Monday, January 19, 2009

Banbra.cc Spyware

Removing Banbra.cc
Categories: Spyware
Spyware programs can collect various types of personal information,
such as Internet surfing habit, sites that have been visited,
but can also interfere with user control of the computer in other ways,
such as installing additional software, redirecting Web browser activity,
accessing websites blindly that will cause more harmful viruses,
or diverting advertising revenue to a third party.

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\imgtd.exe
[%SYSTEM%]\spoobcs.com
[%SYSTEM%]\imgtd.exe
[%SYSTEM%]\spoobcs.com

How to detect Banbra.cc:

Files:
[%SYSTEM%]\imgtd.exe
[%SYSTEM%]\spoobcs.com
[%SYSTEM%]\imgtd.exe
[%SYSTEM%]\spoobcs.com

Registry Keys:
HKEY_CURRENT_USER\imgtd
HKEY_CURRENT_USER\spoobcs

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing Banbra.cc:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Remove CHARGEN.Attack DoS
Optix.Lite Backdoor Removal instruction
HLLO.Picked Trojan Symptoms
Snowdoor Trojan Information
Removing WebDir Adware

Vdrw.Class.Reg.Key BHO

Removing Vdrw.Class.Reg.Key
Categories: BHO
BHO (Browser Helper Object) Trojan.
The BHO waits for the user to post personal information to a monitored website.
As this information is entered by the user, it is captured by the BHO and sent back to the attacker.
The method of network transport used by the attacker makes this Trojan unique.
Typically, keyloggers of this type will send the stolen information back to the attacker via email
or HTTP POST, which can appear suspicious.
Instead, this Trojan encodes the data with a simple XOR algorithm before placing it into
the data section of an ICMP ping packet." explained the company.

How to detect Vdrw.Class.Reg.Key:

Registry Keys:
HKEY_CLASSES_ROOT\clsid\{8711cf54-e9c5-4db4-9b9f-7d67393cc771}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{8711cf54-e9c5-4db4-9b9f-7d67393cc771}

Removing Vdrw.Class.Reg.Key:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Vxidl.AMT Trojan Symptoms
Fermif.BIA Trojan Cleaner
WebD Trojan Removal instruction
T543 Backdoor Cleaner

Lineage.ACC Trojan

Removing Lineage.ACC
Categories: Trojan
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

How to detect Lineage.ACC:

Registry Keys:
HKEY_CURRENT_USER\currentcontrolset\enum\root\legacy_vgadown

Removing Lineage.ACC:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Zlob-X Trojan Information
Http.Reloader Trojan Removal

VirtSpell Backdoor

Removing VirtSpell
Categories: Backdoor
Backdoors are the most dangerous type of Trojans and the most popular.
Backdoors open infected machines to external control via Internet.
They function in the same way as legal remote administration programs used by system administrators.
This makes them difficult to detect.

Backdoors are installed and launched without the consent of the user of computer.
Often the backdoor will not be visible in the log of active programs.

Once a backdoor has been successfully launched, the computer is wide open.
Backdoor functions can include:


  • Launching/ deleting files

  • Sending/ receiving files

  • Deleting data

  • Displaying notification

  • Rebooting the machine

  • Executing files




Backdoors are used by virus writers to detect and download confidential information,
execute malicious code, destroy data, include the machine in bot networks and so forth.
Backdoors combine the functionality of most other types of in one package.

Backdoors have one especially dangerous sub-class: variants that can propagate like worms.

VirtSpell Also known as:

[Kaspersky]Backdoor.Win32.Agent.aon;
[McAfee]Generic BackDoor;
[Other]trojan-backdoor-virtualspell,Backdoor.Trojan,Win32.ExploreHijack

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\vspell.exe
[%SYSTEM%]\vspell.exe

How to detect VirtSpell:

Files:
[%SYSTEM%]\vspell.exe
[%SYSTEM%]\vspell.exe

Registry Keys:
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\virtspell

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing VirtSpell:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
TrojanDownloader.Win32.Wintrim Trojan Removal instruction
Removing Small.gn Downloader
Remove BJCG Spyware
SillyDl.CDS Trojan Removal instruction
Win32.Startpage.FZ.DLL.Tro Trojan Removal

AntiSpywareBot Ransomware

Removing AntiSpywareBot
Categories: Ransomware
A cryptovirus, cryptotrojan or cryptoworm is a type of
malware that encrypts the data belonging to an individual on a computer,
demanding a ransom for its restoration.

The term ransomware is commonly used to describe such software,
although the field known as cryptovirology predates the term "ransomware".

This type of ransom attack can be accomplished by (for example) attaching
a specially crafted file/program to an e-mail message and sending this to the victim.

If the victim opens/executes the attachment, the program encrypts
a number of files on the victim's computer. A ransom note is then left behind for the victim.

The victim will be unable to open the encrypted files without the correct decryption key.
Once the ransom demanded in the ransom note is paid, the cracker may (or may not)
send the decryption key, enabling decryption of the "kidnapped" files.

Visible Symptoms:
Files in system folders:
[%PROGRAM_FILES%]\AntiSpywareBot\AntiSpywareBot.exe
[%PROGRAM_FILES%]\AntiSpywareBot\AntiSpywareBot.exe

How to detect AntiSpywareBot:

Files:
[%PROGRAM_FILES%]\AntiSpywareBot\AntiSpywareBot.exe
[%PROGRAM_FILES%]\AntiSpywareBot\AntiSpywareBot.exe

Folders:
[%PROGRAM_FILES%]\AntiSpywareBot

Registry Values:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Removing AntiSpywareBot:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Remove Virus.VBS.Varal Trojan
Remove New.Virus Trojan
yourbow.com Tracking Cookie Removal
Bat2EXE.Delauto Trojan Symptoms
StartPage.cd Hijacker Cleaner

AntiLamer.Light Trojan

Removing AntiLamer.Light
Categories: Trojan,Adware,Spyware,RAT,Hacker Tool
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits
Spyware is computer software that is installed surreptitiously on a personal computer
to intercept or take partial control over the user's interaction
with the computer, without the user's informed consent.

While the term spyware suggests software that secretly monitors the user's behavior,
the functions of spyware extend well beyond simple monitoring.

Spyware programs can collect various types of personal information,
such as Internet surfing habit, sites that have been visited,
but can also interfere with user control of the computer in other ways,
such as installing additional software, redirecting Web browser activity,
accessing websites blindly that will cause more harmful viruses,
or diverting advertising revenue to a third party.

Spyware can even change computer settings, resulting in slow connection speeds,
different home pages, and loss of Internet or other programs.
In an attempt to increase the understanding of spyware, a more formal classification
of its included software types is captured under the term privacy-invasive software.
Many trojans and backdoors now have remote administration capabilities
allowing an individual to control the victim's computer.
Many times a file called the server must be opened on the victim's computer before
the trojan can have access to it.

