..\Software\Microsoft\Windows NT\CurrentVersion\image file execution options\fssm32.exe\(Default) |
..\Software\Microsoft\active setup\installed components\{cae4973b-6e51-eaa7-e215-21afaeb0dc78}\(Default) |
..\Software\Microsoft\active setup\installed components\{8cee828f-507a-d288-f5b2-f375d6640dc0}\(Default) |
..\System\CurrentControlSet\Enum\root\legacy_ntservice\(Default) |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"jdbtray"\"%root%\input\11139_backdoor.win32.agent_20091109\c84d4111.exe" |
..\Software\Microsoft\wbem\"udbb"\"trza2kipko9es6ok+jdyk/lcpe2p5qqffvzsmadiactw7lpzlyhik87m6ko" |
..\System\CurrentControlSet\Enum\root\legacy_sysloader\(Default) |
..\System\CurrentControlSet\Enum\root\legacy_windows_update_servrices!\(Default) |
..\System\CurrentControlSet\Services\windows update servrices!\(Default) |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"vxvfkhgt.exe"\"%win%\vxvfkhgt.exe" |