..\Software\Microsoft\Windows\CurrentVersion\Run\\"%root%\docume~1\admin\locals~1\temp\\n_v14"\"%das.au.ls%\temp\\n_v14.exe" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"%root%\docume~1\admin\locals~1\temp\\draw memory"\"%das.au.ls%\temp\\draw memory.exe" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"winlogon"\"%DAS%\admin\Local Settings\Temp\f800b6fe.exe" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"msmacro32"\"%WIN%\msmacro64.exe" |
..\Software\Microsoft\Windows\CurrentVersion\RunServices\\"Rundll32"\"%WIN.SYS32%\Run32.exe" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"Windows Media SP.2.7.7"\"%WIN.SYS32%\TROJAN-PSW.WIN32.LMIR.FJ.exe" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"Rundll32"\"%WIN.SYS32%\Run32.exe" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"Microsoft system32"\"%WIN%\system32win.exe" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"Microsoft system"\"%WIN%\systemwin.exe" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"Microsoft Windows"\"%WIN%\Internet.exe" |