These are generally sent through email, P2P file sharing software,
and in internet downloads. They are usually disguised as a legitimate program or file.
Many server files will display a fake error message when opened, to make it seem like it didn't open.
Some will also kill antivirus and firewall software.

Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on
April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.
They usually do whimsical things like flip the screen upside-down, open the CD-ROM tray,
and swap mouse buttons. However, they can be quite hard to remove.
These utilities are designed to penetrate remote computers
in order to use them as zombies (by using backdoors) or to download other malicious programs to computer.

Exploits use vulnerabilities in operating systems and applications to achieve the same result.

AntiLamer.Light Also known as:

[Kaspersky]Trojan.PSW.AlLight.201;
[Eset]Win32/PSW.AlLight.201 trojan;
[Panda]Trj/PSW.AlLight,Dialer.DQ;
[Computer Associates]Win32.AntilamLite.201,Win32/PSW.AlLight.201.Trojan

Visible Symptoms:
Files in system folders:
[%WINDOWS%]\runwin32.exe
[%DESKTOP%]\5-1-14-24.lnk
[%PROFILE%]\administrator\start menu\5-1-14-24.lnk
[%PROFILE%]\administrator\start menu\programs\5-1-14-24.lnk
[%WINDOWS%]\system\runwin.exe
[%WINDOWS%]\system\runwindows32.exe
[%WINDOWS%]\runwin32.exe
[%DESKTOP%]\5-1-14-24.lnk
[%PROFILE%]\administrator\start menu\5-1-14-24.lnk
[%PROFILE%]\administrator\start menu\programs\5-1-14-24.lnk
[%WINDOWS%]\system\runwin.exe
[%WINDOWS%]\system\runwindows32.exe

How to detect AntiLamer.Light:

Files:
[%WINDOWS%]\runwin32.exe
[%DESKTOP%]\5-1-14-24.lnk
[%PROFILE%]\administrator\start menu\5-1-14-24.lnk
[%PROFILE%]\administrator\start menu\programs\5-1-14-24.lnk
[%WINDOWS%]\system\runwin.exe
[%WINDOWS%]\system\runwindows32.exe
[%WINDOWS%]\runwin32.exe
[%DESKTOP%]\5-1-14-24.lnk
[%PROFILE%]\administrator\start menu\5-1-14-24.lnk
[%PROFILE%]\administrator\start menu\programs\5-1-14-24.lnk
[%WINDOWS%]\system\runwin.exe
[%WINDOWS%]\system\runwindows32.exe

Folders:
[%PROGRAM_FILES%]\websx

Registry Keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7589EEE6-E336-11D4-8A7E-EE1D971D9B47}
HKEY_LOCAL_MACHINE\software\classes\acontixcontrol
HKEY_LOCAL_MACHINE\software\classes\clsid\{7589eee6-e336-11d4-8a7e-ee1d971d9b47}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{7589eee6-e336-11d4-8a7e-ee1d971d9b47}

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/acontix.ocx
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/acontix.ocx
HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\window
HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows
HKEY_LOCAL_MACHINE\software\anti-lamer backdoor
HKEY_LOCAL_MACHINE\software\anti-lamer backdoor
HKEY_LOCAL_MACHINE\software\anti-lamer backdoor
HKEY_LOCAL_MACHINE\software\anti-lamer backdoor
HKEY_LOCAL_MACHINE\software\anti-lamer backdoor
HKEY_LOCAL_MACHINE\software\anti-lamer backdoor
HKEY_LOCAL_MACHINE\software\anti-lamer backdoor
HKEY_LOCAL_MACHINE\software\anti-lamer backdoor
HKEY_LOCAL_MACHINE\software\antilamer backdoor
HKEY_LOCAL_MACHINE\software\antilamer backdoor
HKEY_LOCAL_MACHINE\software\antilamer backdoor
HKEY_LOCAL_MACHINE\software\antilamer backdoor
HKEY_LOCAL_MACHINE\software\antilamer backdoor
HKEY_LOCAL_MACHINE\software\antilamer backdoor
HKEY_LOCAL_MACHINE\software\antilamer backdoor
HKEY_LOCAL_MACHINE\software\antilamer backdoor
HKEY_LOCAL_MACHINE\software\antilamer backdoor
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\keyconfig
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\keyconfig
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\keyconfig
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\keyconfig
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\keyconfig
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\keyconfig
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\keyconfig
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\keyconfig
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\keyconfig
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/acontix.ocx
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]/downloaded program files/acontix.ocx
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\5-1-14-24
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\5-1-14-24
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\5-1-14-24

Removing AntiLamer.Light:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Valla Trojan Symptoms
Removing SillyDl.CPJ Trojan
Remove Renmog Trojan
Enles Trojan Removal instruction
Removing Spysender Backdoor

Delf Trojan

Removing Delf
Categories: Trojan,Adware,Spyware,Backdoor,RAT,Downloader,Hacker Tool,DoS
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.

Spyware is computer software that is installed surreptitiously on a personal computer
to intercept or take partial control over the user's interaction
with the computer, without the user's informed consent.

While the term spyware suggests software that secretly monitors the user's behavior,
the functions of spyware extend well beyond simple monitoring.

Spyware programs can collect various types of personal information,
such as Internet surfing habit, sites that have been visited,
but can also interfere with user control of the computer in other ways,
such as installing additional software, redirecting Web browser activity,
accessing websites blindly that will cause more harmful viruses,
or diverting advertising revenue to a third party.

Spyware can even change computer settings, resulting in slow connection speeds,
different home pages, and loss of Internet or other programs.
In an attempt to increase the understanding of spyware, a more formal classification
of its included software types is captured under the term privacy-invasive software.
Backdoors combine the functionality of most other types of in one package.
Backdoors have one especially dangerous sub-class: variants that can propagate like worms.

Many trojans and backdoors now have remote administration capabilities
allowing an individual to control the victim's computer.
Many times a file called the server must be opened on the victim's computer before
the trojan can have access to it.

These are generally sent through email, P2P file sharing software,
and in internet downloads. They are usually disguised as a legitimate program or file.
Many server files will display a fake error message when opened, to make it seem like it didn't open.
Some will also kill antivirus and firewall software.

Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on
April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.
They usually do whimsical things like flip the screen upside-down, open the CD-ROM tray,
and swap mouse buttons. However, they can be quite hard to remove.
This family of Trojans downloads and installs new malware or adware on the computer.
The downloader then either launches the new malware or registers it to enable autorun
according to the local operating system requirements.

The names and locations of malware to be downloaded are either coded into the
Trojan or downloaded from a specified website.
These utilities are designed to penetrate remote computers
in order to use them as zombies (by using backdoors) or to download other malicious programs to computer.

