| HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\GetModule21 |
| HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\GetPack20 |
| HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Smart Antivirus-2009.exe Smart Antivirus 2009 |
| HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\Somefox |
| HKEY_CURRENT_USER\Software\SAV System Antivirus 2008 |
| HKEY_CURRENT_USER\Software\Smart Antivirus 2009 Smart Antivirus 2009 |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{fca2963f-7501-08f2-8e2a-e96d69325783} |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Cpl32ver |
| HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Somefox |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\adgpfoxs [C:\Windows\adgpfoxs.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\adsntzt.dll [C:\WINDOWS\system32\adsntzt.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\AlrtKbd [] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\AlrtRam [C:\WINDOWS\Installer\{be996609-9567-4177-8850-b6e11ef7498a}\AlrtRam.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\auAsBcJ [C:\WINDOWS\system32\dtwrwy.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\AvpChk [C:\WINDOWS\Installer\{3f0c675a-e70a-4c9c-aa34-8416daa3fb7b}\AvpChk.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\AvpService [C:\WINDOWS\Installer\{779e207b-4225-465f-9f66-bdb44424b150}\AvpService.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\BootBoot [C:\WINDOWS\Resources\BootBoot.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Brotiurl [C:\WINNT\system32\seliw3d.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\CDSetup [C:\WINDOWS\Resources\CDSetup.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\cliconfgzx.dll [C:\WINDOWS\system32\cliconfgzx.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Conehexp [C:\WINDOWS\system32\regixipv.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\csiCNqCRDzQO [C:\WINDOWS\system32\aeqy.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\DbUi [C:\Program Files\zldmste\DbUi.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\DbWin [C:\Program Files\sxchpsb\DbWin.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\DesktopWin [C:\WINDOWS\AppPatch\DesktopWin.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\DriveDrv [] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\DriveRom [C:\WINDOWS\Installer\{12f089a8-6c5d-411c-8e42-63fe1ac0998a}\DriveRom.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\DriveSrv [C:\WINDOWS\Installer\{002e758a-4c36-42a2-b0e2-d67f7a816809}\DriveSrv.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\DrvBoot [C:\WINDOWS\Installer\{24f42b3b-9491-4d8d-8c9e-90444953b4da}\DrvBoot.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\DrvComponent [C:\WINDOWS\Installer\{de88c05a-2f27-4f8b-a03a-66edb91c43c7}\DrvComponent.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\DrvWin [F:\WINDOWS\Installer\{b20e47c7-83e4-422f-bb38-768ef6fcaf84}\DrvWin.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\dsktbwfe [C:\Windows\dsktbwfe.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\eLZrYk [C:\WINDOWS\system32\vhg.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\enmsg [C:\Program Files\crvrwz\enmsg.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\fkdnrwsv [C:\WINDOWS\fkdnrwsv.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\hqxcvaxc [C:\Documents and Settings\All Users\Application Data\hqxcvaxc.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ijcbmjcr [C:\Documents and Settings\All Users\Application Data\ijcbmjcr.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\KbdMon [C:\WINDOWS\Installer\{331c05dd-7cde-498c-986e-8502cbf249c8}\KbdMon.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\KbdSetup [C:\WINDOWS\Installer\{ac633de7-14d4-4297-8e5f-613b933fb5ab}\KbdSetup.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\KernelAlrt [] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Midieng [C:\WINDOWS\system32\vgareg.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\mntshsrv [C:\Program Files\pgtpflf\mntshsrv.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\mondb [C:\Program Files\zupvbse\mondb.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ogxtsepr [C:\Windows\ogxtsepr.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\okmdepgb [C:\WINDOWS\okmdepgb.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\PrxBoot [C:\WINDOWS\Installer\{d8d888fa-05d1-44f2-b0c2-4db94b418108}\PrxBoot.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\PrxService [C:\WINDOWS\Installer\{747a3ea5-7922-46c8-8499-ece141fa4f62}\PrxService.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\PrxSetup [C:\WINDOWS\Installer\{3902a8dc-0918-4ff8-9c32-56b89c985906}\PrxSetup.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\qdnkewfa [C:\WINDOWS\qdnkewfa.dll] |
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\RamWin [C:\Windows\Installer\{0caf65c1-b63a-485c-b201-c01b9c4f2 6ba}\RamWin.dll] |