..\Software\Microsoft\Windows\CurrentVersion\Run\\"svchost"\"%root%\input\20987_exploit.win32.activepost_20091123\ac5ab6c2.exe" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"dskpsrvc"\"%DAS%\admin\Local Settings\Temp\53ff4ae1.exe" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"rundll"\"%DAS%\admin\Local Settings\Temp\0de3a190.exe" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"PRINTER SERVICE"\"%DAS%\admin\Local Settings\Temp\59953312.exe" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"PROXY SERVER"\"%DAS.AU.LS%\TEMP\581739AC.EXE" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"proxy server" |