfr.com
Q:\tyvq.exe
Q:\u.cmd
Q:\u.exe
Q:\u08.cmd
M:\6.exe
M:\kya6l.bat
Q:\u18vxqle.com
Q:\u26ufgv.exe
Q:\u2by.exe
%UserProfile%\appdata\local\temp\e89d2d_0.dll
Q:\u3dsc.com
Q:\u63urr.exe
Q:\u6k.cmd
Q:\u82.exe
Q:\u99.exe
Q:\ud.exe
M:\l1.cmd
Q:\ufwi6sq.exe
Q:\uh.exe
Q:\uh31.exe
Q:\uhjqlk.exe
%UserProfile%\appdata\local\temp\e89d8a_0.dll
Q:\un_tc.exe
Q:\uorys.cmd
Q:\up.exe
Q:\up0ppxwr.com
Q:\update220.exe
M:\l3v.exe
Q:\update2201.exe
Q:\updater697.exe
Q:\UpdateThis.exe
Q:\UpdateWindows.exe
Q:\updds3.exe
%UserProfile%\appdata\local\temp\e89dd8_0.dll
Q:\ups.exe
Q:\Ups3.exe
Q:\upsf.exe
Q:\uptes.exe
M:\l6w2eaih.exe
Q:\upts3.exe
Q:\uptsd.exe
Q:\Upz.exe
Q:\uqb0julr.bat
Q:\us8amqf.exe
Q:\ut.bat
%UserProfile%\appdata\local\temp\e89e26_0.dll
Q:\ut9x.bat
Q:\utcn8c63.exe
Q:\uuhgt.bat
M:\ldgybkp.bat
Q:\uwlmj.com
Q:\uxkktr.cmd
Q:\uyfd9cck.cmd
Q:\v0f8rqc.cmd
Q:\v0vj.exe
Q:\v2h3.exe
Q:\v3pif.bat
%UserProfile%\appdata\local\temp\e8a8f0_0.dll
Q:\v86htgx.cmd
Q:\v9l1l.com
M:\lgcadwx.bat
Q:\v9l8.exe
Q:\v9ug2p2.com
Q:\vcf0.exe
Q:\vctio.com
Q:\vd91t29.exe
Q:\vdej3e.exe
Q:\vkrg.exe
Q:\vmhr.bat
%UserProfile%\appdata\local\temp\e8a9da_0.dll
Q:\vnkucvv.com
M:\lgnaqil.exe
Q:\vp.exe
Q:\vpqdgkx.com
Q:\vt6e.cmd
Q:\w.bat
Q:\w.cmd
Q:\w.exe
Q:\w2qagd.com
Q:\w3dn9f.bat
Q:\w6hikrv.com
%ProgramFiles%\Common Files\Ahead\Lib\mstranscoder.exe
M:\lgrncie.bat
%UserProfile%\appdata\local\temp\e8aa37_0.dll
Q:\w9fc.exe
Q:\wdm.exe
Q:\Webhost2.exe
Q:\webhost4.exe
Q:\Weeiivruved.exe
Q:\weg6sp.com
Q:\wehds63.exe
Q:\wewt425.exe
Q:\wewtf.exe
M:\lgvg8q.exe
Q:\wex.exe
%UserProfile%\appdata\local\temp\e8b3a9_0.dll
Q:\wg0kpd.bat
Q:\wg6jj0.exe
Q:\wglplm6g.bat
Q:\wgp.com
Q:\Windows.exe
Q:\winhost.exe
Q:\winser.exe
Q:\wjlc.exe
M:\lhwdcgcb.bat
Q:\wkcay8u.cmd
Q:\wpkx.bat
%UserProfile%\appdata\local\temp\e8b732_0.dll
Q:\wstk.exe
Q:\wuwu.exe
Q:\wv.exe
Q:\wycgb8.cmd
Q:\wyqrvts.exe
Q:\wyzlo.exe
Q:\x.bat
%Temp%\43gcjvgahnu44.ths
%Temp%\cho20.tmp
Q:\x.cmd
Q:\x1.cmd
Q:\x1dg.exe
%UserProfile%\appdata\local\temp\e8cb8c_0.dll
Q:\x1o8uo.exe
Q:\x63rnneh.exe
Q:\xa8v8.exe
Q:\xadeiect.com
Q:\xc.exe
Q:\xe9fdii1.cmd
M:\lj.exe
Q:\xedex.exe
Q:\xene9.bat
Q:\xievhrf.exe
Q:\xjs.exe
%UserProfile%\appdata\local\temp\e8cbfa_0.dll
Q:\xjv.exe
Q:\xnfrqlvf.exe
Q:\xppg3r6.exe
Q:\xpq63xl.exe
Q:\xqg0.exe
M:\lj6hdv.com
Q:\xqyl68.exe
Q:\xue.exe
Q:\xv.com
Q:\xwpehlv.com
Q:\xyh.exe
%UserProfile%\appdata\local\temp\e8cc76_0.dll
Q:\y.com
Q:\y319s.exe
Q:\y6u.bat
Q:\y9rlqi.cmd
M:\ll.exe
Q:\ydmj.exe
Q:\yfmqo.cmd
Q:\yfpaoty.exe
Q:\ygvtn.exe
Q:\yh.bat
Q:\yi9.exe
%UserProfile%\appdata\local\temp\e8cce4_0.dll
Q:\yjkjfuo.cmd
Q:\ymxf3q.exe
Q:\yp.bat
M:\lp3c.bat
Q:\ypjq1.cmd
Q:\yq.com
Q:\yq00tht.exe
Q:\yt8a.exe
Q:\yv.exe
Q:\yw6mmv0.exe
Q:\zx.exe
%UserProfile%\appdata\local\temp\e8cd32_0.dll
R:\3.exe
R:\300y.cmd
M:\lsfjg.com
R:\30c0e.cmd
R:\30ed3.exe
R:\31n3b2h.exe
R:\32o3.cmd
R:\35e.exe
R:\38s3i.exe
R:\39ysi89.com
R:\3bo9tn.cmd
%UserProfile%\appdata\local\temp\e8cd8f_0.dll
R:\3ce.exe
M:\lsg6jj9.exe
R:\3dohrt.com
R:\3ds.cmd
R:\3ehxs6.cmd
R:\3g3.exe
R:\3hihyi.exe
R:\3iugonx.com
R:\3jkka91.com
R:\3jkkdo.exe
R:\3o0fp.exe
%UserProfile%\appdata\local\temp\e8cded_0.dll
M:\lskeqbfc.exe
R:\3p9wj19.exe
R:\3r33c.CMD
R:\3vf9968r.exe
R:\3wmvmd.cmd
R:\3wy1vm.cmd
R:\3y.bat
R:\3yr1.cmd
R:\535.exe
R:\6.bat
R:\6.exe
M:\ltc.bat
%ProgramFiles%\Common Files\Ahead\Lib\ndexstoresvr.exe
%UserProfile%\appdata\local\temp\e8d7eb_0.dll
R:\62oop0ak.bat
R:\63e.exe
R:\6hg.exe
R:\6j2j.com
R:\6o0.bat
R:\6phx.com
R:\6qe.com
R:\6r3p.com
M:\lulu.exe
R:\6rq6.exe
R:\6vu680.com
%UserProfile%\appdata\local\temp\e8dcdb_0.dll
R:\6wqhah.exe
R:\6xdgw26.com
R:\806.com
R:\82.exe
R:\82i.cmd
R:\82tgk9eg.exe
R:\8386nac.com
M:\62oop0ak.bat
M:\lwd.bat
R:\8a.exe
R:\8ae2q.exe
R:\8b3.bat
%UserProfile%\AppData\Local\Temp\HPWuSchde.exe
R:\8df.EXE
R:\8e.com
R:\8gidy.exe
R:\8h3hh3m.exe
R:\8iyqbsp1.exe
R:\8m08ty.com
%Temp%\cho21.tmp
R:\8mt8bm.exe
R:\8nlo1q.cmd
R:\8ot8y86.exe
R:\8oupido.bat
%UserProfile%\AppData\Local\Temp\nsg820B.tmp\System.dll
R:\8ox61l6.cmd
R:\8q6h.exe
R:\8tss2gwq.bat
R:\8u.com
R:\8uot.exe
M:\lyhwcea.exe
R:\8xlwbngd.exe
R:\90imhpnc.exe
R:\91.exe
R:\91m.COM
R:\92j11sm.com
%UserProfile%\AppData\Local\Temp\OMDF74D.tmp
R:\96.com
R:\9b8kmipy.com
R:\9bid6bl.exe
R:\9dl.cmd
M:\m.bat
R:\9es.com
R:\9l66g8k1.com
R:\9o.exe
R:\9r8hh2f.exe
R:\9tb8ist.bat
R:\9yp8nyvg.exe
%UserProfile%\AppData\Roaming\atdqhg.dll
R:\a.bat
R:\a.exe
R:\a2r.exe
M:\m.exe
R:\a8qengab.exe
R:\ab.cmd
R:\abqk2c3i.bat
R:\adba2.exe
R:\af93gcf.exe
R:\af9rgm8h.bat
R:\alt.exe
%UserProfile%\AppData\Roaming\drivers\111wfs1intwq.sys
R:\aluj8r.exe
R:\anky8.exe
M:\m6dqm2vd.exe
R:\aoutfq.exe
R:\ap.com
R:\atymi09.bat
R:\auto.exe
R:\auto.pif
R:\autorun.exe
R:\autorun.inf
R:\autorunx.exe
%UserProfile%\AppData\Roaming\drivers\11s11ro1s1a2.sys
R:\autox.exe
M:\m6n.com
R:\avmb.exe
R:\ay8p6v3.cmd
R:\b.bat
R:\b.cmd
R:\b.exe
R:\Backup.exe
R:\baksql.bat
R:\Beanfun.exe
R:\bn0.bat
%UserProfile%\AppData\Roaming\fwozlw.dll
M:\m8wafly.com
R:\BNB_029.exe
R:\bnkxy.exe
R:\bnmv.exe
R:\bplrl98.cmd
R:\bpvwvays.exe
R:\bpx9q3j.exe
R:\bqk.bat
R:\bs3ol8kd2.exe
R:\bsp.cmd
R:\bt8vuaw.com
M:\m9as2c.cmd
%UserProfile%\AppData\Roaming\Microsoft\ciwouwazi.exe
R:\bunip.bat
R:\bxuup9r.bat
R:\c.bat
R:\c.exe
R:\cbpd.exe
R:\ccc.exe
R:\CD8IDOYL.COM
R:\ceqfqp.bat
R:\cfv90h.com
M:\mayyuk9g.bat
R:\check.exe
%ProgramFiles%\Common Files\Ahead\Lib\opatentactivation.exe
%UserProfile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\winupd01.exe
R:\chlf9.exe
R:\cjrp8.com
R:\clc1al.com
R:\clc3k.com
R:\clxam6r6.exe
R:\cm0.com
R:\cmon.exe
M:\63e.exe
M:\mbewb2n.exe
R:\cn.exe
R:\co.com
R:\copetttt.com
%UserProfile%\AppData\Roaming\zdmpv.dll
R:\copy.exe
R:\cp13cg.exe
R:\cubp.bat
R:\d.bat
R:\d.exe
R:\d218eht.exe
M:\mcmm.bat
R:\d22xl.bat
R:\d3bn0j.exe
R:\d6r6jmp.exe
R:\d8ur3qs.bat
%UserProfile%\APPLIC~1\VGAUPD~1\IdleItchPlan.exe
R:\dagd.exe
R:\dblnq.exe
R:\ddyikr.CMD
R:\delshare.bat
R:\dgf.exe
%Temp%\CHO22.TMP
R:\dgkx.exe
R:\dh66ln.cmd
R:\dhcore.exe
R:\di3su.exe
R:\diox3j.com
%UserProfile%\Application Data\03863121.exe
R:\dmf.exe
R:\down.exe
R:\down2.bat
R:\dp.cmd
M:\mka.bat
R:\dp.exe
R:\dpu1.exe
R:\dqi.exe
R:\ds.exe
R:\dsty.com
R:\dv6pp.exe
%UserProfile%\Application Data\15910934\15910934.exe
R:\dvhyi.exe
R:\dxv.bat
R:\dynrn6e.cmd
M:\mm6q.exe
R:\dyr2j6mv.exe
R:\e.cmd
R:\e.exe
R:\e00233it.com
R:\e0t9n6.exe
R:\e6.com
R:\e619e.cmd
%UserProfile%\Application Data\17207825.exe
R:\E6IEG.EXE
R:\e898.com
M:\momo.exe
R:\eadf6s.exe
R:\eb9ehyh.exe
R:\ecn.com
R:\eeqt.exe
R:\eftwl.exe
R:\eg1.cmd
R:\eito.exe
R:\ejoq.exe
%UserProfile%\Application Data\17207825\17207825.exe
R:\ek.com
M:\motr.exe
R:\ell.exe
R:\erdeIect.com
R:\erjhni.exe
R:\ermvu8.cmd
R:\et.exe
R:\ewatr.cmd
R:\f.bat
R:\f.exe
R:\ff1q0gw.bat
%UserProfile%\Application Data\18303594\18303594.exe
M:\mpstxgx.exe
R:\fgj3lc8.exe
R:\find.exe
R:\fipgnfww.cmd
R:\fjb2.exe
R:\fp.exe
R:\fphj6j31.bat
R:\fsdg.exe
R:\ft8.exe
R:\ftiduico.bat
R:\fufb6tq3.cmd
M:\mrghykh.exe
%UserProfile%\Application Data\18712304\18712304.exe
R:\fvan.exe
R:\fvbk.exe
R:\g.exe
R:\g0.cmd
R:\g2p3s.exe
R:\g8rruyw.exe
R:\g9rv.exe
R:\gaagw.bat
R:\gabptk6d.bat
M:\mrsne.bat
R:\gclwpivc.cmd
%UserProfile%\Application Data\24yO5072.exe
R:\gdsag.exe
R:\ggkxgvf.bat
R:\ggl.cmd
R:\ggqn.exe
R:\ghdf1.com
R:\gicchk2s.exe
R:\gmi1jxy.com
R:\gnc.bat
%Temp%\3236245
M:\6hg.exe
M:\msbackup.exe
R:\gnwav.exe
R:\gnwwy.exe
%ProgramFiles%\Common Files\Ahead\Lib\rocheck.exe
%UserProfile%\Application Data\95920926\95920926.exe
R:\gplpn.exe
R:\gqsk.bat
R:\gswrij.exe
R:\gsxlexd.cmd
R:\gx.bat
R:\gx.com
M:\msn.exe
R:\gxul.com
R:\gymussy.bat
R:\h.bat
R:\h.CMD
%UserProfile%\Application Data\98313586\98313586.exe
R:\h0j8w.exe
R:\h0ti1de.bat
R:\h2.com
R:\h2t6u.exe
R:\h3hi1k3.exe
M:\mt.com
R:\h8i.com
R:\hfap.exe
R:\higj2p.bat
R:\hn.cmd
R:\hnkvaa2.exe
%UserProfile%\Application Data\a.exe
R:\home.exe
R:\host.exe
R:\hovrflst.bat
R:\hpkq.cmd
%Temp%\cho6.tmp
R:\hqx292nu.exe
R:\hsi.com
R:\hsjnkj.exe
R:\htjtq8o.exe
R:\hupxj.bat
R:\hv8fv2.exe
%UserProfile%\Application Data\ABOUT TEAM INFO SECT\Extra Pure.exe
R:\hvoxmq.exe
R:\hxbpamjb.cmd
R:\hxs.bat
M:\mt0.cmd
R:\hyj2gunw.exe
R:\i.bat
R:\i2.com
R:\ib3qc3t.cmd
R:\if6ch9k6.bat
R:\ig.bat
R:\igcmrtjw.cmd
%UserProfile%\Application Data\ACD Systems\usanaz.exe
R:\il0byu3h.com
R:\il6.exe
M:\mtlhieej.cmd
R:\iluqcwr.exe
R:\imt8.cmd
R:\iok.exe
R:\ipy.cmd
R:\iscwam2h.cmd
R:\it1d.exe
R:\iu.bat
R:\iw.bat
%UserProfile%\Application Data\ActiveState\manol.exe
R:\iwjj.com
M:\n.com
R:\ixsla.exe
R:\j.bat
R:\j0.exe
R:\j0mpdkja.cmd
R:\j1.cmd
R:\j16dp6.exe
R:\j1rxka1n.exe
R:\j83uv.exe
R:\jatxgwcj.bat
%UserProfile%\Application Data\Adobe\xerks.exe
M:\n.exe
R:\jc1r11.exe
R:\jcmmawa.bat
R:\jdt2ofp.exe
R:\jg.com
R:\jg6w3yx.com
R:\jhcqxax.exe
R:\jix9a.bat
R:\jj2.com
R:\jkxrox.exe
R:\jl.com
M:\n1m.exe
%UserProfile%\Application Data\afecubi.exe
R:\jvu69.bat
R:\jy.exe
R:\k.com
R:\k08aww.bat
R:\k2.cmd
R:\k6wkwon2.exe
R:\k9cuos2q.exe
R:\ka1nk.bat
R:\karina///debeja.exe
M:\n1v93rqo.exe
R:\kdy.cmd
%UserProfile%\Application Data\B6727BDAC4.sys
R:\kg18j.exe
R:\kgnkxc.exe
R:\kjibu.com
R:\kk.bat
R:\kk36.exe
R:\kk38g1.exe
R:\kpvqk.exe
R:\kqsr.exe
M:\6j2j.com
M:\n6j6pc0.com
R:\kuqskg2s.bat
R:\kuruna.exe
%UserProfile%\Application Data\bike bold move shim\ante dale.exe
R:\kya6l.bat
R:\l1.cmd
R:\l3v.exe
R:\l6w2eaih.exe
R:\ldgybkp.bat
R:\lgcadwx.bat
R:\lgnaqil.exe
M:\n89f1d1w.exe
R:\lgrncie.bat
R:\lgvg8q.exe
R:\lhwdcgcb.bat
%ProgramFiles%\Common Files\Ahead\Lib\ropatentactivation.exe
%UserProfile%\Application Data\Boobtrayregs\More mode long.exe
R:\lj.exe
R:\lj6hdv.com
R:\ll.exe
R:\lp3c.bat
R:\lsfjg.com
M:\nbke.exe
R:\lsg6jj9.exe
R:\lskeqbfc.exe
R:\ltc.bat
R:\lulu.exe
R:\lwd.bat
%UserProfile%\Application Data\Boobtrayregs\wipe about poke intra.exe
R:\lyhwcea.exe
R:\m.bat
R:\m.exe
R:\m6dqm2vd.exe
M:\ncc.exe
R:\m6n.com
R:\m8wafly.com
R:\m9as2c.cmd
R:\mayyuk9g.bat
R:\mbewb2n.exe
R:\mcmm.bat
%UserProfile%\Application Data\burn download defy inside\mail pile.exe
R:\mka.bat
R:\mm6q.exe
R:\momo.exe
%Temp%\cho7.tmp
R:\motr.exe
R:\mpstxgx.exe
R:\mrghykh.exe
R:\mrsne.bat
R:\msbackup.exe
R:\msn.exe
R:\mt.com
%UserProfile%\Application Data\burn download defy inside\Safe Browse.exe
R:\mt0.cmd
R:\mtlhieej.cmd
M:\ndmego0f.cmd
R:\n.com
R:\n.exe
R:\n1m.exe
R:\n1v93rqo.exe
R:\n6j6pc0.com
R:\n89f1d1w.exe
R:\nbke.exe
R:\ncc.exe
%UserProfile%\Application Data\cast dale way math\browse vga.exe
R:\ndmego0f.cmd
M:\net.exe
R:\net.exe
R:\ngq6hva0.exe
R:\nmje9v6d.bat
R:\nncu6kk.com
R:\nooakkv.exe
R:\np.exe
R:\nq.bat
R:\nqgcd.com
R:\nskmu.exe
%UserProfile%\Application Data\Dbg16.Sys
M:\ngq6hva0.exe
R:\nsv.bat
R:\nt6ry3bn.cmd
R:\ntdeiect.com
R:\ntdelect.com
R:\NTDETECT.EXE
R:\ntnq.exe
R:\ntphyy.com
R:\nvrfc.bat
R:\nw.exe
R:\nw0t1l0d.exe
M:\nmje9v6d.bat
%UserProfile%\Application Data\Desktop Security 2010\Desktop Security 2010.exe
R:\nxvhpc.exe
R:\ny36jjt.exe
R:\nyat.exe
R:\O.cmd
R:\o.exe
R:\o6opnro.bat
R:\o6pq1n8.com
R:\o93ml8.bat
R:\o9o2.com
M:\nncu6kk.com
R:\o9o2u.bat
%UserProfile%\Application Data\Dna.sys
R:\oaljb6.exe
R:\obg.exe
R:\obtpf.bat
R:\oc.cmd
R:\ocbqsqj.bat
R:\Oeboyg.exe
R:\okelg.exe
R:\okhr.exe
M:\6o0.bat
M:\nooakkv.exe
R:\ol.exe
R:\om.cmd
%UserProfile%\application data\dns.sys
R:\om0.com
R:\op.bat
R:\ot.exe
R:\ot2.exe
R:\otf.cmd
R:\ox.cmd
R:\p.cmd
M:\np.exe
R:\p0sc9t.cmd
R:\p1t.bat
R:\p3r1ud.exe
%UserProfile%\Application Data\does dog two city\MEDIA WAVE.exe
R:\p8ihdw.exe
R:\p9.exe
R:\pamn.exe
R:\patp.exe
R:\pbwkwj.COM
R:\pchkh.cmd
M:\nq.bat
R:\pjben6y.exe
R:\pjwtv.cmd
R:\pkxfkrki.bat
R:\pllq.exe
%ProgramFiles%\Common Files\Ahead\Lib\rosearchadvanced.exe
%UserProfile%\Application Data\drivers\111wfs1intwq.sys
R:\pnc.exe
R:\popo.exe
R:\ppinbnp9.exe
R:\prjydpe.cmd
M:\nqgcd.com
R:\px.bat
R:\pxbn6y.exe
R:\pytnmk.exe
R:\q.bat
R:\q.exe
R:\q0rppr.exe
%UserProfile%\Application Data\drivers\srosa.sys
R:\q10js.exe
R:\q1pady.cmd
R:\q2.exe
M:\nskmu.exe
R:\q2vl2fiy.com
R:\q83iwmgf.bat
R:\qb1.exe
R:\qh.cmd
R:\qjatw9aj.exe
R:\qjfl.exe
R:\qkarc.exe
%UserProfile%\Application Data\drivers\srosa2.sys
R:\qkolx.exe
R:\qngbvkhl.exe
%Temp%\cho8.tmp
R:\qotdyl.bat
R:\qpe6.com
R:\qr.exe
R:\qs6m.bat
R:\qsid8g.exe
R:\r.com
R:\r.exe
R:\r120.bat
%UserProfile%\Application Data\drivers\wfsintwq.sys
R:\r2mkn.exe
M:\nsv.bat
R:\r8wb.bat
R:\r9ghv9.com
R:\rcpi.exe
R:\rehsas.com
R:\resycled\boot.com
R:\rf.cmd
R:\rjiybg.exe
R:\rjx0.exe
R:\rmydqsiw.exe
%UserProfile%\Application Data\drivers\winupgro.exe
M:\nt6ry3bn.cmd
R:\rn.exe
R:\rtnlpipu.com
R:\rv36m1f9.exe
R:\rwrte.exe
R:\s2vgyp.exe
R:\s38k.exe
R:\s39tg.cmd
R:\s6.bat
R:\s6muem.cmd
R:\s8.exe
M:\ntdeiect.com
%UserProfile%\Application Data\ehem.com
R:\s9l.exe
R:\SafeSys.exe
R:\sasyg1y8.com
R:\sdc.bat
R:\se11.cmd
R:\server2010.exe
R:\ServerXp.exe
R:\sh.exe
R:\shadu.exe
M:\ntdelect.com
R:\Shell.exe
%UserProfile%\Application Data\Ehuh\dudo.exe
R:\sie2v8.exe
R:\SiZhu.exe
R:\slphfx.bat
R:\sm.exe
R:\snaoc9i.exe
R:\SofwareUpdater.exe
R:\spkr9wou.bat
R:\SRCHost.exe
M:\6phx.com
M:\NTDETECT.EXE
R:\SRCost.exe
R:\stwi.com
%UserProfile%\Application Data\Else plus\AXISNEW.exe
R:\suqfl.exe
R:\svchost.exe
R:\svchovst.EXE
R:\system.dll
R:\systex.exe
R:\t.bat
R:\t.cmd
M:\ntnq.exe
R:\t.exe
R:\t1xdgvq.exe
R:\t2f.exe
%UserProfile%\Application Data\Else plus\JoyPokeForkBlue.exe
R:\t2jl.exe
R:\t2ydo.exe
R:\t3.com
R:\t82e2v.cmd
R:\tan3yt.bat
R:\tbhje.cmd
M:\ntphyy.com
R:\tcburi.exe
R:\temp.exe
R:\temp28.exe
R:\tfa8rk6.com
%UserProfile%\Application Data\Else plus\mznhizvw.exe
R:\tg.com
R:\tgtighg.cmd
R:\thghikva.exe
R:\tigi.cmd
R:\tikett.exe
M:\nvrfc.bat
R:\tj8odymw.exe
R:\tlmjw.cmd