Exploits use vulnerabilities in operating systems and applications to achieve the same result.
DoS programs attack web servers by sending numerous requests to the specified server,
often causing it to crash under an excessive volume of requests.



Delf Also known as:

[Kaspersky]Backdoor.Delf.u,Backdoor.Delf.k,Trojan-Clicker.Win32.Delf.ha,Trojan-Clicker.Win32.Delf.gw,Trojan-Dropper.Win32.Delf.gd,Trojan-PWS.Win32.Delf.lc,Trojan-Spy.Win32.Delf.nt,Trojan-Downloader.Win32.Delf.kc,Trojan-Downloader.Win32.Delf.vm,Trojan-PSW.Win32.Delf.qx,Trojan-Dropper.Win32.Delf.aea,Trojan-Downloader.Win32.Delf.axx,Trojan-Downloader.Win32.Delf.bge,Backdoor.Win32.Delf.aom,Trojan-Downloader.Win32.Delf.cty,Trojan.Generic;
[Eset]Win32/Delf.GR trojan,Win32/Netso.A trojan,Win32/Delf.GE trojan,Win32/Delf.IF trojan,Win32/Delf.JO trojan,Win32/Delf.AJ trojan,Win32/Delf.IU trojan,Win32/Delf.AB trojan,Win32/Delf.G trojan,Win32/Delf.I trojan,Win32/Delf.J trojan,Win32/Delf.L trojan,Win32/Delf.CO trojan;
[McAfee]BackDoor-SY,The-CID,BackDoor-ARR.dr,Downloader-AWI,Generic Downloader.c,Generic PWS,Generic BackDoor;
[F-Prot]security risk or a "backdoor" program,W32/Dropper.WJ,W32/Downloader2.DUS,W32/Dropper.EMO,W32/Downloader.CFYE,W32/Downldr2.AIIS;
[Panda]Backdoor Program,Bck/Delf.K,Backdoor Program.LC,Trojan Horse.LC,Trj/Delf.T,Trj/Downloader.JE,Trojan Horse,Trj/PSW.Delf.D.dll,Trj/PSW.Delf,Trj/PSW.Delf.b,Trj/Lineage.DNW;
[Computer Associates]Backdoor/Carved,Win32.Carved,Backdoor/Delf.K,Backdoor/Delf.GR,Backdoor/Delf.gr!Server,Backdoor/Delf.GU,Backdoor/Delf.GZ,Backdoor/Delf.GE!Server,Backdoor/Delf,Backdoor/Delf!Server,Backdoor/Delf.JQ,Win32/Delf.AM!Trojan,Win32/Delf.AJ!Trojan,Win32/Delf.AK!Trojan,Win32/Delf.m!Spy!Trojan,Win32/Delf.AL!Downloader,Backdoor/Delf.IU,Win32/Delf.BB!PWS!Trojan,Backdoor/Delf.AB,Backdoor/Delf.g,Backdoor/Delf.i,Backdoor/Delf.j,Backdoor/Delf.JP,Win32/Delf.D!PWS!Trojan,Win32/Delf.V!Trojan,Win32/Delf.t!Spy!Trojan,Win32/Delf.O!PWS!Trojan,Backdoor/Delf.l,Win32/Delf.AI!PWS!Trojan,Win32/Delf.B!PWS!Trojan,Win32/Delf.V!Joiner,Backdoor/Delf.A,Win32.Mite,Win32/Notifier.Delf.d!Trojan;
[Other]-Managers DEMO,W32/DLoader.BJEV,Troj/Delf-DXK,Generic Delphi,Troj/Delf-DVK,W32/Delf.LWF,W32/Delf.NJJ,W32/Delf.AFFJ,W32/DLoader.OKP,W32/Delf.AHPH,Trojan:Win32/Delf.B,TROJ_DELF.GUE,Trojan.Dropper,Troj/Maran-Gen,Downloader.Delf.bge,W32/Malware.LYY,TROJ_DELF.EYN,W32/Delf.AIAY,Backdoor.Trojan,W32/Delf.AZWL.dropper,Mal/DelpDldr-B,W32.Pifio,TROJ_DELF.NPF,W32/Malware

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\kf1media.dll
[%SYSTEM%]\pathname.dll
[%WINDOWS%]\crat.dll
[%PROFILE_TEMP%]\cy.dll
[%PROFILE_TEMP%]\cy.exe
[%PROFILE_TEMP%]\Haif1-20.jpg
[%PROFILE_TEMP%]\MyPic.exe
[%PROFILE_TEMP%]\RAVWM.EXE
[%PROFILE_TEMP%]\wmptool.exe
[%SYSTEM%]\DirectX10.dll
[%SYSTEM%]\drivers\8761CCDC.sys
[%SYSTEM%]\gdmoyi32.dll
[%SYSTEM%]\gdmsi32.dll
[%SYSTEM%]\gdwli32.dll
[%SYSTEM%]\hursax.dll
[%SYSTEM%]\kawdeaz.exe
[%SYSTEM%]\kawdezy.dll
[%SYSTEM%]\KVBatch01.dll
[%SYSTEM%]\kvdxjis.exe
[%SYSTEM%]\kvdxjma.dll
[%SYSTEM%]\kvdxsiis.exe
[%SYSTEM%]\kvdxsima.dll
[%SYSTEM%]\pathname.exe
[%SYSTEM%]\ratbjpi.dll
[%SYSTEM%]\ratbjtl.exe
[%SYSTEM%]\RAVWM429.dll
[%SYSTEM%]\sidjdaz.exe
[%SYSTEM%]\sidjdzy.dll
[%SYSTEM%]\videodevice.dll
[%SYSTEM%]\ziouhx.dll
[%WINDOWS%]\49400WL.DLL
[%WINDOWS%]\Fonts\ardaase.fon
[%WINDOWS%]\Fonts\ardasase.fon
[%WINDOWS%]\Fonts\cadaafx.fon
[%WINDOWS%]\Fonts\chtiaur.fon
[%WINDOWS%]\Fonts\enweafx.fon
[%WINDOWS%]\Fonts\kawdecs.dll
[%WINDOWS%]\Fonts\kvdxjcf.dll
[%WINDOWS%]\Fonts\kvdxsicf.dll
[%WINDOWS%]\Fonts\ratbjni.dll
[%WINDOWS%]\Fonts\sidjdcs.dll
[%WINDOWS%]\videoarchivio[1].exe
[%WINDOWS%]\wmptool.exe
[%SYSTEM%]\kf1media.dll
[%SYSTEM%]\pathname.dll
[%WINDOWS%]\crat.dll
[%PROFILE_TEMP%]\cy.dll
[%PROFILE_TEMP%]\cy.exe
[%PROFILE_TEMP%]\Haif1-20.jpg
[%PROFILE_TEMP%]\MyPic.exe
[%PROFILE_TEMP%]\RAVWM.EXE
[%PROFILE_TEMP%]\wmptool.exe
[%SYSTEM%]\DirectX10.dll
[%SYSTEM%]\drivers\8761CCDC.sys
[%SYSTEM%]\gdmoyi32.dll
[%SYSTEM%]\gdmsi32.dll
[%SYSTEM%]\gdwli32.dll
[%SYSTEM%]\hursax.dll
[%SYSTEM%]\kawdeaz.exe
[%SYSTEM%]\kawdezy.dll
[%SYSTEM%]\KVBatch01.dll
[%SYSTEM%]\kvdxjis.exe
[%SYSTEM%]\kvdxjma.dll
[%SYSTEM%]\kvdxsiis.exe
[%SYSTEM%]\kvdxsima.dll
[%SYSTEM%]\pathname.exe
[%SYSTEM%]\ratbjpi.dll
[%SYSTEM%]\ratbjtl.exe
[%SYSTEM%]\RAVWM429.dll
[%SYSTEM%]\sidjdaz.exe
[%SYSTEM%]\sidjdzy.dll
[%SYSTEM%]\videodevice.dll
[%SYSTEM%]\ziouhx.dll
[%WINDOWS%]\49400WL.DLL
[%WINDOWS%]\Fonts\ardaase.fon
[%WINDOWS%]\Fonts\ardasase.fon
[%WINDOWS%]\Fonts\cadaafx.fon
[%WINDOWS%]\Fonts\chtiaur.fon
[%WINDOWS%]\Fonts\enweafx.fon
[%WINDOWS%]\Fonts\kawdecs.dll
[%WINDOWS%]\Fonts\kvdxjcf.dll
[%WINDOWS%]\Fonts\kvdxsicf.dll
[%WINDOWS%]\Fonts\ratbjni.dll
[%WINDOWS%]\Fonts\sidjdcs.dll
[%WINDOWS%]\videoarchivio[1].exe
[%WINDOWS%]\wmptool.exe

