..\Software\Microsoft\Windows\CurrentVersion\Run\\"ixproxy"\""%PF%\ixproxy\ixproxy.exe" /background" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"Firewall auto setup"\"%DAS%\admin\Local Settings\Temp\winlogon.exe" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"CPPONP"\"%DAS.AU.LS%\Temp\63c403c9.exe" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"Firewall auto setup"\"%DAS.AU.LS%\Temp\ee881a4c.exe" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"NAVOPS"\"%DAS.AU.LS%\Temp\df0f67d5.exe" |
..\System\CurrentControlSet\Services\tasmq\(Default) |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"IMSVR"\"%DAS.AU.LS%\Temp\546346ba.exe" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"svcroot"\"%WIN.SYS32%\svcroot.exe" |
..\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\"{F24FD7B3-0C4D-45C5-A71A-32E7FA849057}" |
..\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\"{DCC4B01F-514B-4B59-AAED-3351140E06E6}" |