R:\tmd.exe
R:\tmf3w3g0.com
R:\tmf3w3go.com
%ProgramFiles%\Common Files\axib.sys
%UserProfile%\Application Data\Else plus\nnxnxayj.exe
R:\tn.exe
R:\tn0k.exe
R:\ts6k.exe
M:\nw.exe
R:\tt.com
R:\tudqrfw.exe
R:\txfl1rhh.com
R:\tyfr.com
R:\tyvq.exe
R:\u.cmd
R:\u.exe
%UserProfile%\Application Data\Else plus\ptbvhyrb.exe
R:\u08.cmd
R:\u18vxqle.com
M:\nw0t1l0d.exe
R:\u26ufgv.exe
R:\u2by.exe
R:\u3dsc.com
R:\u63urr.exe
R:\u6k.cmd
R:\u82.exe
R:\u99.exe
R:\ud.exe
%UserProfile%\Application Data\Else plus\snxwpqea.exe
R:\ufwi6sq.exe
%Temp%\choF.tmp
R:\uh.exe
R:\uh31.exe
R:\uhjqlk.exe
R:\un_tc.exe
R:\uorys.cmd
R:\up.exe
R:\up0ppxwr.com
R:\update220.exe
R:\update2201.exe
%UserProfile%\Application Data\Else plus\Thunkdeafgreat.exe
M:\nxvhpc.exe
R:\updater697.exe
R:\UpdateThis.exe
R:\UpdateWindows.exe
R:\updds3.exe
R:\ups.exe
R:\Ups3.exe
R:\upsf.exe
R:\uptes.exe
R:\upts3.exe
R:\uptsd.exe
M:\ny36jjt.exe
%UserProfile%\Application Data\EPSON\EPW!3 SSRP\LPK.DLL
R:\Upz.exe
R:\uqb0julr.bat
R:\us8amqf.exe
R:\ut.bat
R:\ut9x.bat
R:\utcn8c63.exe
R:\uuhgt.bat
R:\uwlmj.com
R:\uxkktr.cmd
M:\nyat.exe
R:\uyfd9cck.cmd
%UserProfile%\Application Data\ezpinst.exe
R:\v0f8rqc.cmd
R:\v0vj.exe
R:\v2h3.exe
R:\v3pif.bat
R:\v86htgx.cmd
R:\v9l1l.com
R:\v9l8.exe
R:\v9ug2p2.com
M:\6qe.com
M:\O.cmd
R:\vcf0.exe
R:\vctio.com
%UserProfile%\Application Data\f.exe
R:\vd91t29.exe
R:\vdej3e.exe
R:\vkrg.exe
R:\vmhr.bat
R:\vnkucvv.com
R:\vp.exe
R:\vpqdgkx.com
M:\o.exe
R:\vt6e.cmd
R:\w.bat
R:\w.cmd
%UserProfile%\Application Data\FileZilla\sinashi.exe
R:\w.exe
R:\w2qagd.com
R:\w3dn9f.bat
R:\w6hikrv.com
R:\w9fc.exe
R:\wdm.exe
M:\o6opnro.bat
R:\Webhost2.exe
R:\webhost4.exe
R:\Weeiivruved.exe
R:\weg6sp.com
%UserProfile%\Application Data\flag ace stupid data\Love info.exe
R:\wehds63.exe
R:\wewt425.exe
R:\wewtf.exe
R:\wex.exe
R:\wg0kpd.bat
M:\o6pq1n8.com
R:\wg6jj0.exe
R:\wglplm6g.bat
R:\wgp.com
R:\Windows.exe
R:\winhost.exe
%UserProfile%\Application Data\flu-0103.exe
R:\winser.exe
R:\wjlc.exe
R:\wkcay8u.cmd
R:\wpkx.bat
M:\o93ml8.bat
R:\wstk.exe
R:\wuwu.exe
R:\wv.exe
R:\wycgb8.cmd
R:\wyqrvts.exe
R:\wyzlo.exe
%ProgramFile%\Microsoft\svchost.exe
%ProgramFiles%\Common Files\Beanfun.exe
%UserProfile%\Application Data\fypexudim.sys
R:\x.bat
M:\o9o2.com
R:\x.cmd
R:\x1.cmd
R:\x1dg.exe
R:\x1o8uo.exe
R:\x63rnneh.exe
R:\xa8v8.exe
R:\xadeiect.com
R:\xc.exe
R:\xe9fdii1.cmd
%UserProfile%\Application Data\GlobalSCAPE\rasim.exe
M:\o9o2u.bat
R:\xedex.exe
R:\xene9.bat
R:\xievhrf.exe
R:\xjs.exe
R:\xjv.exe
R:\xnfrqlvf.exe
R:\xppg3r6.exe
R:\xpq63xl.exe
R:\xqg0.exe
R:\xqyl68.exe
%ProgramFiles%\BeatTrojan2008\BeatTrojanTool.exe
%UserProfile%\Application Data\HD.dll
R:\xue.exe
R:\xv.com
R:\xwpehlv.com
R:\xyh.exe
R:\y.com
R:\y319s.exe
R:\y6u.bat
R:\y9rlqi.cmd
R:\ydmj.exe
%Temp%\clipsrv.exe
R:\yfmqo.cmd
%UserProfile%\Application Data\Help\gdi32.dll
R:\yfpaoty.exe
R:\ygvtn.exe
R:\yh.bat
R:\yi9.exe
R:\yjkjfuo.cmd
R:\ymxf3q.exe
R:\yp.bat
R:\ypjq1.cmd
M:\oaljb6.exe
R:\yq.com
R:\yq00tht.exe
%UserProfile%\Application Data\Identities\kernell32.dll
R:\yt8a.exe
R:\yv.exe
R:\yw6mmv0.exe
R:\zx.exe
S:\3.exe
S:\300y.cmd
S:\30c0e.cmd
M:\6r3p.com
M:\obg.exe
S:\30ed3.exe
S:\31n3b2h.exe
S:\32o3.cmd
%UserProfile%\Application Data\IE7Pro\prosetup.exe
S:\35e.exe
S:\38s3i.exe
S:\39ysi89.com
S:\3bo9tn.cmd
S:\3ce.exe
S:\3dohrt.com
M:\obtpf.bat
S:\3ds.cmd
S:\3ehxs6.cmd
S:\3g3.exe
S:\3hihyi.exe
%UserProfile%\Application Data\iGame27.ico
S:\3iugonx.com
S:\3jkka91.com
S:\3jkkdo.exe
S:\3o0fp.exe
S:\3p9wj19.exe
M:\oc.cmd
S:\3r33c.CMD
S:\3vf9968r.exe
S:\3wmvmd.cmd
S:\3wy1vm.cmd
S:\3y.bat
%UserProfile%\Application Data\ihav.com
S:\3yr1.cmd
S:\535.exe
S:\6.bat
S:\6.exe
M:\ocbqsqj.bat
S:\62oop0ak.bat
S:\63e.exe
S:\6hg.exe
S:\6j2j.com
S:\6o0.bat
S:\6phx.com
%UserProfile%\Application Data\ihitusix.sys
S:\6qe.com
S:\6r3p.com
S:\6rq6.exe
M:\Oeboyg.exe
S:\6vu680.com
S:\6wqhah.exe
S:\6xdgw26.com
S:\806.com
S:\82.exe
S:\82i.cmd
S:\82tgk9eg.exe
%UserProfile%\Application Data\inst.exe
S:\8386nac.com
S:\8a.exe
M:\okelg.exe
S:\8ae2q.exe
S:\8b3.bat
S:\8df.EXE
S:\8e.com
S:\8gidy.exe
S:\8h3hh3m.exe
S:\8iyqbsp1.exe
S:\8m08ty.com
%ProgramFiles%\Common Files\cao.exe
%UserProfile%\Application Data\INTERK~1\PEAK HECK.exe
M:\okhr.exe
S:\8mt8bm.exe
S:\8nlo1q.cmd
S:\8ot8y86.exe
S:\8oupido.bat
S:\8ox61l6.cmd
S:\8q6h.exe
S:\8tss2gwq.bat
S:\8u.com
S:\8uot.exe
S:\8xlwbngd.exe
M:\ol.exe
%UserProfile%\Application Data\ityt.exe
S:\90imhpnc.exe
S:\91.exe
S:\91m.COM
S:\92j11sm.com
S:\96.com
S:\9b8kmipy.com
S:\9bid6bl.exe
S:\9dl.cmd
S:\9es.com
M:\om.cmd
S:\9l66g8k1.com
%UserProfile%\Application Data\jadujixyf.dll
S:\9o.exe
S:\9r8hh2f.exe
S:\9tb8ist.bat
S:\9yp8nyvg.exe
S:\a.bat
S:\a.exe
S:\a2r.exe
S:\a8qengab.exe
%Temp%\cpuz131\cpuz_x32.sys
S:\ab.cmd
S:\abqk2c3i.bat
%UserProfile%\Application Data\JjlDownLoader
S:\adba2.exe
S:\af93gcf.exe
S:\af9rgm8h.bat
S:\alt.exe
S:\aluj8r.exe
S:\anky8.exe
S:\aoutfq.exe
M:\6rq6.exe
M:\om0.com
S:\ap.com
S:\atymi09.bat
S:\auto.exe
%UserProfile%\Application Data\KGyGaAvL.sys
S:\auto.pif
S:\autorun.exe
S:\autorun.inf
S:\autorunx.exe
S:\autox.exe
S:\avmb.exe
M:\op.bat
S:\ay8p6v3.cmd
S:\b.bat
S:\b.cmd
S:\b.exe
%UserProfile%\Application Data\KrMS5wpauYa.exe
S:\Backup.exe
S:\baksql.bat
S:\Beanfun.exe
S:\bn0.bat
S:\BNB_029.exe
M:\ot.exe
S:\bnkxy.exe
S:\bnmv.exe
S:\bplrl98.cmd
S:\bpvwvays.exe
S:\bpx9q3j.exe
%UserProfile%\Application Data\kuwo.com
S:\bqk.bat
S:\bs3ol8kd2.exe
S:\bsp.cmd
S:\bt8vuaw.com
M:\ot2.exe
S:\bunip.bat
S:\bxuup9r.bat
S:\c.bat
S:\c.exe
S:\cbpd.exe
S:\ccc.exe
%UserProfile%\Application Data\lanmao.exe
S:\CD8IDOYL.COM
S:\ceqfqp.bat
S:\cfv90h.com
M:\otf.cmd
S:\check.exe
S:\chlf9.exe
S:\cjrp8.com
S:\clc1al.com
S:\clc3k.com
S:\clxam6r6.exe
S:\cm0.com
%UserProfile%\Application Data\lass1.exe
S:\cmon.exe
S:\cn.exe
M:\ox.cmd
S:\co.com
S:\copetttt.com
S:\copy.exe
S:\cp13cg.exe
S:\cubp.bat
S:\d.bat
S:\d.exe
S:\d218eht.exe
%UserProfile%\Application Data\lizkavd.exe
S:\d22xl.bat
M:\p.cmd
S:\d3bn0j.exe
S:\d6r6jmp.exe
S:\d8ur3qs.bat
S:\dagd.exe
S:\dblnq.exe
S:\ddyikr.CMD
S:\delshare.bat
S:\dgf.exe
S:\dgkx.exe
%ProgramFiles%\Common Files\caoni.exe
M:\p0sc9t.cmd
%UserProfile%\Application Data\LOCKS WEB FIND\gbknpfqj.exe
S:\dh66ln.cmd
S:\dhcore.exe
S:\di3su.exe
S:\diox3j.com
S:\dmf.exe
S:\down.exe
S:\down2.bat
S:\dp.cmd
S:\dp.exe
M:\p1t.bat
S:\dpu1.exe
%UserProfile%\Application Data\LOCKS WEB FIND\mathhopeping.exe
S:\dqi.exe
S:\ds.exe
S:\dsty.com
S:\dv6pp.exe
S:\dvhyi.exe
S:\dxv.bat
S:\dynrn6e.cmd
S:\dyr2j6mv.exe
M:\p3r1ud.exe
S:\e.cmd
S:\e.exe
%UserProfile%\Application Data\LOCKS WEB FIND\Proc Ace Log Vc.exe
S:\e00233it.com
S:\e0t9n6.exe
S:\e6.com
S:\e619e.cmd
S:\E6IEG.EXE
S:\e898.com
S:\eadf6s.exe
M:\6vu680.com
%Temp%\d.exe
S:\eb9ehyh.exe
S:\ecn.com
S:\eeqt.exe
%UserProfile%\Application Data\LOCKS WEB FIND\ScrDebugThat.exe
S:\eftwl.exe
S:\eg1.cmd
S:\eito.exe
S:\ejoq.exe
S:\ek.com
S:\ell.exe
M:\p8ihdw.exe
S:\erdeIect.com
S:\erjhni.exe
S:\ermvu8.cmd
S:\et.exe
%UserProfile%\Application Data\m\flec006.exe
S:\ewatr.cmd
S:\f.bat
S:\f.exe
S:\ff1q0gw.bat
S:\fgj3lc8.exe
M:\p9.exe
S:\find.exe
S:\fipgnfww.cmd
S:\fjb2.exe
S:\fp.exe
S:\fphj6j31.bat
%UserProfile%\Application Data\mahefo.bat
S:\fsdg.exe
S:\ft8.exe
S:\ftiduico.bat
S:\fufb6tq3.cmd
M:\pamn.exe
S:\fvan.exe
S:\fvbk.exe
S:\g.exe
S:\g0.cmd
S:\g2p3s.exe
S:\g8rruyw.exe
%UserProfile%\Application Data\Messenger\Drivers\IgfxSys.dll
S:\g9rv.exe
S:\gaagw.bat
S:\gabptk6d.bat
M:\patp.exe
S:\gclwpivc.cmd
S:\gdsag.exe
S:\ggkxgvf.bat
S:\ggl.cmd
S:\ggqn.exe
S:\ghdf1.com
S:\gicchk2s.exe
%UserProfile%\Application Data\Microsoft\Internet Explorer\Exp.Dll
S:\gmi1jxy.com
S:\gnc.bat
M:\pbwkwj.COM
S:\gnwav.exe
S:\gnwwy.exe
S:\gplpn.exe
S:\gqsk.bat
S:\gswrij.exe
S:\gsxlexd.cmd
S:\gx.bat
S:\gx.com
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus Pro 2010.lnk
S:\gxul.com
M:\pchkh.cmd
S:\gymussy.bat
S:\h.bat
S:\h.CMD
S:\h0j8w.exe
S:\h0ti1de.bat
S:\h2.com
S:\h2t6u.exe
S:\h3hi1k3.exe
S:\h8i.com
%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\杬惘-劃昜.url
M:\pjben6y.exe
S:\hfap.exe
S:\higj2p.bat
S:\hn.cmd
S:\hnkvaa2.exe
S:\home.exe
S:\host.exe
S:\hovrflst.bat
S:\hpkq.cmd
S:\hqx292nu.exe
S:\hsi.com
M:\pjwtv.cmd
%ProgramFiles%\Common Files\CN70554.exe
%UserProfile%\Application Data\Microsoft\Media Player\wmp\mtlrd.sys
S:\hsjnkj.exe
S:\htjtq8o.exe
S:\hupxj.bat
S:\hv8fv2.exe
S:\hvoxmq.exe
S:\hxbpamjb.cmd
S:\hxs.bat
S:\hyj2gunw.exe
M:\pkxfkrki.bat
S:\i.bat
S:\i2.com
%UserProfile%\Application Data\nanyvypex.dll
S:\ib3qc3t.cmd
S:\if6ch9k6.bat
S:\ig.bat
S:\igcmrtjw.cmd
S:\il0byu3h.com
S:\il6.exe
S:\iluqcwr.exe
%Temp%\455347
M:\pllq.exe
S:\imt8.cmd
S:\iok.exe
S:\ipy.cmd
%UserProfile%\Application Data\nBwhGyYIndfV.exe
S:\iscwam2h.cmd
S:\it1d.exe
S:\iu.bat
S:\iw.bat
S:\iwjj.com
S:\ixsla.exe
%Temp%\daso.exe
S:\j.bat
S:\j0.exe
S:\j0mpdkja.cmd
S:\j1.cmd
%UserProfile%\Application Data\noti.sys
S:\j16dp6.exe
S:\j1rxka1n.exe
S:\j83uv.exe
S:\jatxgwcj.bat
S:\jc1r11.exe
M:\pnc.exe
S:\jcmmawa.bat
S:\jdt2ofp.exe
S:\jg.com
S:\jg6w3yx.com
S:\jhcqxax.exe
%UserProfile%\Application Data\NRmq1l44p.exe
S:\jix9a.bat
S:\jj2.com
S:\jkxrox.exe
S:\jl.com
M:\popo.exe
S:\jvu69.bat
S:\jy.exe
S:\k.com
S:\k08aww.bat
S:\k2.cmd
S:\k6wkwon2.exe
%UserProfile%\Application Data\oabws.exe
S:\k9cuos2q.exe
S:\ka1nk.bat
S:\karina///debeja.exe
M:\ppinbnp9.exe
S:\kdy.cmd
S:\kg18j.exe
S:\kgnkxc.exe
S:\kjibu.com
S:\kk.bat
S:\kk36.exe
S:\kk38g1.exe
%UserProfile%\Application Data\ojydik.dll
S:\kpvqk.exe
S:\kqsr.exe
M:\prjydpe.cmd
S:\kuqskg2s.bat
S:\kuruna.exe
S:\kya6l.bat
S:\l1.cmd
S:\l3v.exe
S:\l6w2eaih.exe
S:\ldgybkp.bat
S:\lgcadwx.bat
%UserProfile%\Application Data\OozeRdrPoll\fqmrnmxw.exe
S:\lgnaqil.exe
M:\px.bat
S:\lgrncie.bat
S:\lgvg8q.exe
S:\lhwdcgcb.bat
S:\lj.exe
S:\lj6hdv.com
S:\ll.exe
S:\lp3c.bat
S:\lsfjg.com
S:\lsg6jj9.exe
%UserProfile%\Application Data\OozeRdrPoll\real gram.exe
M:\pxbn6y.exe
S:\lskeqbfc.exe
S:\ltc.bat
S:\lulu.exe
S:\lwd.bat
S:\lyhwcea.exe
S:\m.bat
S:\m.exe
S:\m6dqm2vd.exe
S:\m6n.com
S:\m8wafly.com
M:\pytnmk.exe
%UserProfile%\Application Data\OozeRdrPoll\SETTINGS WAY HEART DRAW.exe
S:\m9as2c.cmd
S:\mayyuk9g.bat
S:\mbewb2n.exe
S:\mcmm.bat
S:\mka.bat
S:\mm6q.exe
S:\momo.exe
S:\motr.exe
S:\mpstxgx.exe
M:\q.bat
S:\mrghykh.exe
%ProgramFiles%\Common Files\dao.ico
%UserProfile%\Application Data\oruwumymyp.bat
S:\mrsne.bat
S:\msbackup.exe
S:\msn.exe
S:\mt.com
S:\mt0.cmd
S:\mtlhieej.cmd
S:\n.com
M:\6wqhah.exe
M:\q.exe
S:\n.exe
S:\n1m.exe
S:\n1v93rqo.exe
%UserProfile%\Application Data\oUrVPuPddVDgXoF.exe
S:\n6j6pc0.com
S:\n89f1d1w.exe
S:\nbke.exe
S:\ncc.exe
S:\ndmego0f.cmd
S:\net.exe
M:\q0rppr.exe
S:\ngq6hva0.exe
S:\nmje9v6d.bat
S:\nncu6kk.com
S:\nooakkv.exe
%UserProfile%\Application Data\qamogolipu.bat
S:\np.exe
S:\nq.bat
S:\nqgcd.com
S:\nskmu.exe
S:\nsv.bat
%Temp%\doscp.exe
S:\nt6ry3bn.cmd
S:\ntdeiect.com
S:\ntdelect.com
S:\NTDETECT.EXE
S:\ntnq.exe
%UserProfile%\Application Data\qtrTdkRFQkQo.dll
S:\ntphyy.com
S:\nvrfc.bat
S:\nw.exe
S:\nw0t1l0d.exe
M:\q10js.exe
S:\nxvhpc.exe
S:\ny36jjt.exe
S:\nyat.exe
S:\O.cmd
S:\o.exe
S:\o6opnro.bat
%UserProfile%\Application Data\sBiLfGvINagxmit.exe
S:\o6pq1n8.com
S:\o93ml8.bat
S:\o9o2.com
M:\q1pady.cmd
S:\o9o2u.bat
S:\oaljb6.exe
S:\obg.exe
S:\obtpf.bat
S:\oc.cmd
S:\ocbqsqj.bat
S:\Oeboyg.exe
%UserProfile%\Application Data\senvjces.exe
S:\okelg.exe
S:\okhr.exe
M:\q2.exe
S:\ol.exe
S:\om.cmd
S:\om0.com
S:\op.bat
S:\ot.exe
S:\ot2.exe
S:\otf.cmd
S:\ox.cmd
%UserProfile%\Application Data\seres.exe
S:\p.cmd
M:\q2vl2fiy.com
S:\p0sc9t.cmd
S:\p1t.bat
S:\p3r1ud.exe
S:\p8ihdw.exe
S:\p9.exe
S:\pamn.exe
S:\patp.exe
S:\pbwkwj.COM
S:\pchkh.cmd
%UserProfile%\Application Data\Server.exe
M:\q83iwmgf.bat
S:\pjben6y.exe
S:\pjwtv.cmd
S:\pkxfkrki.bat
S:\pllq.exe
S:\pnc.exe
S:\popo.exe
S:\ppinbnp9.exe
S:\prjydpe.cmd
S:\px.bat
S:\pxbn6y.exe
M:\qb1.exe
%UserProfile%\Application Data\Simply Super Software\Trojan Remover\yraA.exe
S:\pytnmk.exe
S:\q.bat
S:\q.exe
S:\q0rppr.exe
S:\q10js.exe
S:\q1pady.cmd
S:\q2.exe
S:\q2vl2fiy.com
S:\q83iwmgf.bat
M:\qh.cmd
S:\qb1.exe
%UserProfile%\Application Data\Spy2009.dll
S:\qh.cmd
S:\qjatw9aj.exe
S:\qjfl.exe
S:\qkarc.exe
S:\qkolx.exe
S:\qngbvkhl.exe
S:\qotdyl.bat
S:\qpe6.com
M:\3.exe
M:\6xdgw26.com
M:\qjatw9aj.exe
S:\qr.exe
S:\qs6m.bat
%ProgramFiles%\Common Files\DianJi\LavaNet DNA\FVDISK.SYS
%UserProfile%\Application Data\STORE LESS JUGS SURF\HIDE DEAF.exe
S:\qsid8g.exe
S:\r.com
S:\r.exe
S:\r120.bat
S:\r2mkn.exe
S:\r8wb.bat
M:\qjfl.exe
S:\r9ghv9.com
S:\rcpi.exe
S:\rehsas.com
S:\resycled\boot.com
%UserProfile%\Application Data\svcst.exe
S:\rf.cmd
S:\rjiybg.exe
S:\rjx0.exe
S:\rmydqsiw.exe
S:\rn.exe
M:\qkarc.exe
S:\rtnlpipu.com
S:\rv36m1f9.exe
S:\rwrte.exe
S:\s2vgyp.exe
S:\s38k.exe
%UserProfile%\Application Data\t2jDx9PgC.exe
S:\s39tg.cmd
S:\s6.bat
S:\s6muem.cmd
S:\s8.exe
%Temp%\doscp0.dll
S:\s9l.exe
S:\SafeSys.exe
S:\sasyg1y8.com
S:\sdc.bat
S:\se11.cmd
S:\server2010.exe
%UserProfile%\Application Data\tawa.dll
S:\ServerXp.exe
S:\sh.exe
S:\shadu.exe
M:\qkolx.exe
S:\Shell.exe
S:\sie2v8.exe
S:\SiZhu.exe
S:\slphfx.bat
S:\sm.exe
S:\snaoc9i.exe
S:\SofwareUpdater.exe
%UserProfile%\Application Data\Tick Find Close Surf\grid show.exe
S:\spkr9wou.bat
S:\SRCHost.exe
M:\qngbvkhl.exe
S:\SRCost.exe
S:\stwi.com
S:\suqfl.exe
S:\svchost.exe
S:\svchovst.EXE
S:\system.dll
S:\systex.exe
S:\t.bat
%UserProfile%\Application Data\transcake\Coalbrowsedataheart.exe
S:\t.cmd
M:\qotdyl.bat
S:\t.exe
S:\t1xdgvq.exe
S:\t2f.exe
S:\t2jl.exe
S:\t2ydo.exe
S:\t3.com
S:\t82e2v.cmd
S:\tan3yt.bat
S:\tbhje.cmd
%UserProfile%\Application Data\transcake\fqcnmxwx.exe
M:\qpe6.com
S:\tcburi.exe
S:\temp.exe