How to detect Delf:

Files:
[%SYSTEM%]\kf1media.dll
[%SYSTEM%]\pathname.dll
[%WINDOWS%]\crat.dll
[%PROFILE_TEMP%]\cy.dll
[%PROFILE_TEMP%]\cy.exe
[%PROFILE_TEMP%]\Haif1-20.jpg
[%PROFILE_TEMP%]\MyPic.exe
[%PROFILE_TEMP%]\RAVWM.EXE
[%PROFILE_TEMP%]\wmptool.exe
[%SYSTEM%]\DirectX10.dll
[%SYSTEM%]\drivers\8761CCDC.sys
[%SYSTEM%]\gdmoyi32.dll
[%SYSTEM%]\gdmsi32.dll
[%SYSTEM%]\gdwli32.dll
[%SYSTEM%]\hursax.dll
[%SYSTEM%]\kawdeaz.exe
[%SYSTEM%]\kawdezy.dll
[%SYSTEM%]\KVBatch01.dll
[%SYSTEM%]\kvdxjis.exe
[%SYSTEM%]\kvdxjma.dll
[%SYSTEM%]\kvdxsiis.exe
[%SYSTEM%]\kvdxsima.dll
[%SYSTEM%]\pathname.exe
[%SYSTEM%]\ratbjpi.dll
[%SYSTEM%]\ratbjtl.exe
[%SYSTEM%]\RAVWM429.dll
[%SYSTEM%]\sidjdaz.exe
[%SYSTEM%]\sidjdzy.dll
[%SYSTEM%]\videodevice.dll
[%SYSTEM%]\ziouhx.dll
[%WINDOWS%]\49400WL.DLL
[%WINDOWS%]\Fonts\ardaase.fon
[%WINDOWS%]\Fonts\ardasase.fon
[%WINDOWS%]\Fonts\cadaafx.fon
[%WINDOWS%]\Fonts\chtiaur.fon
[%WINDOWS%]\Fonts\enweafx.fon
[%WINDOWS%]\Fonts\kawdecs.dll
[%WINDOWS%]\Fonts\kvdxjcf.dll
[%WINDOWS%]\Fonts\kvdxsicf.dll
[%WINDOWS%]\Fonts\ratbjni.dll
[%WINDOWS%]\Fonts\sidjdcs.dll
[%WINDOWS%]\videoarchivio[1].exe
[%WINDOWS%]\wmptool.exe
[%SYSTEM%]\kf1media.dll
[%SYSTEM%]\pathname.dll
[%WINDOWS%]\crat.dll
[%PROFILE_TEMP%]\cy.dll
[%PROFILE_TEMP%]\cy.exe
[%PROFILE_TEMP%]\Haif1-20.jpg
[%PROFILE_TEMP%]\MyPic.exe
[%PROFILE_TEMP%]\RAVWM.EXE
[%PROFILE_TEMP%]\wmptool.exe
[%SYSTEM%]\DirectX10.dll
[%SYSTEM%]\drivers\8761CCDC.sys
[%SYSTEM%]\gdmoyi32.dll
[%SYSTEM%]\gdmsi32.dll
[%SYSTEM%]\gdwli32.dll
[%SYSTEM%]\hursax.dll
[%SYSTEM%]\kawdeaz.exe
[%SYSTEM%]\kawdezy.dll
[%SYSTEM%]\KVBatch01.dll
[%SYSTEM%]\kvdxjis.exe
[%SYSTEM%]\kvdxjma.dll
[%SYSTEM%]\kvdxsiis.exe
[%SYSTEM%]\kvdxsima.dll
[%SYSTEM%]\pathname.exe
[%SYSTEM%]\ratbjpi.dll
[%SYSTEM%]\ratbjtl.exe
[%SYSTEM%]\RAVWM429.dll
[%SYSTEM%]\sidjdaz.exe
[%SYSTEM%]\sidjdzy.dll
[%SYSTEM%]\videodevice.dll
[%SYSTEM%]\ziouhx.dll
[%WINDOWS%]\49400WL.DLL
[%WINDOWS%]\Fonts\ardaase.fon
[%WINDOWS%]\Fonts\ardasase.fon
[%WINDOWS%]\Fonts\cadaafx.fon
[%WINDOWS%]\Fonts\chtiaur.fon
[%WINDOWS%]\Fonts\enweafx.fon
[%WINDOWS%]\Fonts\kawdecs.dll
[%WINDOWS%]\Fonts\kvdxjcf.dll
[%WINDOWS%]\Fonts\kvdxsicf.dll
[%WINDOWS%]\Fonts\ratbjni.dll
[%WINDOWS%]\Fonts\sidjdcs.dll
[%WINDOWS%]\videoarchivio[1].exe
[%WINDOWS%]\wmptool.exe

