..\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\"dcom server 60787"\"{2c1cd3d7-86ac-4068-93bc-a02304b60787}" |
..\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\"{2c1cd3d7-86ac-4068-93bc-a02304b60787}"\"dcom server 60787" |
..\Software\Microsoft\Windows NT\CurrentVersion\Windows\\"APPINIT_DLLS"\"%WIN.SYS32%\RXJH.DLL" |
..\Software\Microsoft\Windows NT\CurrentVersion\Windows\\"APPINIT_DLLS"\"%WIN.SYS32%\QOEMSL.DLL" |
..\System\CurrentControlSet\Services\MICROSOFT INTERNET SERVICE\(Default) |
..\Software\Classes\Clsid\{3F0E0DCD-278B-4799-88CF-02F200E58A57}\(Default) |
..\Software\Classes\Clsid\{FFFFFFFF-F538-4F86-ABAF-E9D94D5C007C}\(Default) |
..\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3F0E0DCD-278B-4799-88CF-02F200E58A57}\(Default) |
..\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-F538-4F86-ABAF-E9D94D5C007C}\(Default) |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"MICROSOFT WINDOWS DLL LOADER"\"%ROOT%\INPUT\TROJAN-SPY.WIN32.AGENT.CCY\218C9CE0.EXE" |