S:\temp28.exe
S:\tfa8rk6.com
S:\tg.com
S:\tgtighg.cmd
S:\thghikva.exe
S:\tigi.cmd
S:\tikett.exe
S:\tj8odymw.exe
M:\qr.exe
%UserProfile%\Application Data\transcake\Hope Setup Save.exe
S:\tlmjw.cmd
S:\tmd.exe
S:\tmf3w3g0.com
S:\tmf3w3go.com
S:\tn.exe
S:\tn0k.exe
S:\ts6k.exe
S:\tt.com
S:\tudqrfw.exe
M:\qs6m.bat
S:\txfl1rhh.com
%UserProfile%\Application Data\transcake\kwlonaqc.exe
S:\tyfr.com
S:\tyvq.exe
S:\u.cmd
S:\u.exe
S:\u08.cmd
S:\u18vxqle.com
S:\u26ufgv.exe
S:\u2by.exe
M:\806.com
M:\qsid8g.exe
S:\u3dsc.com
S:\u63urr.exe
%UserProfile%\Application Data\transcake\type store plus.exe
S:\u6k.cmd
S:\u82.exe
S:\u99.exe
S:\ud.exe
S:\ufwi6sq.exe
S:\uh.exe
S:\uh31.exe
M:\r.com
S:\uhjqlk.exe
S:\un_tc.exe
S:\uorys.cmd
%ProgramFiles%\Common Files\Dowa.exe
%UserProfile%\Application Data\transcake\xmqgdqmi.exe
S:\up.exe
S:\up0ppxwr.com
S:\update220.exe
S:\update2201.exe
S:\updater697.exe
M:\r.exe
S:\UpdateThis.exe
S:\UpdateWindows.exe
S:\updds3.exe
S:\ups.exe
S:\Ups3.exe
%UserProfile%\Application Data\ufoz.bat
S:\upsf.exe
S:\uptes.exe
S:\upts3.exe
S:\uptsd.exe
M:\r120.bat
S:\Upz.exe
S:\uqb0julr.bat
S:\us8amqf.exe
S:\ut.bat
S:\ut9x.bat
S:\utcn8c63.exe
%UserProfile%\Application Data\ujiz.exe
S:\uuhgt.bat
S:\uwlmj.com
S:\uxkktr.cmd
%Temp%\doscp1.dll
S:\uyfd9cck.cmd
S:\v0f8rqc.cmd
S:\v0vj.exe
S:\v2h3.exe
S:\v3pif.bat
S:\v86htgx.cmd
S:\v9l1l.com
%UserProfile%\Application Data\updates.exe
S:\v9l8.exe
S:\v9ug2p2.com
M:\r2mkn.exe
S:\vcf0.exe
S:\vctio.com
S:\vd91t29.exe
S:\vdej3e.exe
S:\vkrg.exe
S:\vmhr.bat
S:\vnkucvv.com
S:\vp.exe
%UserProfile%\Application Data\urawofyje.exe
S:\vpqdgkx.com
M:\r8wb.bat
S:\vt6e.cmd
S:\w.bat
S:\w.cmd
S:\w.exe
S:\w2qagd.com
S:\w3dn9f.bat
S:\w6hikrv.com
S:\w9fc.exe
S:\wdm.exe
%UserProfile%\Application Data\waults.exe
M:\r9ghv9.com
S:\Webhost2.exe
S:\webhost4.exe
S:\Weeiivruved.exe
S:\weg6sp.com
S:\wehds63.exe
S:\wewt425.exe
S:\wewtf.exe
S:\wex.exe
S:\wg0kpd.bat
S:\wg6jj0.exe
M:\rcpi.exe
%UserProfile%\Application Data\wd\kswbc.dll
S:\wglplm6g.bat
S:\wgp.com
S:\Windows.exe
S:\winhost.exe
S:\winser.exe
S:\wjlc.exe
S:\wkcay8u.cmd
S:\wpkx.bat
S:\wstk.exe
M:\rehsas.com
S:\wuwu.exe
%UserProfile%\Application Data\wd\kswebshield.dll
S:\wv.exe
S:\wycgb8.cmd
S:\wyqrvts.exe
S:\wyzlo.exe
S:\x.bat
S:\x.cmd
S:\x1.cmd
S:\x1dg.exe
M:\82.exe
M:\resycled\boot.com
S:\x1o8uo.exe
S:\x63rnneh.exe
%UserProfile%\Application Data\wd\KSWebShield.exe
S:\xa8v8.exe
S:\xadeiect.com
S:\xc.exe
S:\xe9fdii1.cmd
S:\xedex.exe
S:\xene9.bat
S:\xievhrf.exe
M:\rf.cmd
S:\xjs.exe
S:\xjv.exe
S:\xnfrqlvf.exe
%UserProfile%\Application Data\wd\kwssp.dll
S:\xppg3r6.exe
S:\xpq63xl.exe
S:\xqg0.exe
S:\xqyl68.exe
S:\xue.exe
S:\xv.com
M:\rjiybg.exe
S:\xwpehlv.com
S:\xyh.exe
S:\y.com
S:\y319s.exe
%ProgramFiles%\Common Files\Dowb.exe
%UserProfile%\Application Data\wd\kwsui.dll
S:\y6u.bat
S:\y9rlqi.cmd
S:\ydmj.exe
S:\yfmqo.cmd
M:\rjx0.exe
S:\yfpaoty.exe
S:\ygvtn.exe
S:\yh.bat
S:\yi9.exe
S:\yjkjfuo.cmd
S:\ymxf3q.exe
%UserProfile%\application data\weemi\weemi129.exe
S:\yp.bat
S:\ypjq1.cmd
S:\yq.com
M:\rmydqsiw.exe
S:\yq00tht.exe
S:\yt8a.exe
S:\yv.exe
S:\yw6mmv0.exe
S:\zx.exe
T:\3.exe
T:\300y.cmd
%UserProfile%\Application Data\xtndio32.dll
T:\30c0e.cmd
T:\30ed3.exe
%Temp%\doscp2.dll
T:\31n3b2h.exe
T:\32o3.cmd
T:\35e.exe
T:\38s3i.exe
T:\39ysi89.com
T:\3bo9tn.cmd
T:\3ce.exe
T:\3dohrt.com
%UserProfile%\Application Data\ypuzuc.dll
T:\3ds.cmd
M:\rn.exe
T:\3ehxs6.cmd
T:\3g3.exe
T:\3hihyi.exe
T:\3iugonx.com
T:\3jkka91.com
T:\3jkkdo.exe
T:\3o0fp.exe
T:\3p9wj19.exe
T:\3r33c.CMD
%UserProfile%\Application Data\YRUvoXXeDU.exe
M:\rtnlpipu.com
T:\3vf9968r.exe
T:\3wmvmd.cmd
T:\3wy1vm.cmd
T:\3y.bat
T:\3yr1.cmd
T:\535.exe
T:\6.bat
T:\6.exe
T:\62oop0ak.bat
T:\63e.exe
M:\rv36m1f9.exe
%UserProfile%\ApplicationData\Microsoft\InternetExplorer\Expert.Dll
T:\6hg.exe
T:\6j2j.com
T:\6o0.bat
T:\6phx.com
T:\6qe.com
T:\6r3p.com
T:\6rq6.exe
T:\6vu680.com
T:\6wqhah.exe
M:\rwrte.exe
T:\6xdgw26.com
%UserProfile%\ApplicationData\Spy2009.dll
T:\806.com
T:\82.exe
T:\82i.cmd
T:\82tgk9eg.exe
T:\8386nac.com
T:\8a.exe
T:\8ae2q.exe
T:\8b3.bat
M:\82i.cmd
M:\s2vgyp.exe
T:\8df.EXE
T:\8e.com
%UserProfile%\av_md.exe
T:\8gidy.exe
T:\8h3hh3m.exe
T:\8iyqbsp1.exe
T:\8m08ty.com
T:\8mt8bm.exe
T:\8nlo1q.cmd
T:\8ot8y86.exe
M:\s38k.exe
T:\8oupido.bat
T:\8ox61l6.cmd
T:\8q6h.exe
%UserProfile%\Cookies\inave.bat
T:\8tss2gwq.bat
T:\8u.com
T:\8uot.exe
T:\8xlwbngd.exe
T:\90imhpnc.exe
T:\91.exe
M:\s39tg.cmd
T:\91m.COM
T:\92j11sm.com
T:\96.com
T:\9b8kmipy.com
%UserProfile%\Cookies\ipadunojaz.sys
T:\9bid6bl.exe
T:\9dl.cmd
T:\9es.com
T:\9l66g8k1.com
T:\9o.exe
M:\s6.bat
T:\9r8hh2f.exe
T:\9tb8ist.bat
T:\9yp8nyvg.exe
T:\a.bat
T:\a.exe
%ProgramFiles%\Common Files\eBay\ylauncher.exe
%UserProfile%\Cookies\jahebequ.bat
T:\a2r.exe
T:\a8qengab.exe
T:\ab.cmd
M:\s6muem.cmd
T:\abqk2c3i.bat
T:\adba2.exe
T:\af93gcf.exe
T:\af9rgm8h.bat
T:\alt.exe
T:\aluj8r.exe
T:\anky8.exe
%UserProfile%\Cookies\nidefaqot.sys
T:\aoutfq.exe
T:\ap.com
M:\s8.exe
T:\atymi09.bat
T:\auto.exe
T:\auto.pif
T:\autorun.exe
T:\autorun.inf
T:\autorunx.exe
T:\autox.exe
T:\avmb.exe
%UserProfile%\Cookies\okugypoj.dll
T:\ay8p6v3.cmd
%Temp%\doscp3.dll
T:\b.bat
T:\b.cmd
T:\b.exe
T:\Backup.exe
T:\baksql.bat
T:\Beanfun.exe
T:\bn0.bat
T:\BNB_029.exe
T:\bnkxy.exe
%UserProfile%\Cookies\togimep.bat
M:\s9l.exe
T:\bnmv.exe
T:\bplrl98.cmd
T:\bpvwvays.exe
T:\bpx9q3j.exe
T:\bqk.bat
T:\bs3ol8kd2.exe
T:\bsp.cmd
T:\bt8vuaw.com
T:\bunip.bat
T:\bxuup9r.bat
M:\SafeSys.exe
%UserProfile%\Cookies\urym.dll
T:\c.bat
T:\c.exe
T:\cbpd.exe
T:\ccc.exe
T:\CD8IDOYL.COM
T:\ceqfqp.bat
T:\cfv90h.com
T:\check.exe
T:\chlf9.exe
M:\sasyg1y8.com
T:\cjrp8.com
%UserProfile%\Cookies\zyxofyly.bat
T:\clc1al.com
T:\clc3k.com
T:\clxam6r6.exe
T:\cm0.com
T:\cmon.exe
T:\cn.exe
T:\co.com
T:\copetttt.com
M:\82tgk9eg.exe
M:\sdc.bat
T:\copy.exe
T:\cp13cg.exe
%UserProfile%\cson.exe
T:\cubp.bat
T:\d.bat
T:\d.exe
T:\d218eht.exe
T:\d22xl.bat
T:\d3bn0j.exe
T:\d6r6jmp.exe
M:\se11.cmd
T:\d8ur3qs.bat
T:\dagd.exe
T:\dblnq.exe
%UserProfile%\csrss.exe
T:\ddyikr.CMD
T:\delshare.bat
T:\dgf.exe
T:\dgkx.exe
T:\dh66ln.cmd
T:\dhcore.exe
M:\server2010.exe
T:\di3su.exe
T:\diox3j.com
T:\dmf.exe
T:\down.exe
%UserProfile%\delself.bat
T:\down2.bat
T:\dp.cmd
T:\dp.exe
T:\dpu1.exe
T:\dqi.exe
M:\ServerXp.exe
T:\ds.exe
T:\dsty.com
T:\dv6pp.exe
T:\dvhyi.exe
T:\dxv.bat
%UserProfile%\Desktop\Antivirus Pro 2010.lnk
T:\dynrn6e.cmd
T:\dyr2j6mv.exe
T:\e.cmd
T:\e.exe
M:\sh.exe
T:\e00233it.com
T:\e0t9n6.exe
T:\e6.com
T:\e619e.cmd
T:\E6IEG.EXE
T:\e898.com
%ProgramFiles%\Common Files\filseclab\filar.sys
%UserProfile%\Documents and Settings\All Users\Application Data\19335464\19335464.exe
T:\eadf6s.exe
T:\eb9ehyh.exe
M:\shadu.exe
T:\ecn.com
T:\eeqt.exe
T:\eftwl.exe
T:\eg1.cmd
T:\eito.exe
T:\ejoq.exe
T:\ek.com
T:\ell.exe
%UserProfile%\Documents\Fun.exe
T:\erdeIect.com
M:\Shell.exe
T:\erjhni.exe
T:\ermvu8.cmd
T:\et.exe
T:\ewatr.cmd
T:\f.bat
T:\f.exe
T:\ff1q0gw.bat
T:\fgj3lc8.exe
T:\find.exe
%UserProfile%\Documents\gxcdue.exe
%Temp%\doscp4.dll
T:\fipgnfww.cmd
T:\fjb2.exe
T:\fp.exe
T:\fphj6j31.bat
T:\fsdg.exe
T:\ft8.exe
T:\ftiduico.bat
T:\fufb6tq3.cmd
T:\fvan.exe
T:\fvbk.exe
M:\sie2v8.exe
%UserProfile%\Documents\inugalav.sys
T:\g.exe
T:\g0.cmd
T:\g2p3s.exe
T:\g8rruyw.exe
T:\g9rv.exe
T:\gaagw.bat
T:\gabptk6d.bat
T:\gclwpivc.cmd
T:\gdsag.exe
M:\SiZhu.exe
T:\ggkxgvf.bat
%UserProfile%\Documents\iwomivig.com
T:\ggl.cmd
T:\ggqn.exe
T:\ghdf1.com
T:\gicchk2s.exe
T:\gmi1jxy.com
T:\gnc.bat
T:\gnwav.exe
T:\gnwwy.exe
M:\8386nac.com
M:\slphfx.bat
T:\gplpn.exe
T:\gqsk.bat
%UserProfile%\Documents\jepi.com
T:\gswrij.exe
T:\gsxlexd.cmd
T:\gx.bat
T:\gx.com
T:\gxul.com
T:\gymussy.bat
T:\h.bat
M:\sm.exe
T:\h.CMD
T:\h0j8w.exe
T:\h0ti1de.bat
%UserProfile%\Documents\kelemygij.bat
T:\h2.com
T:\h2t6u.exe
T:\h3hi1k3.exe
T:\h8i.com
T:\hfap.exe
T:\higj2p.bat
M:\snaoc9i.exe
T:\hn.cmd
T:\hnkvaa2.exe
T:\home.exe
T:\host.exe
%UserProfile%\Documents\lytavib.com
T:\hovrflst.bat
T:\hpkq.cmd
T:\hqx292nu.exe
T:\hsi.com
T:\hsjnkj.exe
M:\SofwareUpdater.exe
T:\htjtq8o.exe
T:\hupxj.bat
T:\hv8fv2.exe
T:\hvoxmq.exe
T:\hxbpamjb.cmd
%UserProfile%\Documents\odosoco.sys
T:\hxs.bat
T:\hyj2gunw.exe
T:\i.bat
T:\i2.com
M:\spkr9wou.bat
T:\ib3qc3t.cmd
T:\if6ch9k6.bat
T:\ig.bat
T:\igcmrtjw.cmd
T:\il0byu3h.com
T:\il6.exe
%UserProfile%\Documents\poviqaxi.com
T:\iluqcwr.exe
T:\imt8.cmd
T:\iok.exe
M:\SRCHost.exe
T:\ipy.cmd
T:\iscwam2h.cmd
T:\it1d.exe
T:\iu.bat
T:\iw.bat
T:\iwjj.com
T:\ixsla.exe
%ProgramFile%\SetWallpaper.cmd
%ProgramFiles%\Common Files\filseclab\filmsg.exe
%UserProfile%\Documents\rude.bat
M:\SRCost.exe
T:\j.bat
T:\j0.exe
T:\j0mpdkja.cmd
T:\j1.cmd
T:\j16dp6.exe
T:\j1rxka1n.exe
T:\j83uv.exe
T:\jatxgwcj.bat
T:\jc1r11.exe
T:\jcmmawa.bat
M:\stwi.com
%UserProfile%\Documents\ryrusipeh.dll
T:\jdt2ofp.exe
T:\jg.com
T:\jg6w3yx.com
T:\jhcqxax.exe
T:\jix9a.bat
T:\jj2.com
T:\jkxrox.exe
T:\jl.com
T:\jvu69.bat
%ProgramFiles%\BeatTrojan2009\BeatTrojanHelperOne.sys
T:\jy.exe
%UserProfile%\Documents\tidado.bat
T:\k.com
T:\k08aww.bat
T:\k2.cmd
T:\k6wkwon2.exe
T:\k9cuos2q.exe
T:\ka1nk.bat
T:\karina///debeja.exe
T:\kdy.cmd
%Temp%\doscp5.dll
T:\kg18j.exe
T:\kgnkxc.exe
%UserProfile%\Documents\vibimigid.bat
T:\kjibu.com
T:\kk.bat
T:\kk36.exe
T:\kk38g1.exe
T:\kpvqk.exe
T:\kqsr.exe
T:\kuqskg2s.bat
M:\8a.exe
M:\suqfl.exe
T:\kuruna.exe
T:\kya6l.bat
T:\l1.cmd
%UserProfile%\Documents\ycuworud.dll
T:\l3v.exe
T:\l6w2eaih.exe
T:\ldgybkp.bat
T:\lgcadwx.bat
T:\lgnaqil.exe
T:\lgrncie.bat
M:\svchost.exe
T:\lgvg8q.exe
T:\lhwdcgcb.bat
T:\lj.exe
T:\lj6hdv.com
%UserProfile%\Documents\zakiq.bat
T:\ll.exe
T:\lp3c.bat
T:\lsfjg.com
T:\lsg6jj9.exe
T:\lskeqbfc.exe
M:\svchovst.EXE
T:\ltc.bat
T:\lulu.exe
T:\lwd.bat
T:\lyhwcea.exe
T:\m.bat
%UserProfile%\EPSONREG.EXE.exe
T:\m.exe
T:\m6dqm2vd.exe
T:\m6n.com
T:\m8wafly.com
M:\system.dll
T:\m9as2c.cmd
T:\mayyuk9g.bat
T:\mbewb2n.exe
T:\mcmm.bat
T:\mka.bat
T:\mm6q.exe
%UserProfile%\Favorites\厙硊絳瑤湮.url
T:\momo.exe
T:\motr.exe
T:\mpstxgx.exe
M:\systex.exe
T:\mrghykh.exe
T:\mrsne.bat
T:\msbackup.exe
T:\msn.exe
T:\mt.com
T:\mt0.cmd
T:\mtlhieej.cmd
%UserProfile%\file.exe
T:\n.com
T:\n.exe
M:\t.bat
T:\n1m.exe
T:\n1v93rqo.exe
T:\n6j6pc0.com
T:\n89f1d1w.exe
T:\nbke.exe
T:\ncc.exe
T:\ndmego0f.cmd
T:\net.exe
%UserProfile%\fxmdk.exe
T:\ngq6hva0.exe
M:\t.cmd
T:\nmje9v6d.bat
T:\nncu6kk.com
T:\nooakkv.exe
T:\np.exe
T:\nq.bat
T:\nqgcd.com
T:\nskmu.exe
T:\nsv.bat
T:\nt6ry3bn.cmd
%ProgramFiles%\Common Files\filseclab\filpp.sys
M:\t.exe
%UserProfile%\GoToAssistDownloadHelper.exe
T:\ntdeiect.com
T:\ntdelect.com
T:\NTDETECT.EXE
T:\ntnq.exe
T:\ntphyy.com
T:\nvrfc.bat
T:\nw.exe
T:\nw0t1l0d.exe
T:\nxvhpc.exe
M:\t1xdgvq.exe
T:\ny36jjt.exe
%UserProfile%\killdll.dll
T:\nyat.exe
T:\O.cmd
T:\o.exe
T:\o6opnro.bat
T:\o6pq1n8.com
T:\o93ml8.bat
T:\o9o2.com
T:\o9o2u.bat
M:\t2f.exe
T:\oaljb6.exe
T:\obg.exe
%UserProfile%\Local Settings\Application Data\~FileLockReboot.tmp
T:\obtpf.bat
T:\oc.cmd
T:\ocbqsqj.bat
T:\Oeboyg.exe
T:\okelg.exe
T:\okhr.exe
T:\ol.exe
M:\8ae2q.exe
%Temp%\doscp6.dll
T:\om.cmd
T:\om0.com
T:\op.bat
%UserProfile%\local settings\application data\ave.exe
T:\ot.exe
T:\ot2.exe
T:\otf.cmd
T:\ox.cmd
T:\p.cmd
T:\p0sc9t.cmd
M:\t2jl.exe
T:\p1t.bat
T:\p3r1ud.exe
T:\p8ihdw.exe
T:\p9.exe
%UserProfile%\Local Settings\Application Data\azykiraj.dll
T:\pamn.exe
T:\patp.exe
T:\pbwkwj.COM
T:\pchkh.cmd
T:\pjben6y.exe
M:\t2ydo.exe
T:\pjwtv.cmd
T:\pkxfkrki.bat
T:\pllq.exe
T:\pnc.exe
T:\popo.exe
%UserProfile%\Local Settings\Application Data\bihanutiti.exe
T:\ppinbnp9.exe
T:\prjydpe.cmd
T:\px.bat
T:\pxbn6y.exe
M:\t3.com
T:\pytnmk.exe
T:\q.bat
T:\q.exe
T:\q0rppr.exe
T:\q10js.exe
T:\q1pady.cmd
%UserProfile%\Local Settings\Application Data\In.exe
T:\q2.exe
T:\q2vl2fiy.com
T:\q83iwmgf.bat
M:\t82e2v.cmd
T:\qb1.exe
T:\qh.cmd
T:\qjatw9aj.exe
T:\qjfl.exe
T:\qkarc.exe
T:\qkolx.exe
T:\qngbvkhl.exe
%UserProfile%\Local Settings\Application Data\itityg.dll
T:\qotdyl.bat
T:\qpe6.com
M:\tan3yt.bat
T:\qr.exe
T:\qs6m.bat
T:\qsid8g.exe
T:\r.com
T:\r.exe
T:\r120.bat
T:\r2mkn.exe
T:\r8wb.bat
%UserProfile%\Local Settings\Application Data\kws.ini
T:\r9ghv9.com
M:\tbhje.cmd
T:\rcpi.exe
T:\rehsas.com
T:\resycled\boot.com
T:\rf.cmd
T:\rjiybg.exe
T:\rjx0.exe
T:\rmydqsiw.exe
T:\rn.exe
T:\rtnlpipu.com
%UserProfile%\Local Settings\Application Data\nylig.exe
M:\tcburi.exe
T:\rv36m1f9.exe
T:\rwrte.exe
T:\s2vgyp.exe
T:\s38k.exe
T:\s39tg.cmd
T:\s6.bat
T:\s6muem.cmd
T:\s8.exe
T:\s9l.exe
T:\SafeSys.exe
M:\temp.exe
%ProgramFiles%\Common Files\goskdl.dll
%UserProfile%\Local Settings\Application Data\onumutaw.sys
T:\sasyg1y8.com
T:\sdc.bat
T:\se11.cmd
T:\server2010.exe
T:\ServerXp.exe
T:\sh.exe
T:\shadu.exe
T:\Shell.exe
M:\temp28.exe
T:\sie2v8.exe
T:\SiZhu.exe
%UserProfile%\Local Settings\Application Data\oxirecur.com
T:\slphfx.bat
T:\sm.exe
T:\snaoc9i.exe
T:\SofwareUpdater.exe
T:\spkr9wou.bat
T:\SRCHost.exe
T:\SRCost.exe
M:\8b3.bat
M:\tfa8rk6.com
T:\stwi.com
T:\suqfl.exe
T:\svchost.exe
%UserProfile%\Local Settings\Application Data\segewe.dll
T:\svchovst.EXE
T:\system.dll
T:\systex.exe
T:\t.bat
T:\t.cmd
T:\t.exe
%Temp%\doscp7.dll
T:\t1xdgvq.exe
T:\t2f.exe
T:\t2jl.exe
T:\t2ydo.exe
%UserProfile%\Local Settings\Application Data\Setup.exe
T:\t3.com
T:\t82e2v.cmd
T:\tan3yt.bat
T:\tbhje.cmd
T:\tcburi.exe
M:\tg.com
T:\temp.exe
T:\temp28.exe
T:\tfa8rk6.com
T:\tg.com
T:\tgtighg.cmd
%UserProfile%\Local Settings\Temp\document.jpg
T:\thghikva.exe
T:\tigi.cmd
T:\tikett.exe
T:\tj8odymw.exe
M:\tgtighg.cmd
T:\tlmjw.cmd
T:\tmd.exe
T:\tmf3w3g0.com
T:\tmf3w3go.com
T:\tn.exe
T:\tn0k.exe
%UserProfile%\Local Settings\Temp\nsr7.tmp\System.dll
T:\ts6k.exe
T:\tt.com