Registry Keys:
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_pcidown
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\pcidown
HKEY_CLASSES_ROOT\clsid\{09f8a0eb-ed61-4714-b0ad-7eaff5361a8b}
HKEY_CLASSES_ROOT\clsid\{48847374-8323-fadc-b443-4732abcd3784}
HKEY_CLASSES_ROOT\clsid\{58907901-1416-3389-9981-372178569985}
HKEY_CLASSES_ROOT\clsid\{9d561258-45f3-a451-f908-a258458226d9}
HKEY_CLASSES_ROOT\clsid\{a12c8d43-ac10-4c17-9136-e3e2fc9b3d21}
HKEY_CLASSES_ROOT\clsid\{a6650011-3344-6688-4899-345fabcd156a}
HKEY_CLASSES_ROOT\clsid\{ac87a354-abc3-dede-ff33-3213fd7447ca}
HKEY_CLASSES_ROOT\clsid\{c51c4afb-8a3a-6c1e-ba41-c20f02940603}
HKEY_CLASSES_ROOT\clsid\{f2cea371-1442-4f42-900f-97c479f406db}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{fad11f89-f11e-4a15-92fb-6f0edc4c8d59}

Registry Values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce

Removing Delf:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Nikki Trojan Symptoms
Tpvo Trojan Symptoms
Removing FastTracker Spyware

SpyLab.WebSpy Spyware

Removing SpyLab.WebSpy
Categories: Spyware
Spyware is computer software that is installed surreptitiously on a personal computer
to intercept or take partial control over the user's interaction
with the computer, without the user's informed consent.

While the term spyware suggests software that secretly monitors the user's behavior,
the functions of spyware extend well beyond simple monitoring.

Spyware programs can collect various types of personal information,
such as Internet surfing habit, sites that have been visited,
but can also interfere with user control of the computer in other ways,
such as installing additional software, redirecting Web browser activity,
accessing websites blindly that will cause more harmful viruses,
or diverting advertising revenue to a third party.

Spyware can even change computer settings, resulting in slow connection speeds,
different home pages, and loss of Internet or other programs.
In an attempt to increase the understanding of spyware, a more formal classification
of its included software types is captured under the term privacy-invasive software.

Visible Symptoms:
Files in system folders:
[%COMMON_PROGRAMS%]\Spylab WebSpy\Spylab WebSpy.lnk
[%COMMON_PROGRAMS%]\Spylab WebSpy\Uninstall Spylab WebSpy.lnk
[%COMMON_PROGRAMS%]\Spylab WebSpy\WebSpy Help.lnk
[%COMMON_PROGRAMS%]\Spylab WebSpy\WebSpy On The Web.lnk
[%DESKTOP%]\Spylab WebSpy.lnk
[%SYSTEM%]\WebSpy.lnk
[%COMMON_PROGRAMS%]\Spylab WebSpy\Spylab WebSpy.lnk
[%COMMON_PROGRAMS%]\Spylab WebSpy\Uninstall Spylab WebSpy.lnk
[%COMMON_PROGRAMS%]\Spylab WebSpy\WebSpy Help.lnk
[%COMMON_PROGRAMS%]\Spylab WebSpy\WebSpy On The Web.lnk
[%DESKTOP%]\Spylab WebSpy.lnk
[%SYSTEM%]\WebSpy.lnk

How to detect SpyLab.WebSpy:

Files:
[%COMMON_PROGRAMS%]\Spylab WebSpy\Spylab WebSpy.lnk
[%COMMON_PROGRAMS%]\Spylab WebSpy\Uninstall Spylab WebSpy.lnk
[%COMMON_PROGRAMS%]\Spylab WebSpy\WebSpy Help.lnk
[%COMMON_PROGRAMS%]\Spylab WebSpy\WebSpy On The Web.lnk
[%DESKTOP%]\Spylab WebSpy.lnk
[%SYSTEM%]\WebSpy.lnk
[%COMMON_PROGRAMS%]\Spylab WebSpy\Spylab WebSpy.lnk
[%COMMON_PROGRAMS%]\Spylab WebSpy\Uninstall Spylab WebSpy.lnk
[%COMMON_PROGRAMS%]\Spylab WebSpy\WebSpy Help.lnk
[%COMMON_PROGRAMS%]\Spylab WebSpy\WebSpy On The Web.lnk
[%DESKTOP%]\Spylab WebSpy.lnk
[%SYSTEM%]\WebSpy.lnk

Folders:
[%PROGRAM_FILES%]\spylab

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing SpyLab.WebSpy:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Ruptnogle Trojan Removal instruction

Trust BHO

Removing Trust
Categories: BHO,Hijacker,Toolbar
As this information is entered by the user, it is captured by the BHO (Browser Helper Object) and
sent back to the attacker.
Typically, keyloggers of this type will send the stolen information back to the attacker via email
or HTTP POST, which can appear suspicious.A desktop hijacker replaces the desktop wallpaper with advertising
for products and services on the desktop.
Toolbar presents itself as a helpful add-on for Internet Explorer but it is a real pest.
It replaces your start page, continuosly open a number of pop up windows and so on.

Visible Symptoms:
Files in system folders:
[%COMMON_PROGRAMS%]\TrustToolbar\Online Help.url
[%PROFILE_TEMP%]\trusttoolbar.exe
[%SYSTEM%]\config\systemprofile\Start Menu\Programs\TrustToolbar\Online Help.url
[%SYSTEM%]\srhook.dll
[%SYSTEM%]\ttbbho.dll
[%SYSTEM%]\ttbsetup.exe
[%SYSTEM%]\ttbsreb.dll
[%SYSTEM%]\wvo_ctrl.exe
[%SYSTEM%]\wvo_util.dll
[%COMMON_PROGRAMS%]\TrustToolbar\Online Help.url
[%PROFILE_TEMP%]\trusttoolbar.exe
[%SYSTEM%]\config\systemprofile\Start Menu\Programs\TrustToolbar\Online Help.url
[%SYSTEM%]\srhook.dll
[%SYSTEM%]\ttbbho.dll
[%SYSTEM%]\ttbsetup.exe
[%SYSTEM%]\ttbsreb.dll
[%SYSTEM%]\wvo_ctrl.exe
[%SYSTEM%]\wvo_util.dll

How to detect Trust:

