..\Software\Microsoft\Windows\CurrentVersion\Run\\"rnbw"\"%WIN.SYS32%\rnbw\ggikindk.exe" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"boby"\"%WIN.SYS32%\csrs.scr" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"TROJAN-SPY.WIN32.BANKER.BEC"\"%DAS.AU.LS%\Temp\TROJAN-SPY.WIN32.BANKER.BEC.EXE" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"Protection"\"%WIN%\nprotects.exe" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"LG32-SWAP"\"%DAS.AU.LS%\Temp\TROJAN-SPY.WIN32.BANKER.BD.EXE" |
..\Software\Classes\{5415486-112364-77845-44457}\(Default) |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"WineWork"\"%WIN.SYS32%\WorkFile.exe" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"SYSTEM32"\"%WIN.SYS32%\SYSTEM32.EXE" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"WMEDIA32"\"WMEDIA32.EXE" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"msrunonce"\""%win.sys%\iexplorer.exe"" |