T:\tudqrfw.exe
M:\thghikva.exe
T:\txfl1rhh.com
T:\tyfr.com
T:\tyvq.exe
T:\u.cmd
T:\u.exe
T:\u08.cmd
T:\u18vxqle.com
%UserProfile%\Local Settings\Temp\nsu2.tmp\System.dll
T:\u26ufgv.exe
T:\u2by.exe
M:\tigi.cmd
T:\u3dsc.com
T:\u63urr.exe
T:\u6k.cmd
T:\u82.exe
T:\u99.exe
T:\ud.exe
T:\ufwi6sq.exe
T:\uh.exe
%UserProfile%\Local Settings\Temporary Internet Files\Content.IE5\MPG1YR8D\36[1].exe
T:\uh31.exe
M:\tikett.exe
T:\uhjqlk.exe
T:\un_tc.exe
T:\uorys.cmd
T:\up.exe
T:\up0ppxwr.com
T:\update220.exe
T:\update2201.exe
T:\updater697.exe
T:\UpdateThis.exe
%UserProfile%\Local Settings\Temporary Internet Files\Content.IE5\MPG1YR8D\install[1].exe
M:\tj8odymw.exe
T:\UpdateWindows.exe
T:\updds3.exe
T:\ups.exe
T:\Ups3.exe
T:\upsf.exe
T:\uptes.exe
T:\upts3.exe
T:\uptsd.exe
T:\Upz.exe
T:\uqb0julr.bat
M:\tlmjw.cmd
%UserProfile%\LOCALS~1\alvsvpd.exe
T:\us8amqf.exe
T:\ut.bat
T:\ut9x.bat
T:\utcn8c63.exe
T:\uuhgt.bat
T:\uwlmj.com
T:\uxkktr.cmd
T:\uyfd9cck.cmd
T:\v0f8rqc.cmd
M:\tmd.exe
T:\v0vj.exe
%ProgramFiles%\Common Files\idyduhin.com
%UserProfile%\Microsoft\smx4pnp.dll
T:\v2h3.exe
T:\v3pif.bat
T:\v86htgx.cmd
T:\v9l1l.com
T:\v9l8.exe
T:\v9ug2p2.com
T:\vcf0.exe
%Temp%\48230029.exe
M:\tmf3w3g0.com
T:\vctio.com
T:\vd91t29.exe
T:\vdej3e.exe
%UserProfile%\msword98.exe
T:\vkrg.exe
T:\vmhr.bat
T:\vnkucvv.com
T:\vp.exe
T:\vpqdgkx.com
T:\vt6e.cmd
M:\tmf3w3go.com
T:\w.bat
T:\w.cmd
T:\w.exe
T:\w2qagd.com
%UserProfile%\NATzyc.dll
T:\w3dn9f.bat
T:\w6hikrv.com
T:\w9fc.exe
T:\wdm.exe
T:\Webhost2.exe
%Temp%\doscp8.dll
T:\webhost4.exe
T:\Weeiivruved.exe
T:\weg6sp.com
T:\wehds63.exe
T:\wewt425.exe
%UserProfile%\QQpinyin.dll
T:\wewtf.exe
T:\wex.exe
T:\wg0kpd.bat
T:\wg6jj0.exe
M:\tn.exe
T:\wglplm6g.bat
T:\wgp.com
T:\Windows.exe
T:\winhost.exe
T:\winser.exe
T:\wjlc.exe
%UserProfile%\reader_s.exe
T:\wkcay8u.cmd
T:\wpkx.bat
T:\wstk.exe
M:\tn0k.exe
T:\wuwu.exe
T:\wv.exe
T:\wycgb8.cmd
T:\wyqrvts.exe
T:\wyzlo.exe
T:\x.bat
T:\x.cmd
%UserProfile%\Remove.exe.exe
T:\x1.cmd
T:\x1dg.exe
M:\ts6k.exe
T:\x1o8uo.exe
T:\x63rnneh.exe
T:\xa8v8.exe
T:\xadeiect.com
T:\xc.exe
T:\xe9fdii1.cmd
T:\xedex.exe
T:\xene9.bat
%UserProfile%\restorer32_a.exe
T:\xievhrf.exe
M:\tt.com
T:\xjs.exe
T:\xjv.exe
T:\xnfrqlvf.exe
T:\xppg3r6.exe
T:\xpq63xl.exe
T:\xqg0.exe
T:\xqyl68.exe
T:\xue.exe
T:\xv.com
%UserProfile%\restorer64_a.exe
M:\tudqrfw.exe
T:\xwpehlv.com
T:\xyh.exe
T:\y.com
T:\y319s.exe
T:\y6u.bat
T:\y9rlqi.cmd
T:\ydmj.exe
T:\yfmqo.cmd
T:\yfpaoty.exe
T:\ygvtn.exe
M:\txfl1rhh.com
%UserProfile%\sys32_nov.exe
T:\yh.bat
T:\yi9.exe
T:\yjkjfuo.cmd
T:\ymxf3q.exe
T:\yp.bat
T:\ypjq1.cmd
T:\yq.com
T:\yq00tht.exe
T:\yt8a.exe
M:\tyfr.com
T:\yv.exe
%UserProfile%\system32\winlogon32.exe
T:\yw6mmv0.exe
T:\zx.exe
U:\3.exe
U:\300y.cmd
U:\30c0e.cmd
U:\30ed3.exe
U:\31n3b2h.exe
U:\32o3.cmd
M:\300y.cmd
M:\8df.EXE
M:\tyvq.exe
U:\35e.exe
U:\38s3i.exe
%ProgramFiles%\Common Files\InstallShield\Driver\11\Intel 32\ckidriver2.exe
%UserProfile%\TISSuprt.exe.exe
U:\39ysi89.com
U:\3bo9tn.cmd
U:\3ce.exe
U:\3dohrt.com
U:\3ds.cmd
U:\3ehxs6.cmd
M:\u.cmd
U:\3g3.exe
U:\3hihyi.exe
U:\3iugonx.com
U:\3jkka91.com
%UserProfile%\tprncqict.exe
U:\3jkkdo.exe
U:\3o0fp.exe
U:\3p9wj19.exe
U:\3r33c.CMD
U:\3vf9968r.exe
M:\u.exe
U:\3wmvmd.cmd
U:\3wy1vm.cmd
U:\3y.bat
U:\3yr1.cmd
U:\535.exe
%UserProfile%\UfSeAgnt.exe.exe
U:\6.bat
U:\6.exe
U:\62oop0ak.bat
U:\63e.exe
%Temp%\doscp9.dll
U:\6hg.exe
U:\6j2j.com
U:\6o0.bat
U:\6phx.com
U:\6qe.com
U:\6r3p.com
%UserProfile%\vytwgs.exe
U:\6rq6.exe
U:\6vu680.com
U:\6wqhah.exe
M:\u08.cmd
U:\6xdgw26.com
U:\806.com
U:\82.exe
U:\82i.cmd
U:\82tgk9eg.exe
U:\8386nac.com
U:\8a.exe
%UserProfile%\wuaucldt.exe
U:\8ae2q.exe
U:\8b3.bat
M:\u18vxqle.com
U:\8df.EXE
U:\8e.com
U:\8gidy.exe
U:\8h3hh3m.exe
U:\8iyqbsp1.exe
U:\8m08ty.com
U:\8mt8bm.exe
U:\8nlo1q.cmd
%UserProfile%\桌面\1.exe
U:\8ot8y86.exe
M:\u26ufgv.exe
U:\8oupido.bat
U:\8ox61l6.cmd
U:\8q6h.exe
U:\8tss2gwq.bat
U:\8u.com
U:\8uot.exe
U:\8xlwbngd.exe
U:\90imhpnc.exe
U:\91.exe
%UserProfile%\桌面\Coopen.lnk
M:\u2by.exe
U:\91m.COM
U:\92j11sm.com
U:\96.com
U:\9b8kmipy.com
U:\9bid6bl.exe
U:\9dl.cmd
U:\9es.com
U:\9l66g8k1.com
U:\9o.exe
U:\9r8hh2f.exe
M:\u3dsc.com
%UserProfile%\桌面\玿ˋ^_^俙1狟ㄐ.lnk
U:\9tb8ist.bat
U:\9yp8nyvg.exe
U:\a.bat
U:\a.exe
U:\a2r.exe
U:\a8qengab.exe
U:\ab.cmd
U:\abqk2c3i.bat
U:\adba2.exe
M:\u63urr.exe
U:\af93gcf.exe
%windir%\ vvxx.exe
U:\af9rgm8h.bat
U:\alt.exe
U:\aluj8r.exe
U:\anky8.exe
U:\aoutfq.exe
U:\ap.com
U:\atymi09.bat
U:\auto.exe
M:\8e.com
M:\u6k.cmd
U:\auto.pif
U:\autorun.exe
%WINDIR%\$hf_mig$\svhost32.exe
U:\autorun.inf
U:\autorunx.exe
U:\autox.exe
U:\avmb.exe
U:\ay8p6v3.cmd
U:\b.bat
U:\b.cmd
M:\u82.exe
U:\b.exe
U:\Backup.exe
U:\baksql.bat
%ProgramFiles%\Common Files\InstallShield\Driver\11\Intel 32\jhidriver.exe
%windir%\_wpbegone.bat
U:\Beanfun.exe
U:\bn0.bat
U:\BNB_029.exe
U:\bnkxy.exe
U:\bnmv.exe
M:\u99.exe
U:\bplrl98.cmd
U:\bpvwvays.exe
U:\bpx9q3j.exe
U:\bqk.bat
U:\bs3ol8kd2.exe
%windir%\_wuauc1t.exe
U:\bsp.cmd
U:\bt8vuaw.com
U:\bunip.bat
U:\bxuup9r.bat
M:\ud.exe
U:\c.bat
U:\c.exe
U:\cbpd.exe
U:\ccc.exe
U:\CD8IDOYL.COM
U:\ceqfqp.bat
%windir%\~hha.tmp
U:\cfv90h.com
U:\check.exe
U:\chlf9.exe
%Temp%\e_4\com.run
U:\cjrp8.com
U:\clc1al.com
U:\clc3k.com
U:\clxam6r6.exe
U:\cm0.com
U:\cmon.exe
U:\cn.exe
%windir%\~tmp6329.exe
U:\co.com
U:\copetttt.com
M:\ufwi6sq.exe
U:\copy.exe
U:\cp13cg.exe
U:\cubp.bat
U:\d.bat
U:\d.exe
U:\d218eht.exe
U:\d22xl.bat
U:\d3bn0j.exe
%windir%\0.exe
U:\d6r6jmp.exe
M:\uh.exe
U:\d8ur3qs.bat
U:\dagd.exe
U:\dblnq.exe
U:\ddyikr.CMD
U:\delshare.bat
U:\dgf.exe
U:\dgkx.exe
U:\dh66ln.cmd
U:\dhcore.exe
%windir%\002381_.tmp
M:\uh31.exe
U:\di3su.exe
U:\diox3j.com
U:\dmf.exe
U:\down.exe
U:\down2.bat
U:\dp.cmd
U:\dp.exe
U:\dpu1.exe
U:\dqi.exe
U:\ds.exe
M:\uhjqlk.exe
%windir%\002618_.tmp
U:\dsty.com
U:\dv6pp.exe
U:\dvhyi.exe
U:\dxv.bat
U:\dynrn6e.cmd
U:\dyr2j6mv.exe
U:\e.cmd
U:\e.exe
U:\e00233it.com
M:\un_tc.exe
U:\e0t9n6.exe
%windir%\002828_.tmp
U:\e6.com
U:\e619e.cmd
U:\E6IEG.EXE
U:\e898.com
U:\eadf6s.exe
U:\eb9ehyh.exe
U:\ecn.com
U:\eeqt.exe
M:\8gidy.exe
M:\uorys.cmd
U:\eftwl.exe
U:\eg1.cmd
%windir%\0053783.tmp
U:\eito.exe
U:\ejoq.exe
U:\ek.com
U:\ell.exe
U:\erdeIect.com
U:\erjhni.exe
U:\ermvu8.cmd
M:\up.exe
U:\et.exe
U:\ewatr.cmd
U:\f.bat
%windir%\0054982.tmp
U:\f.exe
U:\ff1q0gw.bat
U:\fgj3lc8.exe
U:\find.exe
U:\fipgnfww.cmd
U:\fjb2.exe
M:\up0ppxwr.com
U:\fp.exe
U:\fphj6j31.bat
U:\fsdg.exe
U:\ft8.exe
%ProgramFiles%\Common Files\InstallShield\Driver\11\Intel 32\osidrivert.exe
%windir%\005911_.tmp
U:\ftiduico.bat
U:\fufb6tq3.cmd
U:\fvan.exe
U:\fvbk.exe
M:\update220.exe
U:\g.exe
U:\g0.cmd
U:\g2p3s.exe
U:\g8rruyw.exe
U:\g9rv.exe
U:\gaagw.bat
%windir%\052OATNC7V.exe
U:\gabptk6d.bat
U:\gclwpivc.cmd
U:\gdsag.exe
M:\update2201.exe
U:\ggkxgvf.bat
U:\ggl.cmd
U:\ggqn.exe
U:\ghdf1.com
U:\gicchk2s.exe
U:\gmi1jxy.com
U:\gnc.bat
%windir%\0e2.exe
U:\gnwav.exe
U:\gnwwy.exe
%Temp%\e_4\dp1.fne
U:\gplpn.exe
U:\gqsk.bat
U:\gswrij.exe
U:\gsxlexd.cmd
U:\gx.bat
U:\gx.com
U:\gxul.com
U:\gymussy.bat
%windir%\0Sy.exe
U:\h.bat
M:\updater697.exe
U:\h.CMD
U:\h0j8w.exe
U:\h0ti1de.bat
U:\h2.com
U:\h2t6u.exe
U:\h3hi1k3.exe
U:\h8i.com
U:\hfap.exe
U:\higj2p.bat
%windir%\1.bat
M:\UpdateThis.exe
U:\hn.cmd
U:\hnkvaa2.exe
U:\home.exe
U:\host.exe
U:\hovrflst.bat
U:\hpkq.cmd
U:\hqx292nu.exe
U:\hsi.com
U:\hsjnkj.exe
U:\htjtq8o.exe
M:\UpdateWindows.exe
%windir%\1.exe
U:\hupxj.bat
U:\hv8fv2.exe
U:\hvoxmq.exe
U:\hxbpamjb.cmd
U:\hxs.bat
U:\hyj2gunw.exe
U:\i.bat
U:\i2.com
U:\ib3qc3t.cmd
M:\updds3.exe
U:\if6ch9k6.bat
%windir%\1004.exe
U:\ig.bat
U:\igcmrtjw.cmd
U:\il0byu3h.com
U:\il6.exe
U:\iluqcwr.exe
U:\imt8.cmd
U:\iok.exe
U:\ipy.cmd
M:\8h3hh3m.exe
M:\ups.exe
U:\iscwam2h.cmd
U:\it1d.exe
%windir%\1006.exe
U:\iu.bat
U:\iw.bat
U:\iwjj.com
U:\ixsla.exe
U:\j.bat
U:\j0.exe
U:\j0mpdkja.cmd
M:\Ups3.exe
U:\j1.cmd
U:\j16dp6.exe
U:\j1rxka1n.exe
%windir%\10Sy.exe
U:\j83uv.exe
U:\jatxgwcj.bat
U:\jc1r11.exe
U:\jcmmawa.bat
U:\jdt2ofp.exe
U:\jg.com
M:\upsf.exe
U:\jg6w3yx.com
U:\jhcqxax.exe
U:\jix9a.bat
U:\jj2.com
%windir%\11231tro92ze5.dll
U:\jkxrox.exe
U:\jl.com
U:\jvu69.bat
U:\jy.exe
U:\k.com
M:\uptes.exe
U:\k08aww.bat
U:\k2.cmd
U:\k6wkwon2.exe
U:\k9cuos2q.exe
U:\ka1nk.bat
%ProgramFiles%\Common Files\InstallShield\Engine\6\Intel 32\nvikernel.exe
%windir%\1197312.bat
U:\karina///debeja.exe
U:\kdy.cmd
U:\kg18j.exe
M:\upts3.exe
U:\kgnkxc.exe
U:\kjibu.com
U:\kk.bat
U:\kk36.exe
U:\kk38g1.exe
U:\kpvqk.exe
U:\kqsr.exe
%windir%\1197312.exe
U:\kuqskg2s.bat
U:\kuruna.exe
M:\uptsd.exe
U:\kya6l.bat
U:\l1.cmd
U:\l3v.exe
U:\l6w2eaih.exe
U:\ldgybkp.bat
U:\lgcadwx.bat
U:\lgnaqil.exe
U:\lgrncie.bat
%windir%\12 402122cef1.dll
U:\lgvg8q.exe
%Temp%\e_4\eapi.fne
U:\lhwdcgcb.bat
U:\lj.exe
U:\lj6hdv.com
U:\ll.exe
U:\lp3c.bat
U:\lsfjg.com
U:\lsg6jj9.exe
U:\lskeqbfc.exe
U:\ltc.bat
%windir%\120MVP94WL.txt
M:\Upz.exe
U:\lulu.exe
U:\lwd.bat
U:\lyhwcea.exe
U:\m.bat
U:\m.exe
U:\m6dqm2vd.exe
U:\m6n.com
U:\m8wafly.com
U:\m9as2c.cmd
U:\mayyuk9g.bat
M:\uqb0julr.bat
%windir%\139039text.exe
U:\mbewb2n.exe
U:\mcmm.bat
U:\mka.bat
U:\mm6q.exe
U:\momo.exe
U:\motr.exe
U:\mpstxgx.exe
U:\mrghykh.exe
U:\mrsne.bat
M:\us8amqf.exe
U:\msbackup.exe
%windir%\14079sp5mbzt526.dll
U:\msn.exe
U:\mt.com
U:\mt0.cmd
U:\mtlhieej.cmd
U:\n.com
U:\n.exe
U:\n1m.exe
U:\n1v93rqo.exe
M:\8iyqbsp1.exe
M:\ut.bat
U:\n6j6pc0.com
U:\n89f1d1w.exe
%windir%\147261text.exe
U:\nbke.exe
U:\ncc.exe
U:\ndmego0f.cmd
U:\net.exe
U:\ngq6hva0.exe
U:\nmje9v6d.bat
U:\nncu6kk.com
M:\ut9x.bat
U:\nooakkv.exe
U:\np.exe
U:\nq.bat
%windir%\14912sp5mbo9z98.dll
U:\nqgcd.com
U:\nskmu.exe
U:\nsv.bat
U:\nt6ry3bn.cmd
U:\ntdeiect.com
U:\ntdelect.com
M:\utcn8c63.exe
U:\NTDETECT.EXE
U:\ntnq.exe
U:\ntphyy.com
U:\nvrfc.bat
%windir%\1497sparze4245.dll
U:\nw.exe
U:\nw0t1l0d.exe
U:\nxvhpc.exe
U:\ny36jjt.exe
U:\nyat.exe
M:\uuhgt.bat
U:\O.cmd
U:\o.exe
U:\o6opnro.bat
U:\o6pq1n8.com
U:\o93ml8.bat
%windir%\14cspzr9e5450.dll
U:\o9o2.com
U:\o9o2u.bat
U:\oaljb6.exe
U:\obg.exe
M:\uwlmj.com
U:\obtpf.bat
U:\oc.cmd
U:\ocbqsqj.bat
U:\Oeboyg.exe
U:\okelg.exe
U:\okhr.exe
%ProgramFiles%\Common Files\InstallShield\Professional\RunTime\0701\Intel32\netinstaller.exe
%windir%\15055z9y645.dll
U:\ol.exe
U:\om.cmd
M:\uxkktr.cmd
U:\om0.com
U:\op.bat
U:\ot.exe
U:\ot2.exe
U:\otf.cmd
U:\ox.cmd
U:\p.cmd
U:\p0sc9t.cmd
%windir%\15327spazbot5ce9.dll
U:\p1t.bat
M:\uyfd9cck.cmd
U:\p3r1ud.exe
U:\p8ihdw.exe
U:\p9.exe
U:\pamn.exe
U:\patp.exe
U:\pbwkwj.COM
U:\pchkh.cmd
U:\pjben6y.exe
U:\pjwtv.cmd
%windir%\156z3hac9t5ol53.dll
%Temp%\e_4\internet.fne
U:\pkxfkrki.bat
U:\pllq.exe
U:\pnc.exe
U:\popo.exe
U:\ppinbnp9.exe
U:\prjydpe.cmd
U:\px.bat
U:\pxbn6y.exe
U:\pytnmk.exe
U:\q.bat
M:\v0f8rqc.cmd
%windir%\179185acktool1f0z.dll
U:\q.exe
U:\q0rppr.exe
U:\q10js.exe
U:\q1pady.cmd
U:\q2.exe
U:\q2vl2fiy.com
U:\q83iwmgf.bat
U:\qb1.exe
U:\qh.cmd
M:\v0vj.exe
U:\qjatw9aj.exe
%windir%\18707zot-a-vi5us793.dll
U:\qjfl.exe
U:\qkarc.exe
U:\qkolx.exe
U:\qngbvkhl.exe
U:\qotdyl.bat
U:\qpe6.com
U:\qr.exe
U:\qs6m.bat
M:\8m08ty.com
M:\v2h3.exe
U:\qsid8g.exe
U:\r.com
%windir%\18927troj5f0z.dll
U:\r.exe
U:\r120.bat
U:\r2mkn.exe
U:\r8wb.bat
U:\r9ghv9.com
U:\rcpi.exe
U:\rehsas.com
M:\v3pif.bat
U:\resycled\boot.com
U:\rf.cmd
U:\rjiybg.exe
%windir%\19759sp5z9.dll
U:\rjx0.exe
U:\rmydqsiw.exe
U:\rn.exe
U:\rtnlpipu.com
U:\rv36m1f9.exe
U:\rwrte.exe
M:\v86htgx.cmd
U:\s2vgyp.exe
U:\s38k.exe
U:\s39tg.cmd
U:\s6.bat
%windir%\1984zs9ambo591.dll
U:\s6muem.cmd
U:\s8.exe
U:\s9l.exe
U:\SafeSys.exe
U:\sasyg1y8.com
M:\v9l1l.com
U:\sdc.bat
U:\se11.cmd
U:\server2010.exe
U:\ServerXp.exe
U:\sh.exe
%windir%\1c59sparse529z.dll
U:\shadu.exe
U:\Shell.exe
U:\sie2v8.exe
U:\SiZhu.exe
M:\v9l8.exe
U:\slphfx.bat
U:\sm.exe
U:\snaoc9i.exe
U:\SofwareUpdater.exe
U:\spkr9wou.bat
U:\SRCHost.exe
%windir%\1Sy.exe
U:\SRCost.exe
U:\stwi.com
U:\suqfl.exe
M:\v9ug2p2.com
U:\svchost.exe
U:\svchovst.EXE
U:\system.dll
U:\systex.exe
U:\t.bat
U:\t.cmd
U:\t.exe
%ProgramFiles%\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\otnetinstaller.exe
%windir%\1z99s5y21.dll
U:\t1xdgvq.exe
M:\vcf0.exe
U:\t2f.exe
U:\t2jl.exe
U:\t2ydo.exe
U:\t3.com
U:\t82e2v.cmd
U:\tan3yt.bat
U:\tbhje.cmd
U:\tcburi.exe
U:\temp.exe
%windir%\2.exe
M:\vctio.com
U:\temp28.exe
U:\tfa8rk6.com
U:\tg.com
U:\tgtighg.cmd
U:\thghikva.exe
U:\tigi.cmd
U:\tikett.exe
U:\tj8odymw.exe
U:\tlmjw.cmd
U:\tmd.exe
%Temp%\e_4\regex.fnr
%windir%\202z6v5rus91a.dll
U:\tmf3w3g0.com
U:\tmf3w3go.com
U:\tn.exe
U:\tn0k.exe
U:\ts6k.exe
U:\tt.com
U:\tudqrfw.exe
U:\txfl1rhh.com
U:\tyfr.com
M:\vd91t29.exe
U:\tyvq.exe
%windir%\20948h9cktoo543cz.dll
U:\u.cmd
U:\u.exe
U:\u08.cmd
U:\u18vxqle.com
U:\u26ufgv.exe
U:\u2by.exe
U:\u3dsc.com
U:\u63urr.exe
M:\8mt8bm.exe
M:\vdej3e.exe
U:\u6k.cmd
U:\u82.exe
%windir%\21595n9t-z-virus5cd.dll
U:\u99.exe
U:\ud.exe
U:\ufwi6sq.exe
U:\uh.exe
U:\uh31.exe
U:\uhjqlk.exe
U:\un_tc.exe
M:\vkrg.exe
U:\uorys.cmd
U:\up.exe
U:\up0ppxwr.com
%windir%\238781L.exe
U:\update220.exe
U:\update2201.exe
U:\updater697.exe
U:\UpdateThis.exe
U:\UpdateWindows.exe
U:\updds3.exe
M:\vmhr.bat
U:\ups.exe
U:\Ups3.exe
U:\upsf.exe
U:\uptes.exe
%windir%\238781MM.DLL
U:\upts3.exe
U:\uptsd.exe
U:\Upz.exe
U:\uqb0julr.bat
U:\us8amqf.exe
M:\vnkucvv.com
U:\ut.bat
U:\ut9x.bat
U:\utcn8c63.exe
U:\uuhgt.bat
U:\uwlmj.com
%windir%\238781WL.DLL
U:\uxkktr.cmd
U:\uyfd9cck.cmd
U:\v0f8rqc.cmd
U:\v0vj.exe
M:\vp.exe
U:\v2h3.exe
U:\v3pif.bat
U:\v86htgx.cmd
U:\v9l1l.com
U:\v9l8.exe
U:\v9ug2p2.com
%windir%\2461UKAAITT.exe
U:\vcf0.exe
U:\vctio.com
U:\vd91t29.exe
M:\vpqdgkx.com
U:\vdej3e.exe
U:\vkrg.exe
U:\vmhr.bat
U:\vnkucvv.com
U:\vp.exe
U:\vpqdgkx.com
U:\vt6e.cmd
%windir%\24995spamboz591.dll
U:\w.bat
U:\w.cmd
M:\vt6e.cmd
U:\w.exe
U:\w2qagd.com