Files:
[%COMMON_PROGRAMS%]\TrustToolbar\Online Help.url
[%PROFILE_TEMP%]\trusttoolbar.exe
[%SYSTEM%]\config\systemprofile\Start Menu\Programs\TrustToolbar\Online Help.url
[%SYSTEM%]\srhook.dll
[%SYSTEM%]\ttbbho.dll
[%SYSTEM%]\ttbsetup.exe
[%SYSTEM%]\ttbsreb.dll
[%SYSTEM%]\wvo_ctrl.exe
[%SYSTEM%]\wvo_util.dll
[%COMMON_PROGRAMS%]\TrustToolbar\Online Help.url
[%PROFILE_TEMP%]\trusttoolbar.exe
[%SYSTEM%]\config\systemprofile\Start Menu\Programs\TrustToolbar\Online Help.url
[%SYSTEM%]\srhook.dll
[%SYSTEM%]\ttbbho.dll
[%SYSTEM%]\ttbsetup.exe
[%SYSTEM%]\ttbsreb.dll
[%SYSTEM%]\wvo_ctrl.exe
[%SYSTEM%]\wvo_util.dll

Folders:
[%PROGRAMS%]\trusttoolbar

Registry Keys:
HKEY_CLASSES_ROOT\.wvo
HKEY_CLASSES_ROOT\clsid\{21c066eb-1e61-4ab1-98ae-fc102f30b5c7}
HKEY_CLASSES_ROOT\clsid\{2c2c1bed-5b1c-4bf2-bc2a-86bf224b01ab}
HKEY_CLASSES_ROOT\clsid\{4c1f4ce1-57bf-4dfd-baff-58b825254e6b}
HKEY_CLASSES_ROOT\clsid\{bd49a497-f9cb-4c47-8606-ac420efb68c3}
HKEY_CLASSES_ROOT\interface\{c7851188-e89f-435c-a7f2-604a241a4282}
HKEY_CLASSES_ROOT\interface\{e0708144-8950-4d8a-ba61-45abd7b52984}
HKEY_CLASSES_ROOT\trusttoolbar
HKEY_CLASSES_ROOT\ttbbho.trusttoolbabho
HKEY_CLASSES_ROOT\ttbbho.trusttoolbabho.1
HKEY_CLASSES_ROOT\ttbwebinstaller.webinstaller
HKEY_CLASSES_ROOT\ttbwebinstaller.webinstaller.1
HKEY_CLASSES_ROOT\typelib\{ba07cf38-b8a7-41e7-806c-c079e6f80c67}
HKEY_CLASSES_ROOT\webvisibleobject
HKEY_CURRENT_USER\software\comodo\ttbsettings
HKEY_CURRENT_USER\software\comodo\wvo
HKEY_LOCAL_MACHINE\software\comodo\wvo
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\explorer bars\{4c1f4ce1-57bf-4dfd-baff-58b825254e6b}
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{8ba1adb8-5b71-47ef-9663-6b68eb3ca9fa}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\webvisibleobject

Registry Values:
HKEY_CLASSES_ROOT\searchhook.urlsearchhook.1\clsid
HKEY_CURRENT_USER\software\microsoft\internet explorer\urlsearchhooks
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{093caf40-3ba6-4071-a050-e830cbdc6480}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{093caf40-3ba6-4071-a050-e830cbdc6480}\contains\files
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{093caf40-3ba6-4071-a050-e830cbdc6480}\downloadinformation
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{093caf40-3ba6-4071-a050-e830cbdc6480}\downloadinformation
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{093caf40-3ba6-4071-a050-e830cbdc6480}\installedversion
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shell extensions\approved

Removing Trust:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Leszcz RAT Cleaner
Remove CFSD Trojan
PSW.Lmir.ec Trojan Removal
Removing Pigeon.ANP Trojan
Removing Pigeon.AKK Trojan

Win32.Post.fh Trojan

Removing Win32.Post.fh
Categories: Trojan
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Win32.Post.fh Also known as:

[Kaspersky]Trojan.Win32.Post.e;
[McAfee]Generic StartPage.c;
[Other]Download.Trojan

Visible Symptoms:
Files in system folders:
[%SYSTEM%]\config\systemprofile\Favorites\Fresh XXX pics & movie.url
[%SYSTEM%]\config\systemprofile\Favorites\Links\Fresh XXX pics & movie.url
[%SYSTEM%]\config\systemprofile\Favorites\Fresh XXX pics & movie.url
[%SYSTEM%]\config\systemprofile\Favorites\Links\Fresh XXX pics & movie.url

How to detect Win32.Post.fh:

Files:
[%SYSTEM%]\config\systemprofile\Favorites\Fresh XXX pics & movie.url
[%SYSTEM%]\config\systemprofile\Favorites\Links\Fresh XXX pics & movie.url
[%SYSTEM%]\config\systemprofile\Favorites\Fresh XXX pics & movie.url
[%SYSTEM%]\config\systemprofile\Favorites\Links\Fresh XXX pics & movie.url

Removing Win32.Post.fh:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
TravelersAdvantage.com Tracking Cookie Cleaner
Removing RTB666 Backdoor
Sub.Mariner RAT Information

Ren.Bat Trojan

Removing Ren.Bat
Categories: Trojan
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Visible Symptoms:
Files in system folders:
[%DESKTOP%]\grl realhidden.lnk
[%DESKTOP%]\grl realhidden.lnk

How to detect Ren.Bat:

Files:
[%DESKTOP%]\grl realhidden.lnk
[%DESKTOP%]\grl realhidden.lnk

Folders:
[%PROGRAMS%]\grl realhidden
[%PROGRAM_FILES%]\grl realhidden

Removing Ren.Bat:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Poetry@M Trojan Cleaner
Removing TrojanDropper.Win32.Delf.bk Trojan
Removing BackDoor.AFF Trojan

StartPage.zy Hijacker

Removing StartPage.zy
Categories: Hijacker
When the default home page is hijacked, the browser opens to the web page set by the hijacker
instead of the user's designated home page. In some cases, the hijacker may block users from
restoring their desired home page.

How to detect StartPage.zy:

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing StartPage.zy:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
MonaBomber RAT Information
Pigeon.ANY Trojan Symptoms
Winpwd Trojan Information
SkyRat.Show.version RAT Symptoms

TGDC.IE.Plugin Adware

Removing TGDC.IE.Plugin
Categories: Adware
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits

How to detect TGDC.IE.Plugin:

Folders:
[%PROGRAM_FILES%]\tgdc

Removing TGDC.IE.Plugin:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
eShopee Trojan Symptoms
Removing SillyDl.CHT Trojan

UDIS Adware

Removing UDIS
Categories: Adware
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer.


