..\Software\Microsoft\Windows\CurrentVersion\Run\\"AVMANAGER"\"%WIN.SYS32%\~A~M~B~U~R~A~D~U~L~\CSRSS.EXE" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"CONFIGVIR"\"%WIN.SYS32%\~A~M~B~U~R~A~D~U~L~\SERVICES.EXE" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"NARMONVIRUSANTI"\"%WIN.SYS32%\~A~M~B~U~R~A~D~U~L~\SMSS.EXE" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"PARAY_VM"\"%WIN.SYS32%\~A~M~B~U~R~A~D~U~L~\WINLOGON.EXE" |
..\Software\Microsoft\Windows NT\CurrentVersion\image file execution options\wscript.exe\"debugger"\"rundll32.exe" |