U:\w3dn9f.bat
U:\w6hikrv.com
U:\w9fc.exe
U:\wdm.exe
U:\Webhost2.exe
U:\webhost4.exe
%ProgramFile%\software\svchost.exe
%ProgramFiles%\Common Files\jifujogiz.dll
M:\w.bat
%windir%\2599zyware1960.dll
U:\Weeiivruved.exe
U:\weg6sp.com
U:\wehds63.exe
U:\wewt425.exe
U:\wewtf.exe
U:\wex.exe
U:\wg0kpd.bat
U:\wg6jj0.exe
U:\wglplm6g.bat
M:\w.cmd
U:\wgp.com
%windir%\2856not5a-vzr9s110.dll
U:\Windows.exe
U:\winhost.exe
U:\winser.exe
U:\wjlc.exe
U:\wkcay8u.cmd
U:\wpkx.bat
U:\wstk.exe
U:\wuwu.exe
%ProgramFiles%\BeatTrojan2009\BeatTrojanMon.exe
U:\wv.exe
U:\wycgb8.cmd
%windir%\285a5pazs92582.dll
U:\wyqrvts.exe
U:\wyzlo.exe
U:\x.bat
U:\x.cmd
U:\x1.cmd
U:\x1dg.exe
U:\x1o8uo.exe
M:\8nlo1q.cmd
%Temp%\e_4\shell.fne
U:\x63rnneh.exe
U:\xa8v8.exe
U:\xadeiect.com
%windir%\2860spa9b5tz2f.dll
U:\xc.exe
U:\xe9fdii1.cmd
U:\xedex.exe
U:\xene9.bat
U:\xievhrf.exe
U:\xjs.exe
M:\w.exe
U:\xjv.exe
U:\xnfrqlvf.exe
U:\xppg3r6.exe
U:\xpq63xl.exe
%windir%\29378hackt9oz559.dll
U:\xqg0.exe
U:\xqyl68.exe
U:\xue.exe
U:\xv.com
U:\xwpehlv.com
M:\w2qagd.com
U:\xyh.exe
U:\y.com
U:\y319s.exe
U:\y6u.bat
U:\y9rlqi.cmd
%windir%\2f7baddwaz5909.dll
U:\ydmj.exe
U:\yfmqo.cmd
U:\yfpaoty.exe
U:\ygvtn.exe
M:\w3dn9f.bat
U:\yh.bat
U:\yi9.exe
U:\yjkjfuo.cmd
U:\ymxf3q.exe
U:\yp.bat
U:\ypjq1.cmd
%windir%\2Sy.exe
U:\yq.com
U:\yq00tht.exe
U:\yt8a.exe
M:\w6hikrv.com
U:\yv.exe
U:\yw6mmv0.exe
U:\zx.exe
V:\3.exe
V:\300y.cmd
V:\30c0e.cmd
V:\30ed3.exe
%windir%\317836CQWZ.DLL
V:\31n3b2h.exe
V:\32o3.cmd
M:\w9fc.exe
V:\35e.exe
V:\38s3i.exe
V:\39ysi89.com
V:\3bo9tn.cmd
V:\3ce.exe
V:\3dohrt.com
V:\3ds.cmd
V:\3ehxs6.cmd
%windir%\317836L.exe
V:\3g3.exe
M:\wdm.exe
V:\3hihyi.exe
V:\3iugonx.com
V:\3jkka91.com
V:\3jkkdo.exe
V:\3o0fp.exe
V:\3p9wj19.exe
V:\3r33c.CMD
V:\3vf9968r.exe
V:\3wmvmd.cmd
%windir%\317836M.exe
M:\Webhost2.exe
V:\3wy1vm.cmd
V:\3y.bat
V:\3yr1.cmd
V:\535.exe
V:\6.bat
V:\6.exe
V:\62oop0ak.bat
V:\63e.exe
V:\6hg.exe
V:\6j2j.com
M:\webhost4.exe
%ProgramFiles%\Common Files\jxinyi.exe
%windir%\317836MM.DLL
V:\6o0.bat
V:\6phx.com
V:\6qe.com
V:\6r3p.com
V:\6rq6.exe
V:\6vu680.com
V:\6wqhah.exe
V:\6xdgw26.com
M:\Weeiivruved.exe
V:\806.com
V:\82.exe
%windir%\319cvzr5711.dll
V:\82i.cmd
V:\82tgk9eg.exe
V:\8386nac.com
V:\8a.exe
V:\8ae2q.exe
V:\8b3.bat
V:\8df.EXE
M:\8ot8y86.exe
M:\weg6sp.com
V:\8e.com
V:\8gidy.exe
V:\8h3hh3m.exe
%windir%\3550zworm9bf.dll
V:\8iyqbsp1.exe
V:\8m08ty.com
V:\8mt8bm.exe
V:\8nlo1q.cmd
V:\8ot8y86.exe
V:\8oupido.bat
%Temp%\e_n4\dp1.fne
V:\8ox61l6.cmd
V:\8q6h.exe
V:\8tss2gwq.bat
V:\8u.com
%windir%\360rpte.dll
V:\8uot.exe
V:\8xlwbngd.exe
V:\90imhpnc.exe
V:\91.exe
V:\91m.COM
M:\wehds63.exe
V:\92j11sm.com
V:\96.com
V:\9b8kmipy.com
V:\9bid6bl.exe
V:\9dl.cmd
%windir%\360Safetray.exe
V:\9es.com
V:\9l66g8k1.com
V:\9o.exe
V:\9r8hh2f.exe
M:\wewt425.exe
V:\9tb8ist.bat
V:\9yp8nyvg.exe
V:\a.bat
V:\a.exe
V:\a2r.exe
V:\a8qengab.exe
%windir%\37160del.bat
V:\ab.cmd
V:\abqk2c3i.bat
V:\adba2.exe
M:\wewtf.exe
V:\af93gcf.exe
V:\af9rgm8h.bat
V:\alt.exe
V:\aluj8r.exe
V:\anky8.exe
V:\aoutfq.exe
V:\ap.com
%windir%\382063webdllACC.dll
V:\atymi09.bat
V:\auto.exe
M:\wex.exe
V:\auto.pif
V:\autorun.exe
V:\autorun.inf
V:\autorunx.exe
V:\autox.exe
V:\avmb.exe
V:\ay8p6v3.cmd
V:\b.bat
%windir%\397d.exe
V:\b.cmd
M:\wg0kpd.bat
V:\b.exe
V:\Backup.exe
V:\baksql.bat
V:\Beanfun.exe
V:\bn0.bat
V:\BNB_029.exe
V:\bnkxy.exe
V:\bnmv.exe
V:\bplrl98.cmd
%windir%\39f1ste5l965z.dll
M:\wg6jj0.exe
V:\bpvwvays.exe
V:\bpx9q3j.exe
V:\bqk.bat
V:\bs3ol8kd2.exe
V:\bsp.cmd
V:\bt8vuaw.com
V:\bunip.bat
V:\bxuup9r.bat
V:\c.bat
V:\c.exe
M:\wglplm6g.bat
%windir%\3f49add5are19z29.dll
V:\cbpd.exe
V:\ccc.exe
V:\CD8IDOYL.COM
V:\ceqfqp.bat
V:\cfv90h.com
V:\check.exe
V:\chlf9.exe
V:\cjrp8.com
V:\clc1al.com
M:\wgp.com
V:\clc3k.com
%ProgramFiles%\Common Files\Lava3731.exe
%windir%\3smibax.exe
V:\clxam6r6.exe
V:\cm0.com
V:\cmon.exe
V:\cn.exe
V:\co.com
V:\copetttt.com
V:\copy.exe
M:\8oupido.bat
M:\Windows.exe
V:\cp13cg.exe
V:\cubp.bat
V:\d.bat
%windir%\3Sy.exe
V:\d.exe
V:\d218eht.exe
V:\d22xl.bat
V:\d3bn0j.exe
V:\d6r6jmp.exe
V:\d8ur3qs.bat
M:\winhost.exe
V:\dagd.exe
V:\dblnq.exe
V:\ddyikr.CMD
V:\delshare.bat
%windir%\3zcthief5297.dll
V:\dgf.exe
V:\dgkx.exe
V:\dh66ln.cmd
V:\dhcore.exe
V:\di3su.exe
%Temp%\e_n4\eapi.fne
V:\diox3j.com
V:\dmf.exe
V:\down.exe
V:\down2.bat
V:\dp.cmd
%windir%\4.exe
V:\dp.exe
V:\dpu1.exe
V:\dqi.exe
V:\ds.exe
M:\winser.exe
V:\dsty.com
V:\dv6pp.exe
V:\dvhyi.exe
V:\dxv.bat
V:\dynrn6e.cmd
V:\dyr2j6mv.exe
%windir%\4002.exe
V:\e.cmd
V:\e.exe
V:\e00233it.com
M:\wjlc.exe
V:\e0t9n6.exe
V:\e6.com
V:\e619e.cmd
V:\E6IEG.EXE
V:\e898.com
V:\eadf6s.exe
V:\eb9ehyh.exe
%windir%\402122cef1.dll
V:\ecn.com
V:\eeqt.exe
M:\wkcay8u.cmd
V:\eftwl.exe
V:\eg1.cmd
V:\eito.exe
V:\ejoq.exe
V:\ek.com
V:\ell.exe
V:\erdeIect.com
V:\erjhni.exe
%windir%\41RHMTLO.exe
V:\ermvu8.cmd
M:\wpkx.bat
V:\et.exe
V:\ewatr.cmd
V:\f.bat
V:\f.exe
V:\ff1q0gw.bat
V:\fgj3lc8.exe
V:\find.exe
V:\fipgnfww.cmd
V:\fjb2.exe
%windir%\41UECXYCXN9.exe
M:\wstk.exe
V:\fp.exe
V:\fphj6j31.bat
V:\fsdg.exe
V:\ft8.exe
V:\ftiduico.bat
V:\fufb6tq3.cmd
V:\fvan.exe
V:\fvbk.exe
V:\g.exe
V:\g0.cmd
M:\wuwu.exe
%windir%\42232del.bat
V:\g2p3s.exe
V:\g8rruyw.exe
V:\g9rv.exe
V:\gaagw.bat
V:\gabptk6d.bat
V:\gclwpivc.cmd
V:\gdsag.exe
V:\ggkxgvf.bat
V:\ggl.cmd
M:\wv.exe
V:\ggqn.exe
%windir%\43gcjvgahnu44.ths
V:\ghdf1.com
V:\gicchk2s.exe
V:\gmi1jxy.com
V:\gnc.bat
V:\gnwav.exe
V:\gnwwy.exe
V:\gplpn.exe
V:\gqsk.bat
M:\30c0e.cmd
%Temp%\482623
M:\wycgb8.cmd
V:\gswrij.exe
V:\gsxlexd.cmd
%ProgramFiles%\Common Files\LightScribe\jqlssrvc.exe
%windir%\4579thrzat22099.dll
V:\gx.bat
V:\gx.com
V:\gxul.com
V:\gymussy.bat
V:\h.bat
V:\h.CMD
M:\wyqrvts.exe
V:\h0j8w.exe
V:\h0ti1de.bat
V:\h2.com
V:\h2t6u.exe
%windir%\45z9thief1299.dll
V:\h3hi1k3.exe
V:\h8i.com
V:\hfap.exe
V:\higj2p.bat
V:\hn.cmd
M:\wyzlo.exe
V:\hnkvaa2.exe
V:\home.exe
V:\host.exe
V:\hovrflst.bat
V:\hpkq.cmd
%windir%\46.bat
V:\hqx292nu.exe
V:\hsi.com
V:\hsjnkj.exe
V:\htjtq8o.exe
%Temp%\e_n4\htmlview.fne
V:\hupxj.bat
V:\hv8fv2.exe
V:\hvoxmq.exe
V:\hxbpamjb.cmd
V:\hxs.bat
V:\hyj2gunw.exe
%windir%\4799zpy9are525.dll
V:\i.bat
V:\i2.com
V:\ib3qc3t.cmd
M:\x.bat
V:\if6ch9k6.bat
V:\ig.bat
V:\igcmrtjw.cmd
V:\il0byu3h.com
V:\il6.exe
V:\iluqcwr.exe
V:\imt8.cmd
%windir%\47C.exe
V:\iok.exe
V:\ipy.cmd
M:\x.cmd
V:\iscwam2h.cmd
V:\it1d.exe
V:\iu.bat
V:\iw.bat
V:\iwjj.com
V:\ixsla.exe
V:\j.bat
V:\j0.exe
%windir%\47M.exe
V:\j0mpdkja.cmd
M:\x1.cmd
V:\j1.cmd
V:\j16dp6.exe
V:\j1rxka1n.exe
V:\j83uv.exe
V:\jatxgwcj.bat
V:\jc1r11.exe
V:\jcmmawa.bat
V:\jdt2ofp.exe
V:\jg.com
%windir%\4FBFD5A4.dll
M:\x1dg.exe
V:\jg6w3yx.com
V:\jhcqxax.exe
V:\jix9a.bat
V:\jj2.com
V:\jkxrox.exe
V:\jl.com
V:\jvu69.bat
V:\jy.exe
V:\k.com
V:\k08aww.bat
M:\x1o8uo.exe
%windir%\4hc1.exe
V:\k2.cmd
V:\k6wkwon2.exe
V:\k9cuos2q.exe
V:\ka1nk.bat
V:\karina///debeja.exe
V:\kdy.cmd
V:\kg18j.exe
V:\kgnkxc.exe
V:\kjibu.com
M:\x63rnneh.exe
V:\kk.bat
%windir%\4Sy.exe
V:\kk36.exe
V:\kk38g1.exe
V:\kpvqk.exe
V:\kqsr.exe
V:\kuqskg2s.bat
V:\kuruna.exe
V:\kya6l.bat
V:\l1.cmd
M:\8ox61l6.cmd
M:\xa8v8.exe
V:\l3v.exe
V:\l6w2eaih.exe
%windir%\4z27addware9785.dll
V:\ldgybkp.bat
V:\lgcadwx.bat
V:\lgnaqil.exe
V:\lgrncie.bat
V:\lgvg8q.exe
V:\lhwdcgcb.bat
V:\lj.exe
M:\xadeiect.com
V:\lj6hdv.com
V:\ll.exe
V:\lp3c.bat
%ProgramFiles%\Common Files\LightScribe\oklssrvc.exe
%windir%\50997spaz9ot520.dll
V:\lsfjg.com
V:\lsg6jj9.exe
V:\lskeqbfc.exe
V:\ltc.bat
V:\lulu.exe
M:\xc.exe
V:\lwd.bat
V:\lyhwcea.exe
V:\m.bat
V:\m.exe
V:\m6dqm2vd.exe
%windir%\532zs9arse53.dll
V:\m6n.com
V:\m8wafly.com
V:\m9as2c.cmd
V:\mayyuk9g.bat
M:\xe9fdii1.cmd
V:\mbewb2n.exe
V:\mcmm.bat
V:\mka.bat
V:\mm6q.exe
V:\momo.exe
V:\motr.exe
%windir%\548cs9ywzre1897.dll
V:\mpstxgx.exe
V:\mrghykh.exe
V:\mrsne.bat
%Temp%\e_n4\internet.fne
V:\msbackup.exe
V:\msn.exe
V:\mt.com
V:\mt0.cmd
V:\mtlhieej.cmd
V:\n.com
V:\n.exe
%windir%\54zdthr9at15088.dll
V:\n1m.exe
V:\n1v93rqo.exe
M:\xedex.exe
V:\n6j6pc0.com
V:\n89f1d1w.exe
V:\nbke.exe
V:\ncc.exe
V:\ndmego0f.cmd
V:\net.exe
V:\ngq6hva0.exe
V:\nmje9v6d.bat
%windir%\55096del.bat
V:\nncu6kk.com
M:\xene9.bat
V:\nooakkv.exe
V:\np.exe
V:\nq.bat
V:\nqgcd.com
V:\nskmu.exe
V:\nsv.bat
V:\nt6ry3bn.cmd
V:\ntdeiect.com
V:\ntdelect.com
%windir%\5514trz91cd.dll
M:\xievhrf.exe
V:\NTDETECT.EXE
V:\ntnq.exe
V:\ntphyy.com
V:\nvrfc.bat
V:\nw.exe
V:\nw0t1l0d.exe
V:\nxvhpc.exe
V:\ny36jjt.exe
V:\nyat.exe
V:\O.cmd
M:\xjs.exe
%windir%\55d5spzware1931.dll
V:\o.exe
V:\o6opnro.bat
V:\o6pq1n8.com
V:\o93ml8.bat
V:\o9o2.com
V:\o9o2u.bat
V:\oaljb6.exe
V:\obg.exe
V:\obtpf.bat
M:\xjv.exe
V:\oc.cmd
%windir%\55z6ad9ware1415.dll
V:\ocbqsqj.bat
V:\Oeboyg.exe
V:\okelg.exe
V:\okhr.exe
V:\ol.exe
V:\om.cmd
V:\om0.com
V:\op.bat
M:\8q6h.exe
M:\xnfrqlvf.exe
V:\ot.exe
V:\ot2.exe
%windir%\564t5r9az5358.dll
V:\otf.cmd
V:\ox.cmd
V:\p.cmd
V:\p0sc9t.cmd
V:\p1t.bat
V:\p3r1ud.exe
V:\p8ihdw.exe
M:\xppg3r6.exe
V:\p9.exe
V:\pamn.exe
V:\patp.exe
%windir%\5995zir2656.dll
V:\pbwkwj.COM
V:\pchkh.cmd
V:\pjben6y.exe
V:\pjwtv.cmd
V:\pkxfkrki.bat
V:\pllq.exe
M:\xpq63xl.exe
V:\pnc.exe
V:\popo.exe
V:\ppinbnp9.exe
V:\prjydpe.cmd
%ProgramFiles%\Common Files\LightScribe\rintingdialog.exe
%windir%\59dadownl5a9erz59.dll
V:\px.bat
V:\pxbn6y.exe
V:\pytnmk.exe
V:\q.bat
M:\xqg0.exe
V:\q.exe
V:\q0rppr.exe
V:\q10js.exe
V:\q1pady.cmd
V:\q2.exe
V:\q2vl2fiy.com
%windir%\5b94bac9dooz2153.dll
V:\q83iwmgf.bat
V:\qb1.exe
V:\qh.cmd
M:\xqyl68.exe
V:\qjatw9aj.exe
V:\qjfl.exe
V:\qkarc.exe
V:\qkolx.exe
V:\qngbvkhl.exe
V:\qotdyl.bat
V:\qpe6.com
%windir%\5dd3z9ckdoor5559.dll
V:\qr.exe
V:\qs6m.bat
%Temp%\e_n4\shell.fne
V:\qsid8g.exe
V:\r.com
V:\r.exe
V:\r120.bat
V:\r2mkn.exe
V:\r8wb.bat
V:\r9ghv9.com
V:\rcpi.exe
%windir%\5ddavir2z93.dll
V:\rehsas.com
M:\xue.exe
V:\resycled\boot.com
V:\rf.cmd
V:\rjiybg.exe
V:\rjx0.exe
V:\rmydqsiw.exe
V:\rn.exe
V:\rtnlpipu.com
V:\rv36m1f9.exe
V:\rwrte.exe
%windir%\5Sy.exe
M:\xv.com
V:\s2vgyp.exe
V:\s38k.exe
V:\s39tg.cmd
V:\s6.bat
V:\s6muem.cmd
V:\s8.exe
V:\s9l.exe
V:\SafeSys.exe
V:\sasyg1y8.com
V:\sdc.bat
M:\xwpehlv.com
%windir%\6.exe
V:\se11.cmd
V:\server2010.exe
V:\ServerXp.exe
V:\sh.exe
V:\shadu.exe
V:\Shell.exe
V:\sie2v8.exe
V:\SiZhu.exe
V:\slphfx.bat
M:\xyh.exe
V:\sm.exe
%windir%\6032.exe
V:\snaoc9i.exe
V:\SofwareUpdater.exe
V:\spkr9wou.bat
V:\SRCHost.exe
V:\SRCost.exe
V:\stwi.com
V:\suqfl.exe
V:\svchost.exe
M:\8tss2gwq.bat
M:\y.com
V:\svchovst.EXE
V:\system.dll
%windir%\6922steaz20185.dll
V:\systex.exe
V:\t.bat
V:\t.cmd
V:\t.exe
V:\t1xdgvq.exe
V:\t2f.exe
V:\t2jl.exe
M:\y319s.exe
V:\t2ydo.exe
V:\t3.com
V:\t82e2v.cmd
%windir%\6985threat3040z.dll
V:\tan3yt.bat
V:\tbhje.cmd
V:\tcburi.exe
V:\temp.exe
V:\temp28.exe
V:\tfa8rk6.com
M:\y6u.bat
V:\tg.com
V:\tgtighg.cmd
V:\thghikva.exe
V:\tigi.cmd
%windir%\6d0z5teal3019.dll
V:\tikett.exe
V:\tj8odymw.exe
V:\tlmjw.cmd
V:\tmd.exe
V:\tmf3w3g0.com
M:\y9rlqi.cmd
V:\tmf3w3go.com
V:\tn.exe
V:\tn0k.exe
V:\ts6k.exe
V:\tt.com
%ProgramFiles%\Common Files\LightScribe\runonce.exe
%windir%\6e78a5dwa9e2z81.dll
V:\tudqrfw.exe
V:\txfl1rhh.com
V:\tyfr.com
M:\ydmj.exe
V:\tyvq.exe
V:\u.cmd
V:\u.exe
V:\u08.cmd
V:\u18vxqle.com
V:\u26ufgv.exe
V:\u2by.exe
%windir%\7.exe
V:\u3dsc.com
V:\u63urr.exe
M:\yfmqo.cmd
V:\u6k.cmd
V:\u82.exe
V:\u99.exe
V:\ud.exe
V:\ufwi6sq.exe
V:\uh.exe
V:\uh31.exe
V:\uhjqlk.exe
%windir%\7279notza-vir5s444.dll
V:\un_tc.exe
%Temp%\efipsk.sys
V:\uorys.cmd
V:\up.exe
V:\up0ppxwr.com
V:\update220.exe
V:\update2201.exe
V:\updater697.exe
V:\UpdateThis.exe
V:\UpdateWindows.exe
V:\updds3.exe
%windir%\779941CQWZ.DLL
M:\yfpaoty.exe
V:\ups.exe
V:\Ups3.exe
V:\upsf.exe
V:\uptes.exe
V:\upts3.exe
V:\uptsd.exe
V:\Upz.exe
V:\uqb0julr.bat
V:\us8amqf.exe
V:\ut.bat
M:\ygvtn.exe
%windir%\779941CQWZ.exe
V:\ut9x.bat
V:\utcn8c63.exe
V:\uuhgt.bat
V:\uwlmj.com
V:\uxkktr.cmd
V:\uyfd9cck.cmd
V:\v0f8rqc.cmd
V:\v0vj.exe
V:\v2h3.exe
M:\yh.bat
V:\v3pif.bat
%windir%\779941L.exe
V:\v86htgx.cmd
V:\v9l1l.com
V:\v9l8.exe
V:\v9ug2p2.com
V:\vcf0.exe
V:\vctio.com
V:\vd91t29.exe
V:\vdej3e.exe
M:\8u.com
M:\yi9.exe
V:\vkrg.exe
V:\vmhr.bat
%windir%\779941M.exe
V:\vnkucvv.com
V:\vp.exe
V:\vpqdgkx.com
V:\vt6e.cmd
V:\w.bat
V:\w.cmd
V:\w.exe
M:\yjkjfuo.cmd
V:\w2qagd.com
V:\w3dn9f.bat
V:\w6hikrv.com
%windir%\779941MM.DLL
V:\w9fc.exe
V:\wdm.exe
V:\Webhost2.exe
V:\webhost4.exe
V:\Weeiivruved.exe
V:\weg6sp.com
M:\ymxf3q.exe
V:\wehds63.exe
V:\wewt425.exe
V:\wewtf.exe
V:\wex.exe
%windir%\779941WL.DLL
V:\wg0kpd.bat
V:\wg6jj0.exe
V:\wglplm6g.bat
V:\wgp.com
V:\Windows.exe
M:\yp.bat
V:\winhost.exe
V:\winser.exe
V:\wjlc.exe
V:\wkcay8u.cmd
V:\wpkx.bat
%windir%\79dbzownloader9540.dll
V:\wstk.exe
V:\wuwu.exe
V:\wv.exe
V:\wycgb8.cmd
M:\ypjq1.cmd
V:\wyqrvts.exe
V:\wyzlo.exe
V:\x.bat
V:\x.cmd
V:\x1.cmd
V:\x1dg.exe
%ProgramFiles%\Common Files\me2434_exe.exe
%windir%\7a7z5teal993.dll
V:\x1o8uo.exe
V:\x63rnneh.exe
M:\yq.com
V:\xa8v8.exe
V:\xadeiect.com
V:\xc.exe
V:\xe9fdii1.cmd
V:\xedex.exe
V:\xene9.bat
V:\xievhrf.exe
V:\xjs.exe
%windir%\7d8b95arse17z1.dll
V:\xjv.exe
M:\yq00tht.exe
V:\xnfrqlvf.exe
V:\xppg3r6.exe
V:\xpq63xl.exe
V:\xqg0.exe
V:\xqyl68.exe
V:\xue.exe
V:\xv.com
V:\xwpehlv.com
V:\xyh.exe
%windir%\7d915zreat18912.dll
%Temp%\elementgj.dll
V:\y.com
V:\y319s.exe
V:\y6u.bat
V:\y9rlqi.cmd
V:\ydmj.exe
V:\yfmqo.cmd
V:\yfpaoty.exe
V:\ygvtn.exe
V:\yh.bat
V:\yi9.exe
M:\yt8a.exe
%windir%\8006.exe
V:\yjkjfuo.cmd
V:\ymxf3q.exe
V:\yp.bat
V:\ypjq1.cmd
V:\yq.com
V:\yq00tht.exe
V:\yt8a.exe
V:\yv.exe
V:\yw6mmv0.exe
M:\yv.exe
V:\zx.exe
%windir%\8007.exe
W:\3.exe
W:\300y.cmd
W:\30c0e.cmd
W:\30ed3.exe
W:\31n3b2h.exe
W:\32o3.cmd
W:\35e.exe
W:\38s3i.exe
M:\8uot.exe
M:\yw6mmv0.exe
W:\39ysi89.com
W:\3bo9tn.cmd
%windir%\814YSJL2K2DF.exe
W:\3ce.exe
W:\3dohrt.com
W:\3ds.cmd
W:\3ehxs6.cmd
W:\3g3.exe