UDIS Also known as:

[Kaspersky]Dialer.Win32.UDIS.a;
[Other]Win32/Udis.A,Dialer.Generic,W32/Dialer.gen,Dial/UDIS-B,Porndialer.Gen

How to detect UDIS:

Registry Keys:
HKEY_CLASSES_ROOT\interface\{9be99029-f00d-4b44-b28d-02b8187a0004}
HKEY_CLASSES_ROOT\interface\{9ea7bb29-0b84-4fa2-a048-6850dc4a56f4}
HKEY_CLASSES_ROOT\clsid\{12e5e9d9-4366-45d9-ba41-d0bcd55ad8cf}
HKEY_CLASSES_ROOT\typelib\{7011804e-188f-4077-9877-588bf6df70c7}
HKEY_CLASSES_ROOT\udconn.udconnect
HKEY_CLASSES_ROOT\udconn.udconnect.1

Removing UDIS:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Removing Keylogger.Common.Components Spyware
Frethog.ACM Trojan Removal
Kroey Trojan Information
Removing Searchaid.URL.Search.Hook Adware

SillyDl.CAF Downloader

Removing SillyDl.CAF
Categories: Downloader
Trojans-downloaders downloads and installs new malware or adware on the computer.


SillyDl.CAF Also known as:

[Kaspersky]Trojan-Downloader.Win32.Banload.bns;
[Other]Win32/SillyDl.CAF

Visible Symptoms:
Files in system folders:
[%WINDOWS%]\fishwin.scr
[%WINDOWS%]\fishwin.scr

How to detect SillyDl.CAF:

Files:
[%WINDOWS%]\fishwin.scr
[%WINDOWS%]\fishwin.scr

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing SillyDl.CAF:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Pigeon.AES Trojan Cleaner

SearchAndClick Adware

Removing SearchAndClick
Categories: Adware
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits

How to detect SearchAndClick:

Folders:
[%APPDATA%]\{2cf0b992-5eeb-4143-99c0-5297ef71f444}

Registry Keys:
HKEY_CLASSES_ROOT\typelib\{2cf0b992-5eeb-4143-99c0-5297ef71f445}

Removing SearchAndClick:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Rush.Hour Trojan Information
Removing SillyDl.CAJ Downloader
Windows.Activity.Logging.Interface Spyware Removal instruction
Remove Bancos.FVD Trojan

SillyDl.DJA Trojan

Removing SillyDl.DJA
Categories: Trojan
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.

SillyDl.DJA Also known as:

[Other]Trojan.Dropper

Visible Symptoms:
Files in system folders:
[%PROFILE_TEMP%]\~up.log
[%WINDOWS%]\inf\MsnSvc64.exe
[%WINDOWS%]\inf\SendSoftInfo2
[%WINDOWS%]\inf\usbctrl02.inf
[%WINDOWS%]\inf\~win.log
[%PROFILE_TEMP%]\~up.log
[%WINDOWS%]\inf\MsnSvc64.exe
[%WINDOWS%]\inf\SendSoftInfo2
[%WINDOWS%]\inf\usbctrl02.inf
[%WINDOWS%]\inf\~win.log

How to detect SillyDl.DJA:

Files:
[%PROFILE_TEMP%]\~up.log
[%WINDOWS%]\inf\MsnSvc64.exe
[%WINDOWS%]\inf\SendSoftInfo2
[%WINDOWS%]\inf\usbctrl02.inf
[%WINDOWS%]\inf\~win.log
[%PROFILE_TEMP%]\~up.log
[%WINDOWS%]\inf\MsnSvc64.exe
[%WINDOWS%]\inf\SendSoftInfo2
[%WINDOWS%]\inf\usbctrl02.inf
[%WINDOWS%]\inf\~win.log

Folders:
[%SYSTEM%]\inf

Registry Keys:
HKEY_LOCAL_MACHINE\software\microplugins
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_dnservice
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\c:
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\dnservice

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ctfmon.exe

Removing SillyDl.DJA:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Removing DuduAccelerator Adware
SillyDl.CPF Trojan Removal instruction

W95.CIH Trojan

Removing W95.CIH
Categories: Trojan,Worm,Backdoor,RAT,Downloader,Hacker Tool,DoS
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.
Worms can be classified by installation method, launch method and finally according
to characteristics standard to all malware: polymorphism, stealth etc.

Many of the worms which managed to cause significant outbreaks use more then
one propagation method as well as more than one infection technique.

Backdoors are the most dangerous type of Trojans and the most popular.
Backdoors open infected machines to external control via Internet.
Often the backdoor will not be visible in the log of active programs.
Many trojans and backdoors now have remote administration capabilities
allowing an individual to control the victim's computer.
Many times a file called the server must be opened on the victim's computer before
the trojan can have access to it.

These are generally sent through email, P2P file sharing software,
and in internet downloads. They are usually disguised as a legitimate program or file.
Many server files will display a fake error message when opened, to make it seem like it didn't open.
Some will also kill antivirus and firewall software.

Some RAT trojans are pranks that are most likely being controlled by a friend or enemy on
April Fool's day or a holiday. Prank RATS are generally not harmful, and won't log keystrokes or hack.
They usually do whimsical things like flip the screen upside-down, open the CD-ROM tray,
and swap mouse buttons. However, they can be quite hard to remove.
The downloader either launches the new malware or registers it to enable autorun
according to the local operating system requirements.
Exploits use vulnerabilities in operating systems and applications to achieve the same result.
These programs attack web servers by sending numerous requests to the specified server,
often causing it to crash under an excessive volume of requests.

DoS trojans conduct such attacks from a single computer with the consent of the user.

Worms can carry a DoS procedure as part of their payload.

W95.CIH Also known as:

[Kaspersky]Win95.CIH,Win95.CIH.1024,Win95.CIH.1019.c,Win95.CIH-Killer.1373,Win95.CIH.1003.b,Win95.CIH.1026,Win95.CIH.1035,Win95.CIH.1040,Win95.CIH.1042,Win95.CIH.1230,Win95.CIH.1363,Win95.CIH.1262;
[McAfee]W95/CIH;
[F-Prot]W32/CIH.1003.A,contains W32/CIH.1003.A (non-working),W32/CIH.1019.C,W32/Cih_Killer.1373,W32/CIH.1003.B,W32/CIH.1026,W32/CIH.1035,W32/CIH.1040,W32/CIH.1042,W32/CIH.1103,W32/CIH.1230,W32/CIH.1230.intended;
[Panda]W95/CIH,W95/CIH.Killer.1373,W95/CIH.1003.B,W95/CIH.1042;
[Computer Associates]Win95.CIH.1003.A,Win95/CIH.1003,Win95.CIH.family,Win95/CIH.1024,Win95.CIH.1003.D/1010/1024,Win95.CihKiller.1373,Win95.FCIH,Win95.CIH.1040,Win95.CIH.1042,Win95.CIH.1103/1297,Win95.FCIH.1230

How to detect W95.CIH:

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run

Removing W95.CIH:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Remove JScript.Exception Trojan

WebSearch BHO

Removing WebSearch
Categories: BHO,Hijacker,Toolbar
As this information is entered by the user, it is captured by the BHO (Browser Helper Object) and
sent back to the attacker.
Typically, keyloggers of this type will send the stolen information back to the attacker via email
or HTTP POST, which can appear suspicious.A Search hijacker redirects search results to other pages and may
transmit search and browsing data to unknown servers. An error page hijacker directs
the browser to another page, usually an advertising page, instead of the usual error
page when the requested URL is not found.
Toolbar presents itself as a helpful add-on for Internet Explorer but it is a real pest.
It replaces your start page, continuosly open a number of pop up windows and so on.

