..\Software\Microsoft\Windows\CurrentVersion\policies\explorer\run\"qlkjilcf"\"rundll32.exe "%WIN.SYS32%\sechonqp.sys" WLEntryPoint" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"fapkjmlg"\"rundll32.exe %DAS.AU.LS%\Temp\browqhgrm.nls WLEntryPoint" |
..\System\CurrentControlSet\Services\hebvvvhz\(Default) |
..\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\mhgbid\(Default) |
..\Software\Microsoft\Windows NT\CurrentVersion\\"NTInternalSign"\"30013897" |
..\Software\Microsoft\Windows\CurrentVersion\policies\explorer\run\"etcjqtgr"\"rundll32.exe "%WIN.SYS32%\perfatorq.dll" WLEntryPoint" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"orqpcfid"\"rundll32.exe %DAS.AU.LS%\Temp\tcpknqp.sys WLEntryPoint" |
..\Software\Classes\Clsid\{177D637B-5849-B877-11E2-F9A7B4D01EA5}\(Default) |
..\System\CurrentControlSet\Services\iegmovco\(Default) |
..\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\napsjmhcnmt\(Default) |