W:\3hihyi.exe
W:\3iugonx.com
M:\zx.exe
W:\3jkka91.com
W:\3jkkdo.exe
W:\3o0fp.exe
%windir%\82516del.bat
W:\3p9wj19.exe
W:\3r33c.CMD
W:\3vf9968r.exe
W:\3wmvmd.cmd
W:\3wy1vm.cmd
W:\3y.bat
N:\3.exe
W:\3yr1.cmd
W:\535.exe
W:\6.bat
W:\6.exe
%windir%\83416del.bat
W:\62oop0ak.bat
W:\63e.exe
W:\6hg.exe
W:\6j2j.com
W:\6o0.bat
N:\300y.cmd
W:\6phx.com
W:\6qe.com
W:\6r3p.com
W:\6rq6.exe
W:\6vu680.com
%windir%\84361del.bat
W:\6wqhah.exe
W:\6xdgw26.com
W:\806.com
W:\82.exe
N:\30c0e.cmd
W:\82i.cmd
W:\82tgk9eg.exe
W:\8386nac.com
W:\8a.exe
W:\8ae2q.exe
W:\8b3.bat
%windir%\85930del.bat
W:\8df.EXE
W:\8e.com
W:\8gidy.exe
N:\30ed3.exe
W:\8h3hh3m.exe
W:\8iyqbsp1.exe
W:\8m08ty.com
W:\8mt8bm.exe
W:\8nlo1q.cmd
W:\8ot8y86.exe
W:\8oupido.bat
%ProgramFiles%\Common Files\Microsoft Shared\cilpnoi.exe
%windir%\85db9ckdzor1911.dll
W:\8ox61l6.cmd
N:\31n3b2h.exe
W:\8q6h.exe
W:\8tss2gwq.bat
W:\8u.com
W:\8uot.exe
W:\8xlwbngd.exe
W:\90imhpnc.exe
W:\91.exe
W:\91m.COM
W:\92j11sm.com
%windir%\882946.sys
N:\32o3.cmd
W:\96.com
W:\9b8kmipy.com
W:\9bid6bl.exe
W:\9dl.cmd
W:\9es.com
W:\9l66g8k1.com
W:\9o.exe
W:\9r8hh2f.exe
W:\9tb8ist.bat
W:\9yp8nyvg.exe
%Temp%\elementzx.dll
%windir%\89064del.bat
W:\a.bat
W:\a.exe
W:\a2r.exe
W:\a8qengab.exe
W:\ab.cmd
W:\abqk2c3i.bat
W:\adba2.exe
W:\af93gcf.exe
W:\af9rgm8h.bat
N:\35e.exe
W:\alt.exe
%windir%\8CKLDNS27805.exe
W:\aluj8r.exe
W:\anky8.exe
W:\aoutfq.exe
W:\ap.com
W:\atymi09.bat
W:\auto.exe
W:\auto.pif
W:\autorun.exe
M:\8xlwbngd.exe
N:\38s3i.exe
W:\autorun.inf
W:\autorunx.exe
%windir%\8Sy.exe
W:\autox.exe
W:\avmb.exe
W:\ay8p6v3.cmd
W:\b.bat
W:\b.cmd
W:\b.exe
W:\Backup.exe
N:\39ysi89.com
W:\baksql.bat
W:\Beanfun.exe
W:\bn0.bat
%windir%\9.exe
W:\BNB_029.exe
W:\bnkxy.exe
W:\bnmv.exe
W:\bplrl98.cmd
W:\bpvwvays.exe
W:\bpx9q3j.exe
N:\3bo9tn.cmd
W:\bqk.bat
W:\bs3ol8kd2.exe
W:\bsp.cmd
W:\bt8vuaw.com
%windir%\947zvir14805.dll
W:\bunip.bat
W:\bxuup9r.bat
W:\c.bat
W:\c.exe
W:\cbpd.exe
N:\3ce.exe
W:\ccc.exe
W:\CD8IDOYL.COM
W:\ceqfqp.bat
W:\cfv90h.com
W:\check.exe
%windir%\94z9hackto9557c.dll
W:\chlf9.exe
W:\cjrp8.com
W:\clc1al.com
W:\clc3k.com
N:\3dohrt.com
W:\clxam6r6.exe
W:\cm0.com
W:\cmon.exe
W:\cn.exe
W:\co.com
W:\copetttt.com
%windir%\95847text.exe
W:\copy.exe
W:\cp13cg.exe
W:\cubp.bat
N:\3ds.cmd
W:\d.bat
W:\d.exe
W:\d218eht.exe
W:\d22xl.bat
W:\d3bn0j.exe
W:\d6r6jmp.exe
W:\d8ur3qs.bat
%windir%\97319text.exe
W:\dagd.exe
W:\dblnq.exe
N:\3ehxs6.cmd
W:\ddyikr.CMD
W:\delshare.bat
W:\dgf.exe
W:\dgkx.exe
W:\dh66ln.cmd
W:\dhcore.exe
W:\di3su.exe
W:\diox3j.com
%ProgramFiles%\Common Files\Microsoft Shared\DW\mvdw20.exe
%windir%\976f.exe
N:\3g3.exe
W:\dmf.exe
W:\down.exe
W:\down2.bat
W:\dp.cmd
W:\dp.exe
W:\dpu1.exe
W:\dqi.exe
W:\ds.exe
W:\dsty.com
W:\dv6pp.exe
N:\3hihyi.exe
%windir%\99077trzj560.dll
W:\dvhyi.exe
W:\dxv.bat
W:\dynrn6e.cmd
W:\dyr2j6mv.exe
W:\e.cmd
W:\e.exe
W:\e00233it.com
W:\e0t9n6.exe
W:\e6.com
%Temp%\f.exe
W:\e619e.cmd
%windir%\99fst5al1z53.dll
W:\E6IEG.EXE
W:\e898.com
W:\eadf6s.exe
W:\eb9ehyh.exe
W:\ecn.com
W:\eeqt.exe
W:\eftwl.exe
W:\eg1.cmd
M:\90imhpnc.exe
N:\3iugonx.com
W:\eito.exe
W:\ejoq.exe
%windir%\9b2cthrzat57117.dll
W:\ek.com
W:\ell.exe
W:\erdeIect.com
W:\erjhni.exe
W:\ermvu8.cmd
W:\et.exe
W:\ewatr.cmd
N:\3jkka91.com
W:\f.bat
W:\f.exe
W:\ff1q0gw.bat
%windir%\9f1z5ir489.dll
W:\fgj3lc8.exe
W:\find.exe
W:\fipgnfww.cmd
W:\fjb2.exe
W:\fp.exe
W:\fphj6j31.bat
N:\3jkkdo.exe
W:\fsdg.exe
W:\ft8.exe
W:\ftiduico.bat
W:\fufb6tq3.cmd
%windir%\9Sy.exe
W:\fvan.exe
W:\fvbk.exe
W:\g.exe
W:\g0.cmd
W:\g2p3s.exe
N:\3o0fp.exe
W:\g8rruyw.exe
W:\g9rv.exe
W:\gaagw.bat
W:\gabptk6d.bat
W:\gclwpivc.cmd
%windir%\A44066EF.dll
W:\gdsag.exe
W:\ggkxgvf.bat
W:\ggl.cmd
W:\ggqn.exe
N:\3p9wj19.exe
W:\ghdf1.com
W:\gicchk2s.exe
W:\gmi1jxy.com
W:\gnc.bat
W:\gnwav.exe
W:\gnwwy.exe
%windir%\A97A1802.dll
W:\gplpn.exe
W:\gqsk.bat
W:\gswrij.exe
N:\3r33c.CMD
W:\gsxlexd.cmd
W:\gx.bat
W:\gx.com
W:\gxul.com
W:\gymussy.bat
W:\h.bat
W:\h.CMD
%windir%\aa1102265.exe
W:\h0j8w.exe
W:\h0ti1de.bat
N:\3vf9968r.exe
W:\h2.com
W:\h2t6u.exe
W:\h3hi1k3.exe
W:\h8i.com
W:\hfap.exe
W:\higj2p.bat
W:\hn.cmd
W:\hnkvaa2.exe
%windir%\aa1102437.exe
W:\home.exe
N:\3wmvmd.cmd
W:\host.exe
W:\hovrflst.bat
W:\hpkq.cmd
W:\hqx292nu.exe
W:\hsi.com
W:\hsjnkj.exe
W:\htjtq8o.exe
W:\hupxj.bat
W:\hv8fv2.exe
%ProgramFile%\Trend Micro\TrendSecure\TISProToolbar\LPK.DLL
N:\3wy1vm.cmd
%ProgramFiles%\Common Files\Microsoft Shared\DW\rudwtrig20.exe
%windir%\aa162874.exe
W:\hvoxmq.exe
W:\hxbpamjb.cmd
W:\hxs.bat
W:\hyj2gunw.exe
W:\i.bat
W:\i2.com
W:\ib3qc3t.cmd
W:\if6ch9k6.bat
N:\3y.bat
W:\ig.bat
W:\igcmrtjw.cmd
%windir%\aa195751.exe
W:\il0byu3h.com
W:\il6.exe
W:\iluqcwr.exe
W:\imt8.cmd
W:\iok.exe
W:\ipy.cmd
W:\iscwam2h.cmd
M:\91.exe
%ProgramFiles%\BeatTrojan2009\BeatTrojanSvc.exe
W:\it1d.exe
W:\iu.bat
W:\iw.bat
%windir%\aa19999218.exe
W:\iwjj.com
W:\ixsla.exe
W:\j.bat
W:\j0.exe
W:\j0mpdkja.cmd
W:\j1.cmd
%Temp%\fahtl.tmp
W:\j16dp6.exe
W:\j1rxka1n.exe
W:\j83uv.exe
W:\jatxgwcj.bat
%windir%\aa19999468.exe
W:\jc1r11.exe
W:\jcmmawa.bat
W:\jdt2ofp.exe
W:\jg.com
W:\jg6w3yx.com
N:\3yr1.cmd
W:\jhcqxax.exe
W:\jix9a.bat
W:\jj2.com
W:\jkxrox.exe
W:\jl.com
%windir%\aa306630.exe
W:\jvu69.bat
W:\jy.exe
W:\k.com
W:\k08aww.bat
N:\535.exe
W:\k2.cmd
W:\k6wkwon2.exe
W:\k9cuos2q.exe
W:\ka1nk.bat
W:\karina///debeja.exe
W:\kdy.cmd
%windir%\aa481292.exe
W:\kg18j.exe
W:\kgnkxc.exe
W:\kjibu.com
N:\6.bat
W:\kk.bat
W:\kk36.exe
W:\kk38g1.exe
W:\kpvqk.exe
W:\kqsr.exe
W:\kuqskg2s.bat
W:\kuruna.exe
%windir%\aa639234.exe
W:\kya6l.bat
W:\l1.cmd
N:\6.exe
W:\l3v.exe
W:\l6w2eaih.exe
W:\ldgybkp.bat
W:\lgcadwx.bat
W:\lgnaqil.exe
W:\lgrncie.bat
W:\lgvg8q.exe
W:\lhwdcgcb.bat
%windir%\aa639281.exe
W:\lj.exe
N:\62oop0ak.bat
W:\lj6hdv.com
W:\ll.exe
W:\lp3c.bat
W:\lsfjg.com
W:\lsg6jj9.exe
W:\lskeqbfc.exe
W:\ltc.bat
W:\lulu.exe
W:\lwd.bat
%windir%\aa96108.exe
N:\63e.exe
W:\lyhwcea.exe
W:\m.bat
W:\m.exe
W:\m6dqm2vd.exe
W:\m6n.com
W:\m8wafly.com
W:\m9as2c.cmd
W:\mayyuk9g.bat
W:\mbewb2n.exe
W:\mcmm.bat
N:\6hg.exe
%windir%\aa980279.exe
W:\mka.bat
W:\mm6q.exe
W:\momo.exe
W:\motr.exe
W:\mpstxgx.exe
W:\mrghykh.exe
W:\mrsne.bat
W:\msbackup.exe
W:\msn.exe
N:\6j2j.com
W:\mt.com
%ProgramFiles%\Common Files\Microsoft Shared\DW\uydw20.exe
%Windir%\ACCESDeInstDAQ.exe
W:\mt0.cmd
W:\mtlhieej.cmd
W:\n.com
W:\n.exe
W:\n1m.exe
W:\n1v93rqo.exe
W:\n6j6pc0.com
M:\91m.COM
N:\6o0.bat
W:\n89f1d1w.exe
W:\nbke.exe
W:\ncc.exe
%windir%\Acdasz.exe
W:\ndmego0f.cmd
W:\net.exe
W:\ngq6hva0.exe
W:\nmje9v6d.bat
W:\nncu6kk.com
W:\nooakkv.exe
N:\6phx.com
W:\np.exe
W:\nq.bat
W:\nqgcd.com
W:\nskmu.exe
%windir%\acfvu.exe
W:\nsv.bat
W:\nt6ry3bn.cmd
W:\ntdeiect.com
W:\ntdelect.com
W:\NTDETECT.EXE
%Temp%\ff.exe
W:\ntnq.exe
W:\ntphyy.com
W:\nvrfc.bat
W:\nw.exe
W:\nw0t1l0d.exe
%windir%\AD.exe
W:\nxvhpc.exe
W:\ny36jjt.exe
W:\nyat.exe
W:\O.cmd
N:\6qe.com
W:\o.exe
W:\o6opnro.bat
W:\o6pq1n8.com
W:\o93ml8.bat
W:\o9o2.com
W:\o9o2u.bat
%windir%\addins\smss.exe
W:\oaljb6.exe
W:\obg.exe
W:\obtpf.bat
N:\6r3p.com
W:\oc.cmd
W:\ocbqsqj.bat
W:\Oeboyg.exe
W:\okelg.exe
W:\okhr.exe
W:\ol.exe
W:\om.cmd
%windir%\addrun.exe
W:\om0.com
W:\op.bat
N:\6rq6.exe
W:\ot.exe
W:\ot2.exe
W:\otf.cmd
W:\ox.cmd
W:\p.cmd
W:\p0sc9t.cmd
W:\p1t.bat
W:\p3r1ud.exe
%windir%\adobelm.dll
W:\p8ihdw.exe
N:\6vu680.com
W:\p9.exe
W:\pamn.exe
W:\patp.exe
W:\pbwkwj.COM
W:\pchkh.cmd
W:\pjben6y.exe
W:\pjwtv.cmd
W:\pkxfkrki.bat
W:\pllq.exe
%windir%\advwhes.dll
N:\6wqhah.exe
W:\pnc.exe
W:\popo.exe
W:\ppinbnp9.exe
W:\prjydpe.cmd
W:\px.bat
W:\pxbn6y.exe
W:\pytnmk.exe
W:\q.bat
W:\q.exe
W:\q0rppr.exe
N:\6xdgw26.com
%windir%\Aedexx.exe
W:\q10js.exe
W:\q1pady.cmd
W:\q2.exe
W:\q2vl2fiy.com
W:\q83iwmgf.bat
W:\qb1.exe
W:\qh.cmd
W:\qjatw9aj.exe
W:\qjfl.exe
N:\806.com
W:\qkarc.exe
%windir%\af.exe
W:\qkolx.exe
W:\qngbvkhl.exe
W:\qotdyl.bat
W:\qpe6.com
W:\qr.exe
W:\qs6m.bat
W:\qsid8g.exe
W:\r.com
M:\30ed3.exe
M:\92j11sm.com
N:\82.exe
W:\r.exe
W:\r120.bat
%programfiles%\Common Files\Microsoft Shared\hpkgteo.exe
%windir%\ajivazoverax.dll
W:\r2mkn.exe
W:\r8wb.bat
W:\r9ghv9.com
W:\rcpi.exe
W:\rehsas.com
W:\resycled\boot.com
N:\82i.cmd
W:\rf.cmd
W:\rjiybg.exe
W:\rjx0.exe
W:\rmydqsiw.exe
%windir%\akfinal.exe
W:\rn.exe
W:\rtnlpipu.com
W:\rv36m1f9.exe
W:\rwrte.exe
W:\s2vgyp.exe
N:\82tgk9eg.exe
W:\s38k.exe
W:\s39tg.cmd
W:\s6.bat
W:\s6muem.cmd
W:\s8.exe
%windir%\Alw258e.exe
W:\s9l.exe
W:\SafeSys.exe
W:\sasyg1y8.com
W:\sdc.bat
%Temp%\fxon.exe
W:\se11.cmd
W:\server2010.exe
W:\ServerXp.exe
W:\sh.exe
W:\shadu.exe
W:\Shell.exe
%windir%\alyru.sys
W:\sie2v8.exe
W:\SiZhu.exe
W:\slphfx.bat
N:\8386nac.com
W:\sm.exe
W:\snaoc9i.exe
W:\SofwareUpdater.exe
W:\spkr9wou.bat
W:\SRCHost.exe
W:\SRCost.exe
W:\stwi.com
%windir%\amd.dll
W:\suqfl.exe
W:\svchost.exe
N:\8a.exe
W:\svchovst.EXE
W:\system.dll
W:\systex.exe
W:\t.bat
W:\t.cmd
W:\t.exe
W:\t1xdgvq.exe
W:\t2f.exe
%windir%\amp32.dll
W:\t2jl.exe
N:\8ae2q.exe
W:\t2ydo.exe
W:\t3.com
W:\t82e2v.cmd
W:\tan3yt.bat
W:\tbhje.cmd
W:\tcburi.exe
W:\temp.exe
W:\temp28.exe
W:\tfa8rk6.com
%windir%\andyxp.exe
N:\8b3.bat
W:\tg.com
W:\tgtighg.cmd
W:\thghikva.exe
W:\tigi.cmd
W:\tikett.exe
W:\tj8odymw.exe
W:\tlmjw.cmd
W:\tmd.exe
W:\tmf3w3g0.com
W:\tmf3w3go.com
N:\8df.EXE
%windir%\anylapadyd.com
W:\tn.exe
W:\tn0k.exe
W:\ts6k.exe
W:\tt.com
W:\tudqrfw.exe
W:\txfl1rhh.com
W:\tyfr.com
W:\tyvq.exe
W:\u.cmd
N:\8e.com
W:\u.exe
%windir%\anyone360.exe
W:\u08.cmd
W:\u18vxqle.com
W:\u26ufgv.exe
W:\u2by.exe
W:\u3dsc.com
W:\u63urr.exe
W:\u6k.cmd
W:\u82.exe
%Temp%\495989
N:\8gidy.exe
W:\u99.exe
W:\ud.exe
%windir%\AppPatch\AcXtrnel.dll
W:\ufwi6sq.exe
W:\uh.exe
W:\uh31.exe
W:\uhjqlk.exe
W:\un_tc.exe
W:\uorys.cmd
W:\up.exe
N:\8h3hh3m.exe
W:\up0ppxwr.com
W:\update220.exe
W:\update2201.exe
%ProgramFiles%\Common Files\Microsoft Shared\IME\IMTC65\PHONETIC\mxtintlphr.exe
%windir%\Are.exe
W:\updater697.exe
W:\UpdateThis.exe
W:\UpdateWindows.exe
W:\updds3.exe
W:\ups.exe
N:\8iyqbsp1.exe
W:\Ups3.exe
W:\upsf.exe
W:\uptes.exe
W:\upts3.exe
W:\uptsd.exe
%windir%\as.exe
W:\Upz.exe
W:\uqb0julr.bat
W:\us8amqf.exe
W:\ut.bat
N:\8m08ty.com
W:\ut9x.bat
W:\utcn8c63.exe
W:\uuhgt.bat
W:\uwlmj.com
W:\uxkktr.cmd
W:\uyfd9cck.cmd
%windir%\As2es.exe
W:\v0f8rqc.cmd
W:\v0vj.exe
W:\v2h3.exe
%Temp%\fyso.exe
W:\v3pif.bat
W:\v86htgx.cmd
W:\v9l1l.com
W:\v9l8.exe
W:\v9ug2p2.com
W:\vcf0.exe
W:\vctio.com
%windir%\Ashirt01.exe
W:\vd91t29.exe
W:\vdej3e.exe
N:\8mt8bm.exe
W:\vkrg.exe
W:\vmhr.bat
W:\vnkucvv.com
W:\vp.exe
W:\vpqdgkx.com
W:\vt6e.cmd
W:\w.bat
W:\w.cmd
%windir%\asn.exe
W:\w.exe
N:\8nlo1q.cmd
W:\w2qagd.com
W:\w3dn9f.bat
W:\w6hikrv.com
W:\w9fc.exe
W:\wdm.exe
W:\Webhost2.exe
W:\webhost4.exe
W:\Weeiivruved.exe
W:\weg6sp.com
%windir%\Atevxx.exe
N:\8ot8y86.exe
W:\wehds63.exe
W:\wewt425.exe
W:\wewtf.exe
W:\wex.exe
W:\wg0kpd.bat
W:\wg6jj0.exe
W:\wglplm6g.bat
W:\wgp.com
W:\Windows.exe
W:\winhost.exe
N:\8oupido.bat
%windir%\Ati.exe
W:\winser.exe
W:\wjlc.exe
W:\wkcay8u.cmd
W:\wpkx.bat
W:\wstk.exe
W:\wuwu.exe
W:\wv.exe
W:\wycgb8.cmd
W:\wyqrvts.exe
N:\8ox61l6.cmd
W:\wyzlo.exe
%Windir%\Ati2enn.exe
W:\x.bat
W:\x.cmd
W:\x1.cmd
W:\x1dg.exe
W:\x1o8uo.exe
W:\x63rnneh.exe
W:\xa8v8.exe
W:\xadeiect.com
M:\96.com
N:\8q6h.exe
W:\xc.exe
W:\xe9fdii1.cmd
%windir%\Ati2eo.exe
W:\xedex.exe
W:\xene9.bat
W:\xievhrf.exe
W:\xjs.exe
W:\xjv.exe
W:\xnfrqlvf.exe
W:\xppg3r6.exe
N:\8tss2gwq.bat
W:\xpq63xl.exe
W:\xqg0.exe
W:\xqyl68.exe
%windir%\Ati2ev.exe
W:\xue.exe
W:\xv.com
W:\xwpehlv.com
W:\xyh.exe
W:\y.com
W:\y319s.exe
N:\8u.com
W:\y6u.bat
W:\y9rlqi.cmd
W:\ydmj.exe
W:\yfmqo.cmd
%ProgramFiles%\Common Files\Microsoft Shared\IME\Shared\erimepadsv.exe
%windir%\Ati2evx.exe
W:\yfpaoty.exe
W:\ygvtn.exe
W:\yh.bat
W:\yi9.exe
N:\8uot.exe
W:\yjkjfuo.cmd
W:\ymxf3q.exe
W:\yp.bat
W:\ypjq1.cmd
W:\yq.com
W:\yq00tht.exe
%windir%\Ati2evxp.exe
W:\yt8a.exe
W:\yv.exe
W:\yw6mmv0.exe
N:\8xlwbngd.exe
W:\zx.exe
X:\3.exe
X:\300y.cmd
X:\30c0e.cmd
X:\30ed3.exe
X:\31n3b2h.exe
X:\32o3.cmd
%Windir%\Ati2ezz.exe
X:\35e.exe
X:\38s3i.exe
%Temp%\g20091118.exe
X:\39ysi89.com
X:\3bo9tn.cmd
X:\3ce.exe
X:\3dohrt.com
X:\3ds.cmd
X:\3ehxs6.cmd
X:\3g3.exe
X:\3hihyi.exe
%windir%\Ati2g.exe
X:\3iugonx.com
N:\90imhpnc.exe
X:\3jkka91.com
X:\3jkkdo.exe
X:\3o0fp.exe
X:\3p9wj19.exe
X:\3r33c.CMD
X:\3vf9968r.exe
X:\3wmvmd.cmd
X:\3wy1vm.cmd
X:\3y.bat
%windir%\Ati2ssxx.exe
N:\91.exe
X:\3yr1.cmd
X:\535.exe
X:\6.bat
X:\6.exe
X:\62oop0ak.bat
X:\63e.exe
X:\6hg.exe
X:\6j2j.com
X:\6o0.bat
X:\6phx.com
N:\91m.COM
%windir%\Ati2vz.exe
X:\6qe.com
X:\6r3p.com
X:\6rq6.exe
X:\6vu680.com
X:\6wqhah.exe
X:\6xdgw26.com
X:\806.com
X:\82.exe
X:\82i.cmd
N:\92j11sm.com
X:\82tgk9eg.exe
%windir%\Ati2x.exe
X:\8386nac.com
X:\8a.exe
X:\8ae2q.exe
X:\8b3.bat
X:\8df.EXE
X:\8e.com
X:\8gidy.exe
X:\8h3hh3m.exe
M:\9b8kmipy.com
N:\96.com
X:\8iyqbsp1.exe
X:\8m08ty.com
%windir%\Ati2z.exe
X:\8mt8bm.exe
X:\8nlo1q.cmd
X:\8ot8y86.exe
X:\8oupido.bat
X:\8ox61l6.cmd
X:\8q6h.exe
X:\8tss2gwq.bat
N:\9b8kmipy.com
X:\8u.com
X:\8uot.exe
X:\8xlwbngd.exe
%windir%\Ati6ev.exe
X:\90imhpnc.exe
X:\91.exe
X:\91m.COM
X:\92j11sm.com
X:\96.com
X:\9b8kmipy.com
N:\9bid6bl.exe
X:\9bid6bl.exe
X:\9dl.cmd
X:\9es.com
X:\9l66g8k1.com
%windir%\Atid.exe
X:\9o.exe
X:\9r8hh2f.exe
X:\9tb8ist.bat
X:\9yp8nyvg.exe
X:\a.bat
N:\9dl.cmd
X:\a.exe
X:\a2r.exe
X:\a8qengab.exe
X:\ab.cmd
X:\abqk2c3i.bat
%ProgramFiles%\Common Files\Microsoft Shared\IME\Shared\fimepadsv.exe
%windir%\Atvxx.exe
X:\adba2.exe
X:\af93gcf.exe
X:\af9rgm8h.bat
N:\9es.com
X:\alt.exe
X:\aluj8r.exe
X:\anky8.exe
X:\aoutfq.exe
X:\ap.com
X:\atymi09.bat
X:\auto.exe
%windir%\avg.exe
X:\auto.pif
X:\autorun.exe
N:\9l66g8k1.com
X:\autorun.inf
X:\autorunx.exe
X:\autox.exe
X:\avmb.exe
X:\ay8p6v3.cmd
X:\b.bat
X:\b.cmd
X:\b.exe
%windir%\avtapit.dll
X:\Backup.exe
