..\Software\Microsoft\Windows\CurrentVersion\\"Lastpop"\"1" |
..\Software\Microsoft\Windows\CurrentVersion\RunOnce\\"Winsock2 driver"\"WINSYSTEM32.EXE" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"ntl1cs.exe"\"%WIN.SYS32%\ntl1cs.exe" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"Winsock2 driver"\"WINSYSTEM32.EXE" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"SAHBundle"\"%DAS.AU.LS%\Temp\bundle.exe" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"xhrmy"\"%WIN%\Xhrmy.exe" |
..\Software\Microsoft\Windows\CurrentVersion\policies\explorer\run\"winlogon.exe"\"msole32.exe" |
..\Software\Microsoft\Internet Explorer\URLSearchHooks\"{5D60FF48-95BE-4956-B4C6-6BB168A70310}" |
..\Software\Classes\BHO.IncrediFindBHO.1\(Default) |
..\Software\Classes\BHO.IncrediFindBHO\(Default) |