..\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\"%WIN.SYS32%\mpxa.exe"\"%WIN.SYS32%\mpxa.exe:*:Enabled:mpxa" |
..\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\"%PF%\Microsoft Office\Office\WINWORD.EXE"\"%PF%\Microsoft Office\Office\WINWORD.EXE:*:Enabled:WINWORD" |
..\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\"{98672103-AFBE-4434-92D2-692A124CD60F}" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"kenuhesogu"\"Rundll32.exe "%WIN.SYS32%\repudana.dll",s" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"CPM7b8dcba1"\"Rundll32.exe "%WIN.SYS32%\zareheli.dll",a" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"78bef83d"\"rundll32.exe "%WIN.SYS32%\beyezuki.dll",b" |
..\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{98672103-AFBE-4434-92D2-692A124CD60F}\(Default) |
..\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{933CD473-B65E-4C28-B5EA-9B033AB229A5}\(Default) |
..\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{80539daf-a296-4a3c-81d8-345156a02de7}\(Default) |
..\Software\Classes\Clsid\{80539daf-a296-4a3c-81d8-345156a02de7}\(Default) |