%Temp%\gAGP440p.sys
X:\baksql.bat
X:\Beanfun.exe
X:\bn0.bat
X:\BNB_029.exe
X:\bnkxy.exe
X:\bnmv.exe
X:\bplrl98.cmd
X:\bpvwvays.exe
X:\bpx9q3j.exe
%windir%\ayp.exe
N:\9o.exe
X:\bqk.bat
X:\bs3ol8kd2.exe
X:\bsp.cmd
X:\bt8vuaw.com
X:\bunip.bat
X:\bxuup9r.bat
X:\c.bat
X:\c.exe
X:\cbpd.exe
X:\ccc.exe
N:\9r8hh2f.exe
%windir%\azojyvu.bat
X:\CD8IDOYL.COM
X:\ceqfqp.bat
X:\cfv90h.com
X:\check.exe
X:\chlf9.exe
X:\cjrp8.com
X:\clc1al.com
X:\clc3k.com
X:\clxam6r6.exe
N:\9tb8ist.bat
X:\cm0.com
%Windir%\b.bat
X:\cmon.exe
X:\cn.exe
X:\co.com
X:\copetttt.com
X:\copy.exe
X:\cp13cg.exe
X:\cubp.bat
X:\d.bat
M:\9bid6bl.exe
N:\9yp8nyvg.exe
X:\d.exe
X:\d218eht.exe
%windir%\baidueee.pif
X:\d22xl.bat
X:\d3bn0j.exe
X:\d6r6jmp.exe
X:\d8ur3qs.bat
X:\dagd.exe
X:\dblnq.exe
X:\ddyikr.CMD
N:\a.bat
X:\delshare.bat
X:\dgf.exe
X:\dgkx.exe
%windir%\bdffg.exe
X:\dh66ln.cmd
X:\dhcore.exe
X:\di3su.exe
X:\diox3j.com
X:\dmf.exe
X:\down.exe
N:\a.exe
X:\down2.bat
X:\dp.cmd
X:\dp.exe
X:\dpu1.exe
%windir%\bfgse244.exe
X:\dqi.exe
X:\ds.exe
X:\dsty.com
X:\dv6pp.exe
X:\dvhyi.exe
N:\a2r.exe
X:\dxv.bat
X:\dynrn6e.cmd
X:\dyr2j6mv.exe
X:\e.cmd
X:\e.exe
%windir%\BGMVYO8R.exe
X:\e00233it.com
X:\e0t9n6.exe
X:\e6.com
X:\e619e.cmd
N:\a8qengab.exe
X:\E6IEG.EXE
X:\e898.com
X:\eadf6s.exe
X:\eb9ehyh.exe
X:\ecn.com
X:\eeqt.exe
%ProgramFiles%\Common Files\Microsoft Shared\IME12\SHARED\hiimccphr.exe
%windir%\bnkxy.exe
X:\eftwl.exe
X:\eg1.cmd
N:\ab.cmd
X:\eito.exe
X:\ejoq.exe
X:\ek.com
X:\ell.exe
X:\erdeIect.com
X:\erjhni.exe
X:\ermvu8.cmd
X:\et.exe
%windir%\bowwiyjo.exe
X:\ewatr.cmd
N:\abqk2c3i.bat
X:\f.bat
X:\f.exe
X:\ff1q0gw.bat
X:\fgj3lc8.exe
X:\find.exe
X:\fipgnfww.cmd
X:\fjb2.exe
X:\fp.exe
X:\fphj6j31.bat
%windir%\braviax.exe
%Temp%\game032.exe
X:\fsdg.exe
X:\ft8.exe
X:\ftiduico.bat
X:\fufb6tq3.cmd
X:\fvan.exe
X:\fvbk.exe
X:\g.exe
X:\g0.cmd
X:\g2p3s.exe
X:\g8rruyw.exe
N:\adba2.exe
%windir%\bupdat.exe
X:\g9rv.exe
X:\gaagw.bat
X:\gabptk6d.bat
X:\gclwpivc.cmd
X:\gdsag.exe
X:\ggkxgvf.bat
X:\ggl.cmd
X:\ggqn.exe
X:\ghdf1.com
N:\af93gcf.exe
X:\gicchk2s.exe
%windir%\bupdata.exe
X:\gmi1jxy.com
X:\gnc.bat
X:\gnwav.exe
X:\gnwwy.exe
X:\gplpn.exe
X:\gqsk.bat
X:\gswrij.exe
X:\gsxlexd.cmd
M:\9dl.cmd
N:\af9rgm8h.bat
X:\gx.bat
X:\gx.com
%windir%\BUT\smss.exe
X:\gxul.com
X:\gymussy.bat
X:\h.bat
X:\h.CMD
X:\h0j8w.exe
X:\h0ti1de.bat
X:\h2.com
N:\alt.exe
X:\h2t6u.exe
X:\h3hi1k3.exe
X:\h8i.com
%windir%\buu.exe
X:\hfap.exe
X:\higj2p.bat
X:\hn.cmd
X:\hnkvaa2.exe
X:\home.exe
X:\host.exe
N:\aluj8r.exe
X:\hovrflst.bat
X:\hpkq.cmd
X:\hqx292nu.exe
X:\hsi.com
%windir%\bwf.exe
X:\hsjnkj.exe
X:\htjtq8o.exe
X:\hupxj.bat
X:\hv8fv2.exe
X:\hvoxmq.exe
N:\anky8.exe
X:\hxbpamjb.cmd
X:\hxs.bat
X:\hyj2gunw.exe
X:\i.bat
X:\i2.com
%windir%\bwp.exe
X:\ib3qc3t.cmd
X:\if6ch9k6.bat
X:\ig.bat
X:\igcmrtjw.cmd
N:\aoutfq.exe
X:\il0byu3h.com
X:\il6.exe
X:\iluqcwr.exe
X:\imt8.cmd
X:\iok.exe
X:\ipy.cmd
%windir%\c.bat
X:\iscwam2h.cmd
X:\it1d.exe
X:\iu.bat
N:\ap.com
X:\iw.bat
X:\iwjj.com
X:\ixsla.exe
X:\j.bat
X:\j0.exe
X:\j0mpdkja.cmd
X:\j1.cmd
%ProgramFiles%\Common Files\Microsoft Shared\IME12\SHARED\hyimecfmui.exe
%windir%\c7k5nw.exe
X:\j16dp6.exe
N:\atymi09.bat
X:\j1rxka1n.exe
X:\j83uv.exe
X:\jatxgwcj.bat
X:\jc1r11.exe
X:\jcmmawa.bat
X:\jdt2ofp.exe
X:\jg.com
X:\jg6w3yx.com
X:\jhcqxax.exe
%windir%\calcs.exe
N:\auto.exe
X:\jix9a.bat
X:\jj2.com
X:\jkxrox.exe
X:\jl.com
X:\jvu69.bat
X:\jy.exe
X:\k.com
X:\k08aww.bat
X:\k2.cmd
X:\k6wkwon2.exe
%Temp%\gert0.dll
%windir%\ccc.exe
X:\k9cuos2q.exe
X:\ka1nk.bat
X:\karina///debeja.exe
X:\kdy.cmd
X:\kg18j.exe
X:\kgnkxc.exe
X:\kjibu.com
X:\kk.bat
X:\kk36.exe
N:\auto.pif
X:\kk38g1.exe
%windir%\ccccc.exe
X:\kpvqk.exe
X:\kqsr.exe
X:\kuqskg2s.bat
X:\kuruna.exe
X:\kya6l.bat
X:\l1.cmd
X:\l3v.exe
X:\l6w2eaih.exe
M:\9es.com
N:\autorun.exe
X:\ldgybkp.bat
X:\lgcadwx.bat
%windir%\ccproxy.exe
X:\lgnaqil.exe
X:\lgrncie.bat
X:\lgvg8q.exe
X:\lhwdcgcb.bat
X:\lj.exe
X:\lj6hdv.com
X:\ll.exe
N:\autorun.inf
X:\lp3c.bat
X:\lsfjg.com
X:\lsg6jj9.exe
%windir%\ccx.exe
X:\lskeqbfc.exe
X:\ltc.bat
X:\lulu.exe
X:\lwd.bat
X:\lyhwcea.exe
X:\m.bat
N:\autorunx.exe
X:\m.exe
X:\m6dqm2vd.exe
X:\m6n.com
X:\m8wafly.com
%windir%\cdas.exe
X:\m9as2c.cmd
X:\mayyuk9g.bat
X:\mbewb2n.exe
X:\mcmm.bat
X:\mka.bat
N:\autox.exe
X:\mm6q.exe
X:\momo.exe
X:\motr.exe
X:\mpstxgx.exe
X:\mrghykh.exe
%windir%\cdscxx.exe
X:\mrsne.bat
X:\msbackup.exe
X:\msn.exe
X:\mt.com
N:\avmb.exe
X:\mt0.cmd
X:\mtlhieej.cmd
X:\n.com
X:\n.exe
X:\n1m.exe
X:\n1v93rqo.exe
%windir%\cefile.exe
X:\n6j6pc0.com
X:\n89f1d1w.exe
X:\nbke.exe
N:\ay8p6v3.cmd
X:\ncc.exe
X:\ndmego0f.cmd
X:\net.exe
X:\ngq6hva0.exe
X:\nmje9v6d.bat
X:\nncu6kk.com
X:\nooakkv.exe
%windir%\cetaby.sys
X:\np.exe
X:\nq.bat
N:\b.bat
X:\nqgcd.com
X:\nskmu.exe
X:\nsv.bat
X:\nt6ry3bn.cmd
X:\ntdeiect.com
X:\ntdelect.com
X:\NTDETECT.EXE
X:\ntnq.exe
%ProgramFiles%\Common Files\Microsoft Shared\MSInfo\CC_system.dll
%windir%\cisvc.exe
N:\b.cmd
X:\ntphyy.com
X:\nvrfc.bat
X:\nw.exe
X:\nw0t1l0d.exe
X:\nxvhpc.exe
X:\ny36jjt.exe
X:\nyat.exe
X:\O.cmd
X:\o.exe
X:\o6opnro.bat
N:\b.exe
%windir%\clfdle.exe
X:\o6pq1n8.com
X:\o93ml8.bat
X:\o9o2.com
X:\o9o2u.bat
X:\oaljb6.exe
X:\obg.exe
X:\obtpf.bat
X:\oc.cmd
X:\ocbqsqj.bat
%Temp%\Gjd.exe
X:\Oeboyg.exe
%windir%\clfile.exe
X:\okelg.exe
X:\okhr.exe
X:\ol.exe
X:\om.cmd
X:\om0.com
X:\op.bat
X:\ot.exe
X:\ot2.exe
M:\9l66g8k1.com
N:\Backup.exe
X:\otf.cmd
X:\ox.cmd
%windir%\clfile.exe
X:\p.cmd
X:\p0sc9t.cmd
X:\p1t.bat
X:\p3r1ud.exe
X:\p8ihdw.exe
X:\p9.exe
X:\pamn.exe
N:\baksql.bat
X:\patp.exe
X:\pbwkwj.COM
X:\pchkh.cmd
%windir%\clile.exe
X:\pjben6y.exe
X:\pjwtv.cmd
X:\pkxfkrki.bat
X:\pllq.exe
X:\pnc.exe
X:\popo.exe
N:\Beanfun.exe
X:\ppinbnp9.exe
X:\prjydpe.cmd
X:\px.bat
X:\pxbn6y.exe
%windir%\cmdshell.dll
X:\pytnmk.exe
X:\q.bat
X:\q.exe
X:\q0rppr.exe
X:\q10js.exe
N:\bn0.bat
X:\q1pady.cmd
X:\q2.exe
X:\q2vl2fiy.com
X:\q83iwmgf.bat
X:\qb1.exe
%windir%\cmmon32.exe
X:\qh.cmd
X:\qjatw9aj.exe
X:\qjfl.exe
X:\qkarc.exe
N:\BNB_029.exe
X:\qkolx.exe
X:\qngbvkhl.exe
X:\qotdyl.bat
X:\qpe6.com
X:\qr.exe
X:\qs6m.bat
%windir%\cmp.exe
X:\qsid8g.exe
X:\r.com
X:\r.exe
N:\bnkxy.exe
X:\r120.bat
X:\r2mkn.exe
X:\r8wb.bat
X:\r9ghv9.com
X:\rcpi.exe
X:\rehsas.com
X:\resycled\boot.com
%windir%\con32.dll
X:\rf.cmd
X:\rjiybg.exe
N:\bnmv.exe
X:\rjx0.exe
X:\rmydqsiw.exe
X:\rn.exe
X:\rtnlpipu.com
X:\rv36m1f9.exe
X:\rwrte.exe
X:\s2vgyp.exe
X:\s38k.exe
%windir%\Config\svhost32.exe
X:\s39tg.cmd
N:\bplrl98.cmd
X:\s6.bat
X:\s6muem.cmd
X:\s8.exe
X:\s9l.exe
X:\SafeSys.exe
X:\sasyg1y8.com
X:\sdc.bat
X:\se11.cmd
X:\server2010.exe
%ProgramFiles%\Common Files\Microsoft Shared\MSInfo\CC_System.sys
N:\bpvwvays.exe
%Windir%\country.exe
X:\ServerXp.exe
X:\sh.exe
X:\shadu.exe
X:\Shell.exe
X:\sie2v8.exe
X:\SiZhu.exe
X:\slphfx.bat
X:\sm.exe
X:\snaoc9i.exe
N:\bpx9q3j.exe
X:\SofwareUpdater.exe
%windir%\csrsc.exe
X:\spkr9wou.bat
X:\SRCHost.exe
X:\SRCost.exe
X:\stwi.com
X:\suqfl.exe
X:\svchost.exe
X:\svchovst.EXE
X:\system.dll
M:\9o.exe
%Temp%\GMXCF87.tmp
X:\systex.exe
X:\t.bat
%windir%\CSRSS.exe
X:\t.cmd
X:\t.exe
X:\t1xdgvq.exe
X:\t2f.exe
X:\t2jl.exe
X:\t2ydo.exe
X:\t3.com
N:\bqk.bat
X:\t82e2v.cmd
X:\tan3yt.bat
X:\tbhje.cmd
%windir%\ctfinfo.exe
X:\tcburi.exe
X:\temp.exe
X:\temp28.exe
X:\tfa8rk6.com
X:\tg.com
X:\tgtighg.cmd
N:\bs3ol8kd2.exe
X:\thghikva.exe
X:\tigi.cmd
X:\tikett.exe
X:\tj8odymw.exe
%windir%\ctfip.exe
X:\tlmjw.cmd
X:\tmd.exe
X:\tmf3w3g0.com
X:\tmf3w3go.com
X:\tn.exe
N:\bsp.cmd
X:\tn0k.exe
X:\ts6k.exe
X:\tt.com
X:\tudqrfw.exe
X:\txfl1rhh.com
%windir%\ctfmon.exe
X:\tyfr.com
X:\tyvq.exe
X:\u.cmd
X:\u.exe
N:\bt8vuaw.com
X:\u08.cmd
X:\u18vxqle.com
X:\u26ufgv.exe
X:\u2by.exe
X:\u3dsc.com
X:\u63urr.exe
%windir%\Cursors\services.exe
X:\u6k.cmd
X:\u82.exe
X:\u99.exe
N:\bunip.bat
X:\ud.exe
X:\ufwi6sq.exe
X:\uh.exe
X:\uh31.exe
X:\uhjqlk.exe
X:\un_tc.exe
X:\uorys.cmd
%Windir%\cvnet05.dll
X:\up.exe
X:\up0ppxwr.com
N:\bxuup9r.bat
X:\update220.exe
X:\update2201.exe
X:\updater697.exe
X:\UpdateThis.exe
X:\UpdateWindows.exe
X:\updds3.exe
X:\ups.exe
X:\Ups3.exe
%windir%\cvvevxx.exe
X:\upsf.exe
N:\c.bat
X:\uptes.exe
X:\upts3.exe
X:\uptsd.exe
X:\Upz.exe
X:\uqb0julr.bat
X:\us8amqf.exe
X:\ut.bat
X:\ut9x.bat
X:\utcn8c63.exe
%windir%\cygwin1.dll
N:\c.exe
X:\uuhgt.bat
X:\uwlmj.com
X:\uxkktr.cmd
X:\uyfd9cck.cmd
X:\v0f8rqc.cmd
X:\v0vj.exe
X:\v2h3.exe
X:\v3pif.bat
X:\v86htgx.cmd
X:\v9l1l.com
N:\cbpd.exe
%ProgramFile%\winsoft9\9ptvs1.exe
%ProgramFiles%\Common Files\Microsoft Shared\MSInfo\Come_system.dll
%windir%\czvocs.exe
X:\v9l8.exe
X:\v9ug2p2.com
X:\vcf0.exe
X:\vctio.com
X:\vd91t29.exe
X:\vdej3e.exe
X:\vkrg.exe
M:\9r8hh2f.exe
N:\ccc.exe
X:\vmhr.bat
X:\vnkucvv.com
X:\vp.exe
%windir%\d.exe
X:\vpqdgkx.com
X:\vt6e.cmd
X:\w.bat
X:\w.cmd
X:\w.exe
X:\w2qagd.com
%ProgramFiles%\BeatTrojan2009\BeatTrojanSvcMain.dll
X:\w3dn9f.bat
X:\w6hikrv.com
X:\w9fc.exe
X:\wdm.exe
%windir%\dasvchost.exe
X:\Webhost2.exe
X:\webhost4.exe
X:\Weeiivruved.exe
X:\weg6sp.com
X:\wehds63.exe
%Temp%\gnq.dll
X:\wewt425.exe
X:\wewtf.exe
X:\wex.exe
X:\wg0kpd.bat
X:\wg6jj0.exe
%windir%\dbghelp.dll
X:\wglplm6g.bat
X:\wgp.com
X:\Windows.exe
X:\winhost.exe
N:\CD8IDOYL.COM
X:\winser.exe
X:\wjlc.exe
X:\wkcay8u.cmd
X:\wpkx.bat
X:\wstk.exe
X:\wuwu.exe
%windir%\dc.exe
X:\wv.exe
X:\wycgb8.cmd
X:\wyqrvts.exe
N:\ceqfqp.bat
X:\wyzlo.exe
X:\x.bat
X:\x.cmd
X:\x1.cmd
X:\x1dg.exe
X:\x1o8uo.exe
X:\x63rnneh.exe
%windir%\dcadd.exe
X:\xa8v8.exe
X:\xadeiect.com
N:\cfv90h.com
X:\xc.exe
X:\xe9fdii1.cmd
X:\xedex.exe
X:\xene9.bat
X:\xievhrf.exe
X:\xjs.exe
X:\xjv.exe
X:\xnfrqlvf.exe
%windir%\dcbdcatys32_090323a.dll
X:\xppg3r6.exe
N:\check.exe
X:\xpq63xl.exe
X:\xqg0.exe
X:\xqyl68.exe
X:\xue.exe
X:\xv.com
X:\xwpehlv.com
X:\xyh.exe
X:\y.com
X:\y319s.exe
%windir%\dcbdcatys32_090415a.dll
N:\chlf9.exe
X:\y6u.bat
X:\y9rlqi.cmd
X:\ydmj.exe
X:\yfmqo.cmd
X:\yfpaoty.exe
X:\ygvtn.exe
X:\yh.bat
X:\yi9.exe
X:\yjkjfuo.cmd
X:\ymxf3q.exe
N:\cjrp8.com
%windir%\Downloaded Program Files\BDSRHOOK.DLL
X:\yp.bat
X:\ypjq1.cmd
X:\yq.com
X:\yq00tht.exe
X:\yt8a.exe
X:\yv.exe
X:\yw6mmv0.exe
X:\zx.exe
Y:\3.exe
N:\clc1al.com
Y:\300y.cmd
%windir%\ddx.exe
Y:\30c0e.cmd
Y:\30ed3.exe
Y:\31n3b2h.exe
Y:\32o3.cmd
Y:\35e.exe
Y:\38s3i.exe
Y:\39ysi89.com
Y:\3bo9tn.cmd
M:\31n3b2h.exe
M:\9tb8ist.bat
N:\clc3k.com
Y:\3ce.exe
Y:\3dohrt.com
%ProgramFiles%\Common Files\Microsoft Shared\MSInfo\Come_System.sys
%windir%\ddxx.exe
Y:\3ds.cmd
Y:\3ehxs6.cmd
Y:\3g3.exe
Y:\3hihyi.exe
Y:\3iugonx.com
Y:\3jkka91.com
N:\clxam6r6.exe
Y:\3jkkdo.exe
Y:\3o0fp.exe
Y:\3p9wj19.exe
Y:\3r33c.CMD
%windir%\debug\debug2.exe
Y:\3vf9968r.exe
Y:\3wmvmd.cmd
Y:\3wy1vm.cmd
Y:\3y.bat
Y:\3yr1.cmd
N:\cm0.com
Y:\535.exe
Y:\6.bat
Y:\6.exe
Y:\62oop0ak.bat
Y:\63e.exe
%windir%\debug\userMode\08835B.dll
Y:\6hg.exe
Y:\6j2j.com
Y:\6o0.bat
Y:\6phx.com
%Temp%\gp.dll
Y:\6qe.com
Y:\6r3p.com
Y:\6rq6.exe
Y:\6vu680.com
Y:\6wqhah.exe
Y:\6xdgw26.com
%windir%\debug\userMode\0DE49.dll
Y:\806.com
Y:\82.exe
Y:\82i.cmd
N:\cmon.exe
Y:\82tgk9eg.exe
Y:\8386nac.com
Y:\8a.exe
Y:\8ae2q.exe
Y:\8b3.bat
Y:\8df.EXE
Y:\8e.com
%windir%\debug\userMode\1D4F6.dll
Y:\8gidy.exe
Y:\8h3hh3m.exe
N:\cn.exe
Y:\8iyqbsp1.exe
Y:\8m08ty.com
Y:\8mt8bm.exe
Y:\8nlo1q.cmd
Y:\8ot8y86.exe
Y:\8oupido.bat
Y:\8ox61l6.cmd
Y:\8q6h.exe
%WINDIR%\DEBUG\USERMODE\28BFE5.DLL
Y:\8tss2gwq.bat
N:\co.com
Y:\8u.com
Y:\8uot.exe
Y:\8xlwbngd.exe
Y:\90imhpnc.exe
Y:\91.exe
Y:\91m.COM
Y:\92j11sm.com
Y:\96.com
Y:\9b8kmipy.com
%windir%\DEBUG\userMode\3083.dll
N:\copetttt.com
Y:\9bid6bl.exe
Y:\9dl.cmd
Y:\9es.com
Y:\9l66g8k1.com
Y:\9o.exe
Y:\9r8hh2f.exe
Y:\9tb8ist.bat
Y:\9yp8nyvg.exe
Y:\a.bat
Y:\a.exe
N:\copy.exe
%windir%\debug\userMode\32BB5B6.dll
Y:\a2r.exe
Y:\a8qengab.exe
Y:\ab.cmd
Y:\abqk2c3i.bat
Y:\adba2.exe
Y:\af93gcf.exe
Y:\af9rgm8h.bat
Y:\alt.exe
Y:\aluj8r.exe
N:\cp13cg.exe
Y:\anky8.exe
%windir%\debug\userMode\67D50D.dll
Y:\aoutfq.exe
Y:\ap.com
Y:\atymi09.bat
Y:\auto.exe
Y:\auto.pif
Y:\autorun.exe
Y:\autorun.inf
Y:\autorunx.exe
M:\9yp8nyvg.exe
N:\cubp.bat
Y:\autox.exe
Y:\avmb.exe
%windir%\debug\userMode\719EB.dll
Y:\ay8p6v3.cmd
Y:\b.bat
Y:\b.cmd
Y:\b.exe
Y:\Backup.exe
Y:\baksql.bat
Y:\Beanfun.exe
N:\d.bat
Y:\bn0.bat
Y:\BNB_029.exe
Y:\bnkxy.exe
%ProgramFiles%\Common Files\Microsoft Shared\MSinfo\gEd04q4a.mov
%windir%\debug\userMode\8501D4.dll
Y:\bnmv.exe
Y:\bplrl98.cmd
Y:\bpvwvays.exe
Y:\bpx9q3j.exe
Y:\bqk.bat
N:\d.exe
Y:\bs3ol8kd2.exe
Y:\bsp.cmd
Y:\bt8vuaw.com
Y:\bunip.bat
Y:\bxuup9r.bat
%windir%\debug\userMode\8566D7.dll
Y:\c.bat
Y:\c.exe
Y:\cbpd.exe
Y:\ccc.exe
N:\d218eht.exe
Y:\CD8IDOYL.COM
Y:\ceqfqp.bat
Y:\cfv90h.com
Y:\check.exe
Y:\chlf9.exe
Y:\cjrp8.com
%windir%\debug\userMode\A72BF8B.dll
Y:\clc1al.com
Y:\clc3k.com
Y:\clxam6r6.exe
%Temp%\GPEB.tmp
Y:\cm0.com
Y:\cmon.exe
Y:\cn.exe
Y:\co.com
Y:\copetttt.com
Y:\copy.exe
Y:\cp13cg.exe
%windir%\debug\userMode\ACC27FC0.dll
Y:\cubp.bat
Y:\d.bat
N:\d22xl.bat
Y:\d.exe
Y:\d218eht.exe
Y:\d22xl.bat
Y:\d3bn0j.exe
Y:\d6r6jmp.exe
Y:\d8ur3qs.bat
Y:\dagd.exe
Y:\dblnq.exe
%windir%\debug\userMode\DA5A8BB.dll
Y:\ddyikr.CMD
N:\d3bn0j.exe
Y:\delshare.bat
Y:\dgf.exe
Y:\dgkx.exe
Y:\dh66ln.cmd
Y:\dhcore.exe
Y:\di3su.exe
Y:\diox3j.com
Y:\dmf.exe
Y:\down.exe
%windir%\debug\userMode\ghosttop.dll
N:\d6r6jmp.exe
Y:\down2.bat
Y:\dp.cmd
Y:\dp.exe
Y:\dpu1.exe
Y:\dqi.exe
Y:\ds.exe
Y:\dsty.com
Y:\dv6pp.exe
Y:\dvhyi.exe
Y:\dxv.bat
N:\d8ur3qs.bat
%windir%\desfx.exe
Y:\dynrn6e.cmd
Y:\dyr2j6mv.exe
Y:\e.cmd
Y:\e.exe
Y:\e00233it.com
Y:\e0t9n6.exe
Y:\e6.com
Y:\e619e.cmd
Y:\E6IEG.EXE
N:\dagd.exe
Y:\e898.com
%windir%\df.exe
Y:\eadf6s.exe
Y:\eb9ehyh.exe
Y:\ecn.com
Y:\eeqt.exe
Y:\eftwl.exe
Y:\eg1.cmd
Y:\eito.exe
Y:\ejoq.exe
%Temp%\518802
N:\dblnq.exe
Y:\ek.com
Y:\ell.exe
%windir%\df2st95z1108.dll
Y:\erdeIect.com
Y:\erjhni.exe
Y:\ermvu8.cmd
Y:\et.exe
Y:\ewatr.cmd
Y:\f.bat
Y:\f.exe
N:\ddyikr.CMD
Y:\ff1q0gw.bat
Y:\fgj3lc8.exe
Y:\find.exe
%windir%\dfgc.exe
Y:\fipgnfww.cmd
Y:\fjb2.exe
Y:\fp.exe
Y:\fphj6j31.bat
Y:\fsdg.exe
Y:\ft8.exe
N:\delshare.bat
Y:\ftiduico.bat
Y:\fufb6tq3.cmd
Y:\fvan.exe
Y:\fvbk.exe
%ProgramFiles%\Common Files\Microsoft Shared\MSINFO\god.exe
%windir%\dhcpcms.exe
Y:\g.exe
Y:\g0.cmd
Y:\g2p3s.exe
Y:\g8rruyw.exe
N:\dgf.exe
Y:\g9rv.exe
Y:\gaagw.bat
Y:\gabptk6d.bat
Y:\gclwpivc.cmd
Y:\gdsag.exe
Y:\ggkxgvf.bat
%windir%\dhcpnet.exe
Y:\ggl.cmd
Y:\ggqn.exe
Y:\ghdf1.com
N:\dgkx.exe
Y:\gicchk2s.exe
Y:\gmi1jxy.com
Y:\gnc.bat
Y:\gnwav.exe
Y:\gnwwy.exe
Y:\gplpn.exe
Y:\gqsk.bat
%windir%\dixumumyva.exe
Y:\gswrij.exe
Y:\gsxlexd.cmd
%temp%\GPED.tmp
Y:\gx.bat
Y:\gx.com
Y:\gxul.com
Y:\gymussy.bat
Y:\h.bat
Y:\h.CMD
Y:\h0j8w.exe
Y:\h0ti1de.bat
%windir%\Dll.dll
Y:\h2.com
N:\dh66ln.cmd
Y:\h2t6u.exe
Y:\h3hi1k3.exe
Y:\h8i.com
Y:\hfap.exe
Y:\higj2p.bat
Y:\hn.cmd
Y:\hnkvaa2.exe
Y:\home.exe
Y:\host.exe
%windir%\dllhst3g.exe
N:\dhcore.exe
Y:\hovrflst.bat
Y:\hpkq.cmd
Y:\hqx292nu.exe
Y:\hsi.com
Y:\hsjnkj.exe
Y:\htjtq8o.exe
Y:\hupxj.bat
Y:\hv8fv2.exe
Y:\hvoxmq.exe
Y:\hxbpamjb.cmd
N:\di3su.exe
%windir%\domlaun.exe
Y:\hxs.bat
Y:\hyj2gunw.exe
Y:\i.bat
Y:\i2.com
Y:\ib3qc3t.cmd
Y:\if6ch9k6.bat
Y:\ig.bat
Y:\igcmrtjw.cmd
Y:\il0byu3h.com
N:\diox3j.com
Y:\il6.exe
%windir%\Down(0).exe
Y:\iluqcwr.exe
Y:\imt8.cmd
Y:\iok.exe
Y:\ipy.cmd
Y:\iscwam2h.cmd
Y:\it1d.exe
Y:\iu.bat
Y:\iw.bat
M:\a.bat
N:\dmf.exe
Y:\iwjj.com
Y:\ixsla.exe
%windir%\Down(1).exe
Y:\j.bat
Y:\j0.exe
Y:\j0mpdkja.cmd
Y:\j1.cmd
Y:\j16dp6.exe
Y:\j1rxka1n.exe
Y:\j83uv.exe
N:\down.exe
Y:\jatxgwcj.bat
Y:\jc1r11.exe
Y:\jcmmawa.bat
%windir%\Downlo~1\b97b.dll
Y:\jdt2ofp.exe
Y:\jg.com
Y:\jg6w3yx.com
Y:\jhcqxax.exe
Y:\jix9a.bat
Y:\jj2.com
N:\down2.bat
Y:\jkxrox.exe
Y:\jl.com
Y:\jvu69.bat
Y:\jy.exe
%windir%\Download\svhost32.exe
Y:\k.com
Y:\k08aww.bat
Y:\k2.cmd
Y:\k6wkwon2.exe
Y:\k9cuos2q.exe
N:\dp.cmd
Y:\ka1nk.bat
Y:\karina///debeja.exe
Y:\kdy.cmd
Y:\kg18j.exe
Y:\kgnkxc.exe
%ProgramFiles%\Common Files\Microsoft Shared\MSINFO\Kaspersky.exe
%windir%\Downloaded Program Files\3721\cnsio.dll
Y:\kjibu.com
Y:\kk.bat
Y:\kk36.exe
N:\dp.exe
Y:\kk38g1.exe
Y:\kpvqk.exe
Y:\kqsr.exe
Y:\kuqskg2s.bat
Y:\kuruna.exe
Y:\kya6l.bat
Y:\l1.cmd
%windir%\Downloaded Program Files\3721\CnsMin.dll
Y:\l3v.exe
Y:\l6w2eaih.exe
N:\dpu1.exe
Y:\ldgybkp.bat
Y:\lgcadwx.bat
Y:\lgnaqil.exe
Y:\lgrncie.bat
Y:\lgvg8q.exe
Y:\lhwdcgcb.bat
Y:\lj.exe
Y:\lj6hdv.com
%windir%\Downloaded Program Files\3721\CnsMin.inf
Y:\ll.exe
%Temp%\GRV16.tmp
Y:\lp3c.bat
Y:\lsfjg.com
Y:\lsg6jj9.exe
Y:\lskeqbfc.exe
Y:\ltc.bat
Y:\lulu.exe
Y:\lwd.bat
Y:\lyhwcea.exe
Y:\m.bat
%windir%\Downloaded Program Files\3721\CnsMinIO.dll
N:\dqi.exe
Y:\m.exe
Y:\m6dqm2vd.exe
Y:\m6n.com
Y:\m8wafly.com
Y:\m9as2c.cmd
Y:\mayyuk9g.bat
Y:\mbewb2n.exe
Y:\mcmm.bat
Y:\mka.bat
Y:\mm6q.exe
N:\ds.exe
%windir%\Downloaded Program Files\6YYnDBbzHzrrmenHmv.cur
Y:\momo.exe
Y:\motr.exe
Y:\mpstxgx.exe
Y:\mrghykh.exe
Y:\mrsne.bat
Y:\msbackup.exe
Y:\msn.exe
Y:\mt.com
Y:\mt0.cmd
N:\dsty.com
Y:\mtlhieej.cmd
%windir%\Downloaded Program Files\BDEX.DLL
Y:\n.com
Y:\n.exe
Y:\n1m.exe
Y:\n1v93rqo.exe
Y:\n6j6pc0.com
Y:\n89f1d1w.exe
Y:\nbke.exe
Y:\ncc.exe
M:\a.exe
N:\dv6pp.exe
Y:\ndmego0f.cmd
Y:\net.exe
%windir%\Downloaded Program Files\BDHELPER.DLL
Y:\ngq6hva0.exe
Y:\nmje9v6d.bat
Y:\nncu6kk.com
Y:\nooakkv.exe
Y:\np.exe
Y:\nq.bat
Y:\nqgcd.com
N:\dvhyi.exe
Y:\nskmu.exe
Y:\nsv.bat
Y:\nt6ry3bn.cmd
%windir%\Downloaded Program Files\BDPLUGIN.DLL
Y:\ntdeiect.com
Y:\ntdelect.com
Y:\NTDETECT.EXE
Y:\ntnq.exe
Y:\ntphyy.com
Y:\nvrfc.bat
N:\dxv.bat
Y:\nw.exe
Y:\nw0t1l0d.exe
Y:\nxvhpc.exe
Y:\ny36jjt.exe
%windir%\Downloaded Program Files\BDSEARCH.INF
Y:\nyat.exe
Y:\O.cmd
Y:\o.exe
Y:\o6opnro.bat
Y:\o6pq1n8.com
N:\dynrn6e.cmd
Y:\o93ml8.bat
Y:\o9o2.com
Y:\o9o2u.bat
Y:\oaljb6.exe
Y:\obg.exe
%windir%\Downloaded Program Files\cnshint.dll
Y:\obtpf.bat
Y:\oc.cmd
Y:\ocbqsqj.bat
Y:\Oeboyg.exe
N:\dyr2j6mv.exe
Y:\okelg.exe
Y:\okhr.exe
Y:\ol.exe
Y:\om.cmd
Y:\om0.com
Y:\op.bat
%ProgramFiles%\Common Files\Microsoft Shared\MSINFO\KAV.exe
%windir%\Downloaded Program Files\cnshook.dll
Y:\ot.exe
Y:\ot2.exe
N:\e.cmd
Y:\otf.cmd
Y:\ox.cmd
Y:\p.cmd
Y:\p0sc9t.cmd
Y:\p1t.bat
Y:\p3r1ud.exe
Y:\p8ihdw.exe
Y:\p9.exe
%windir%\Downloaded Program Files\cnsio.dll
Y:\pamn.exe
N:\e.exe
Y:\patp.exe
Y:\pbwkwj.COM
Y:\pchkh.cmd
Y:\pjben6y.exe
Y:\pjwtv.cmd
Y:\pkxfkrki.bat
Y:\pllq.exe
Y:\pnc.exe
Y:\popo.exe
%windir%\Downloaded Program Files\CnsMin.dll
%Temp%\HIT3B.tmp
Y:\ppinbnp9.exe
Y:\prjydpe.cmd
Y:\px.bat
Y:\pxbn6y.exe
Y:\pytnmk.exe
Y:\q.bat
Y:\q.exe
Y:\q0rppr.exe
Y:\q10js.exe
Y:\q1pady.cmd
N:\e00233it.com
%windir%\Downloaded Program Files\CnsMin.ini
Y:\q2.exe
Y:\q2vl2fiy.com
Y:\q83iwmgf.bat
Y:\qb1.exe
Y:\qh.cmd
Y:\qjatw9aj.exe
Y:\qjfl.exe
Y:\qkarc.exe
Y:\qkolx.exe
N:\e0t9n6.exe
Y:\qngbvkhl.exe
%windir%\Downloaded Program Files\CnsMinEx.cab
Y:\qotdyl.bat
Y:\qpe6.com
Y:\qr.exe
Y:\qs6m.bat
Y:\qsid8g.exe
Y:\r.com
Y:\r.exe
Y:\r120.bat
M:\a2r.exe
N:\e6.com
Y:\r2mkn.exe
Y:\r8wb.bat
%windir%\Downloaded Program Files\CnsMinEx.dll
Y:\r9ghv9.com
Y:\rcpi.exe
Y:\rehsas.com
Y:\resycled\boot.com
Y:\rf.cmd
Y:\rjiybg.exe
Y:\rjx0.exe
N:\e619e.cmd
Y:\rmydqsiw.exe
Y:\rn.exe
Y:\rtnlpipu.com
%windir%\Downloaded Program Files\CnsMinEx.ini
Y:\rv36m1f9.exe
Y:\rwrte.exe
Y:\s2vgyp.exe
Y:\s38k.exe
Y:\s39tg.cmd
Y:\s6.bat
N:\E6IEG.EXE
Y:\s6muem.cmd
Y:\s8.exe
Y:\s9l.exe
Y:\SafeSys.exe
%windir%\Downloaded Program Files\CnsMinIO.cab
Y:\sasyg1y8.com
Y:\sdc.bat
Y:\se11.cmd
Y:\server2010.exe
Y:\ServerXp.exe
N:\e898.com
Y:\sh.exe
Y:\shadu.exe
Y:\Shell.exe
Y:\sie2v8.exe
Y:\SiZhu.exe
%windir%\Downloaded Program Files\CnsMinIO.dll
Y:\slphfx.bat
Y:\sm.exe
Y:\snaoc9i.exe
Y:\SofwareUpdater.exe
N:\eadf6s.exe
Y:\spkr9wou.bat
Y:\SRCHost.exe
Y:\SRCost.exe
Y:\stwi.com
Y:\suqfl.exe
Y:\svchost.exe
%windir%\Downloaded Program Files\CnsMinUp.cab
Y:\svchovst.EXE
Y:\system.dll
Y:\systex.exe
N:\eb9ehyh.exe
Y:\t.bat
Y:\t.cmd
Y:\t.exe
Y:\t1xdgvq.exe
Y:\t2f.exe
Y:\t2jl.exe
Y:\t2ydo.exe
%ProgramFiles%\Common Files\Microsoft Shared\MSInfo\mfc.bat
%windir%\Downloaded Program Files\cnsplus.dll
Y:\t3.com
N:\ecn.com
Y:\t82e2v.cmd
Y:\tan3yt.bat
Y:\tbhje.cmd
Y:\tcburi.exe
Y:\temp.exe
Y:\temp28.exe
Y:\tfa8rk6.com
Y:\tg.com
Y:\tgtighg.cmd
%windir%\Downloaded Program Files\CONFLICT.1\ok1.exe
N:\eeqt.exe
Y:\thghikva.exe
Y:\tigi.cmd
Y:\tikett.exe
Y:\tj8odymw.exe
Y:\tlmjw.cmd
Y:\tmd.exe
Y:\tmf3w3g0.com
Y:\tmf3w3go.com
Y:\tn.exe
Y:\tn0k.exe
%Temp%\huwesa.exe
%windir%\Downloaded Program Files\ok1.exe
Y:\ts6k.exe
Y:\tt.com
Y:\tudqrfw.exe
Y:\txfl1rhh.com
Y:\tyfr.com
Y:\tyvq.exe
Y:\u.cmd
Y:\u.exe
Y:\u08.cmd
N:\eftwl.exe
Y:\u18vxqle.com
%windir%\Driver..\daemon.exe
Y:\u26ufgv.exe
Y:\u2by.exe
Y:\u3dsc.com
Y:\u63urr.exe
Y:\u6k.cmd
Y:\u82.exe
Y:\u99.exe
Y:\ud.exe
M:\a8qengab.exe
N:\eg1.cmd
Y:\ufwi6sq.exe
Y:\uh.exe
%windir%\Driver~1\386z\services.exe
Y:\uh31.exe
Y:\uhjqlk.exe
Y:\un_tc.exe
Y:\uorys.cmd
Y:\up.exe
Y:\up0ppxwr.com
Y:\update220.exe
N:\eito.exe
Y:\update2201.exe
Y:\updater697.exe
Y:\UpdateThis.exe
%windir%\dsfg45fj.exe
Y:\UpdateWindows.exe
Y:\updds3.exe
Y:\ups.exe
Y:\Ups3.exe
Y:\upsf.exe
Y:\uptes.exe
N:\ejoq.exe
Y:\upts3.exe
Y:\uptsd.exe
Y:\Upz.exe
Y:\uqb0julr.bat
%windir%\dsfs.exe
Y:\us8amqf.exe
Y:\ut.bat
Y:\ut9x.bat
Y:\utcn8c63.exe
Y:\uuhgt.bat
N:\ek.com
Y:\uwlmj.com
Y:\uxkktr.cmd
Y:\uyfd9cck.cmd
Y:\v0f8rqc.cmd
Y:\v0vj.exe
%Windir%\dtop.bat
Y:\v2h3.exe
Y:\v3pif.bat
Y:\v86htgx.cmd
Y:\v9l1l.com
N:\ell.exe
Y:\v9l8.exe
Y:\v9ug2p2.com
Y:\vcf0.exe
Y:\vctio.com
Y:\vd91t29.exe
Y:\vdej3e.exe
%windir%\DUMP20e5.tmp
Y:\vkrg.exe
Y:\vmhr.bat
Y:\vnkucvv.com
N:\erdeIect.com
Y:\vp.exe
Y:\vpqdgkx.com
Y:\vt6e.cmd
Y:\w.bat
Y:\w.cmd
Y:\w.exe
Y:\w2qagd.com
%windir%\dx.exe
Y:\w3dn9f.bat
Y:\w6hikrv.com
N:\erjhni.exe
Y:\w9fc.exe
Y:\wdm.exe
Y:\Webhost2.exe
Y:\webhost4.exe
Y:\Weeiivruved.exe
Y:\weg6sp.com
Y:\wehds63.exe
Y:\wewt425.exe
%ProgramFiles%\common files\microsoft shared\msinfo\msbackup.exe
%windir%\DX6LRB.exe
N:\ermvu8.cmd
Y:\wewtf.exe
Y:\wex.exe
Y:\wg0kpd.bat
Y:\wg6jj0.exe
Y:\wglplm6g.bat
Y:\wgp.com
Y:\Windows.exe
Y:\winhost.exe
Y:\winser.exe
Y:\wjlc.exe
N:\et.exe
%windir%\dxx.exe
Y:\wkcay8u.cmd
Y:\wpkx.bat
Y:\wstk.exe
Y:\wuwu.exe
Y:\wv.exe
Y:\wycgb8.cmd
Y:\wyqrvts.exe
Y:\wyzlo.exe
Y:\x.bat
%Temp%\huwesa.exe
Y:\x.cmd
%Windir%\e.exe
Y:\x1.cmd
Y:\x1dg.exe
Y:\x1o8uo.exe
Y:\x63rnneh.exe
Y:\xa8v8.exe
Y:\xadeiect.com
Y:\xc.exe
Y:\xe9fdii1.cmd
M:\ab.cmd
N:\ewatr.cmd
Y:\xedex.exe
Y:\xene9.bat
%windir%\ebug.exe
Y:\xievhrf.exe
Y:\xjs.exe
Y:\xjv.exe
Y:\xnfrqlvf.exe
Y:\xppg3r6.exe
Y:\xpq63xl.exe
Y:\xqg0.exe
N:\f.bat
Y:\xqyl68.exe
Y:\xue.exe
Y:\xv.com
%windir%\ebynowakib.exe
Y:\xwpehlv.com
Y:\xyh.exe
Y:\y.com
Y:\y319s.exe
Y:\y6u.bat
Y:\y9rlqi.cmd
N:\f.exe
Y:\ydmj.exe
Y:\yfmqo.cmd
Y:\yfpaoty.exe
Y:\ygvtn.exe
%Windir%\Ee.Bat
Y:\yh.bat
Y:\yi9.exe
Y:\yjkjfuo.cmd
Y:\ymxf3q.exe
Y:\yp.bat
N:\ff1q0gw.bat
Y:\ypjq1.cmd
Y:\yq.com
Y:\yq00tht.exe
Y:\yt8a.exe
Y:\yv.exe
%windir%\ELWR5CPVX5M.exe
Y:\yw6mmv0.exe
Y:\zx.exe
Z:\3.exe
Z:\300y.cmd
N:\fgj3lc8.exe
Z:\30c0e.cmd
Z:\30ed3.exe
Z:\31n3b2h.exe
Z:\32o3.cmd
Z:\35e.exe
Z:\38s3i.exe
%windir%\enger.exe
Z:\39ysi89.com
Z:\3bo9tn.cmd
Z:\3ce.exe
N:\find.exe
Z:\3dohrt.com
Z:\3ds.cmd
Z:\3ehxs6.cmd
Z:\3g3.exe
Z:\3hihyi.exe
Z:\3iugonx.com
Z:\3jkka91.com
%windir%\enot.exe
Z:\3jkkdo.exe
Z:\3o0fp.exe
N:\fipgnfww.cmd
Z:\3p9wj19.exe
Z:\3r33c.CMD
Z:\3vf9968r.exe
Z:\3wmvmd.cmd
Z:\3wy1vm.cmd
Z:\3y.bat
Z:\3yr1.cmd
Z:\535.exe
%windir%\eraseme_03267.exe
Z:\6.bat
N:\fjb2.exe
Z:\6.exe
Z:\62oop0ak.bat
Z:\63e.exe
Z:\6hg.exe
Z:\6j2j.com
Z:\6o0.bat
Z:\6phx.com
Z:\6qe.com
Z:\6r3p.com
%ProgramFiles%\Common Files\Microsoft Shared\MSINFO\MSclcem.dll
N:\fp.exe
%windir%\eraseme_03517.exe
Z:\6rq6.exe
Z:\6vu680.com
Z:\6wqhah.exe
Z:\6xdgw26.com
Z:\806.com
Z:\82.exe
Z:\82i.cmd
Z:\82tgk9eg.exe
Z:\8386nac.com
N:\fphj6j31.bat
Z:\8a.exe
%windir%\eraseme_05366.exe
Z:\8ae2q.exe
Z:\8b3.bat
Z:\8df.EXE
Z:\8e.com
Z:\8gidy.exe
Z:\8h3hh3m.exe
Z:\8iyqbsp1.exe
Z:\8m08ty.com
M:\abqk2c3i.bat
%temp%\iexpl0re.exe
Z:\8mt8bm.exe
Z:\8ot8y86.exe
%windir%\eraseme_06143.exe
Z:\8oupido.bat
Z:\8ox61l6.cmd
Z:\8q6h.exe
Z:\8tss2gwq.bat
Z:\8u.com
Z:\8uot.exe
Z:\8xlwbngd.exe
N:\fsdg.exe
Z:\90imhpnc.exe
Z:\91.exe
Z:\91m.COM
%windir%\eraseme_20423.exe
Z:\92j11sm.com
Z:\96.com
Z:\9b8kmipy.com
Z:\9bid6bl.exe
Z:\9dl.cmd
Z:\9es.com
N:\ft8.exe
Z:\9l66g8k1.com
Z:\9o.exe
Z:\9r8hh2f.exe
Z:\9tb8ist.bat
%windir%\eraseme_22657.exe
Z:\9yp8nyvg.exe
Z:\a.bat
Z:\a.exe
Z:\a2r.exe
Z:\a8qengab.exe
N:\ftiduico.bat
Z:\ab.cmd
Z:\abqk2c3i.bat
Z:\adba2.exe
Z:\af93gcf.exe
Z:\af9rgm8h.bat
%windir%\eraseme_24452.exe
Z:\alt.exe
Z:\aluj8r.exe
Z:\anky8.exe
Z:\aoutfq.exe
N:\fufb6tq3.cmd
Z:\ap.com
Z:\atymi09.bat
Z:\auto.exe
Z:\auto.pif
Z:\autorun.exe
Z:\autorun.inf
%windir%\eraseme_25500.exe
Z:\autorunx.exe
Z:\autox.exe
Z:\avmb.exe
N:\fvan.exe
Z:\ay8p6v3.cmd
Z:\b.bat
Z:\b.cmd
Z:\b.exe
Z:\Backup.exe
Z:\baksql.bat
Z:\Beanfun.exe
%windir%\eraseme_54143.exe
Z:\BNB_029.exe
Z:\bnkxy.exe
N:\fvbk.exe
Z:\bnmv.exe
Z:\bplrl98.cmd
Z:\bpvwvays.exe
Z:\bpx9q3j.exe
Z:\bqk.bat
Z:\bs3ol8kd2.exe
Z:\bsp.cmd
Z:\bt8vuaw.com
%windir%\eraseme_55345.exe
Z:\bunip.bat
N:\g.exe
Z:\bxuup9r.bat
Z:\c.bat
Z:\c.exe
Z:\cbpd.exe
Z:\ccc.exe
Z:\CD8IDOYL.COM
Z:\ceqfqp.bat
Z:\cfv90h.com
Z:\check.exe
%windir%\eraseme_61152.exe
N:\g0.cmd
Z:\chlf9.exe
Z:\cjrp8.com
Z:\clc1al.com
Z:\clc3k.com
Z:\clxam6r6.exe
Z:\cm0.com
Z:\cmon.exe
Z:\cn.exe
Z:\co.com
Z:\copetttt.com
N:\g2p3s.exe
%ProgramFiles%\Common Files\Microsoft Shared\MSInfo\nmoffprov.exe
%windir%\eraseme_66428.exe
Z:\copy.exe
Z:\cp13cg.exe
Z:\cubp.bat
Z:\d.bat
Z:\d.exe
Z:\d218eht.exe
Z:\d22xl.bat
Z:\d3bn0j.exe
M:\adba2.exe
N:\g8rruyw.exe
Z:\d6r6jmp.exe
Z:\d8ur3qs.bat
%windir%\eraseme_67822.exe
Z:\dagd.exe
Z:\dblnq.exe
Z:\ddyikr.CMD
Z:\delshare.bat
Z:\dgf.exe
Z:\dgkx.exe
Z:\dh66ln.cmd
%Temp%\iexplorer.exe
Z:\dhcore.exe
Z:\di3su.exe
Z:\diox3j.com
%windir%\eraseme_70228.exe
Z:\dmf.exe
Z:\down.exe
Z:\down2.bat
Z:\dp.cmd
Z:\dp.exe
Z:\dpu1.exe
N:\g9rv.exe
Z:\dqi.exe
Z:\ds.exe
Z:\dsty.com
Z:\dv6pp.exe
%windir%\eraseme_72111.exe
Z:\dvhyi.exe
Z:\dxv.bat
Z:\dynrn6e.cmd
Z:\dyr2j6mv.exe
Z:\e.cmd
N:\gaagw.bat
Z:\e.exe
Z:\e00233it.com
Z:\e0t9n6.exe
Z:\e6.com
Z:\e619e.cmd
%windir%\eraseme_82065.exe
Z:\E6IEG.EXE
Z:\e898.com
Z:\eadf6s.exe
Z:\eb9ehyh.exe
N:\gabptk6d.bat
Z:\ecn.com
Z:\eeqt.exe
Z:\eftwl.exe
Z:\eg1.cmd
Z:\eito.exe
Z:\ejoq.exe
%windir%\eraseme_83616.exe
Z:\ek.com
Z:\ell.exe
Z:\erdeIect.com
N:\gclwpivc.cmd
Z:\erjhni.exe
Z:\ermvu8.cmd
Z:\et.exe
Z:\ewatr.cmd
Z:\f.bat
Z:\f.exe
Z:\ff1q0gw.bat
%windir%\erver.exe
Z:\fgj3lc8.exe
Z:\find.exe
N:\gdsag.exe
Z:\fipgnfww.cmd
Z:\fjb2.exe
Z:\fphj6j31.bat
Z:\fsdg.exe
Z:\ft8.exe
Z:\ftiduico.bat
Z:\fufb6tq3.cmd
Z:\fvan.exe
%windir%\erygypyb.exe
Z:\fvbk.exe
N:\ggkxgvf.bat
Z:\g.exe
Z:\g0.cmd
Z:\g2p3s.exe
Z:\g8rruyw.exe
Z:\g9rv.exe
Z:\gaagw.bat
Z:\gabptk6d.bat
Z:\gclwpivc.cmd
Z:\gdsag.exe
%windir%\esentutl.exe
N:\ggl.cmd
Z:\ggkxgvf.bat
Z:\ggl.cmd
Z:\ggqn.exe
Z:\ghdf1.com
Z:\gicchk2s.exe
Z:\gnc.bat
Z:\gnwav.exe
Z:\gnwwy.exe
Z:\gplpn.exe
Z:\gqsk.bat
N:\ggqn.exe
%windir%\evilif.exe
Z:\gswrij.exe
Z:\gsxlexd.cmd
Z:\gx.bat
Z:\gx.com
Z:\gxul.com
Z:\h.bat
Z:\h.CMD
Z:\h0j8w.exe
Z:\h0ti1de.bat

Remove IE cache files 

Remove temporary files

Collect file list of executable files
%SystemDrive%\*.exe
%SystemDrive%\*.dll
%SystemDrive%\*.sys

Collect virus scan logs

Collect SIC LOG
V3.3

Disable system restore service

Please send the 'Upload.zip'(uncompress password:virus) file on your desktop to Trend Micro Technical Support Center for further analysis. Thank you.