WebSearch Also known as:

[Panda]Trojan Horse

Visible Symptoms:
Files in system folders:
[%PROFILE_TEMP%]\iexploreskins.exe
[%PROFILE_TEMP%]\CAB41633\zwipvbh.wzg
[%PROFILE_TEMP%]\CAB70283\zwipvbh.wzg
[%PROFILE_TEMP%]\CAB94510\zwipvbh.wzg
[%PROFILE_TEMP%]\hotfix.exe
[%PROFILE_TEMP%]\IExploreSkins.exe
[%PROFILE_TEMP%]\msiein\CAB38140.6678994792\IExploreSkins.exe
[%PROFILE_TEMP%]\tbps.exe
[%PROFILE_TEMP%]\temp.fr????
[%PROFILE_TEMP%]\temp.fr????\WToolsC.cfg
[%PROFILE_TEMP%]\temp.fr????\WToolsT.dll
[%PROFILE_TEMP%]\toolbar.dll
[%PROFILE_TEMP%]\WToolsB.dll
[%PROGRAM_FILES%]\Crawler\Toolbar\CTConf.dat
[%PROGRAM_FILES%]\MySearch\bar\1.bin\S4BAR.DLL
[%PROGRAM_FILES%]\MySearch\bar\2.bin\S4BAR.DLL
[%PROGRAM_FILES_COMMON%]\WinTools\WSup.exe
[%PROGRAM_FILES_COMMON%]\WinTools\WToolsA.exe
[%PROGRAM_FILES_COMMON%]\WinTools\WToolsC.cfg
[%PROGRAM_FILES_COMMON%]\WinTools\WToolsD.cfg
[%SYSTEM%]\1lfc8c5t.dat
[%SYSTEM%]\5kc716be.dat
[%SYSTEM%]\5s72altp.dat
[%SYSTEM%]\6v77fbg9.dat
[%SYSTEM%]\ap2nqrd4.dat
[%SYSTEM%]\Cache\EDow_AS2_r.exe
[%SYSTEM%]\gl9kghup.dat
[%SYSTEM%]\gpg4dpeh.dat
[%SYSTEM%]\kqbu0obd.dat
[%SYSTEM%]\m3205dvn.dat
[%SYSTEM%]\na66t24r.dat
[%SYSTEM%]\nl5b8i3l.dat
[%SYSTEM%]\pplogo48x48.ico
[%SYSTEM%]\q10pvbrv.dat
[%SYSTEM%]\rp7oakvm.dat
[%SYSTEM%]\tbps.ini
[%SYSTEM%]\tm97pj39.dat
[%SYSTEM%]\v2kgiq720.dat
[%SYSTEM%]\vnocnh0c.dat
[%SYSTEM%]\WinTools.exe
[%WINDOWS%]\eMusicSetup.exe
[%WINDOWS%]\partypocker.ico
[%WINDOWS%]\partypocker4.ico
[%WINDOWS%]\partypocker6.ico
[%WINDOWS%]\Temp\baAjAGE8.exe
[%WINDOWS%]\Temp\eyDsN5tC.exe
[%WINDOWS%]\Temp\gz0OcFAV.exe
[%WINDOWS%]\Temp\MRobeF0H.exe
[%WINDOWS%]\Temp\muwLPrdj.exe
[%WINDOWS%]\Temp\wTDBBlxh.exe
[%WINDOWS%]\Temp\X2CrBD4t.exe
[%WINDOWS%]\Temp\zemTaXIx.exe
[%PROFILE%]\locals~1\temp\iexploreskins.exe
[%PROFILE_TEMP%]\mso9cbcb.ppt
[%PROFILE_TEMP%]\wintools.exe
[%SYSTEM%]\aaaamon0.exe
[%SYSTEM%]\appmgr00.exe
[%SYSTEM%]\browseui.exe
[%SYSTEM%]\certcli8.exe
[%SYSTEM%]\comcat94.exe
[%SYSTEM%]\msnycl.exe
[%SYSTEM%]\msrolfn.exe
[%SYSTEM%]\spotonbh.dll
[%WINDOWS%]\fash.exe
[%WINDOWS%]\system\spotonbh.dll
[%WINDOWS%]\winmem32.exe
[%PROFILE_TEMP%]\iexploreskins.exe
[%PROFILE_TEMP%]\CAB41633\zwipvbh.wzg
[%PROFILE_TEMP%]\CAB70283\zwipvbh.wzg
[%PROFILE_TEMP%]\CAB94510\zwipvbh.wzg
[%PROFILE_TEMP%]\hotfix.exe
[%PROFILE_TEMP%]\IExploreSkins.exe
[%PROFILE_TEMP%]\msiein\CAB38140.6678994792\IExploreSkins.exe
[%PROFILE_TEMP%]\tbps.exe
[%PROFILE_TEMP%]\temp.fr????
[%PROFILE_TEMP%]\temp.fr????\WToolsC.cfg
[%PROFILE_TEMP%]\temp.fr????\WToolsT.dll
[%PROFILE_TEMP%]\toolbar.dll
[%PROFILE_TEMP%]\WToolsB.dll
[%PROGRAM_FILES%]\Crawler\Toolbar\CTConf.dat
[%PROGRAM_FILES%]\MySearch\bar\1.bin\S4BAR.DLL
[%PROGRAM_FILES%]\MySearch\bar\2.bin\S4BAR.DLL
[%PROGRAM_FILES_COMMON%]\WinTools\WSup.exe
[%PROGRAM_FILES_COMMON%]\WinTools\WToolsA.exe
[%PROGRAM_FILES_COMMON%]\WinTools\WToolsC.cfg
[%PROGRAM_FILES_COMMON%]\WinTools\WToolsD.cfg
[%SYSTEM%]\1lfc8c5t.dat
[%SYSTEM%]\5kc716be.dat
[%SYSTEM%]\5s72altp.dat
[%SYSTEM%]\6v77fbg9.dat
[%SYSTEM%]\ap2nqrd4.dat
[%SYSTEM%]\Cache\EDow_AS2_r.exe
[%SYSTEM%]\gl9kghup.dat
[%SYSTEM%]\gpg4dpeh.dat
[%SYSTEM%]\kqbu0obd.dat
[%SYSTEM%]\m3205dvn.dat
[%SYSTEM%]\na66t24r.dat
[%SYSTEM%]\nl5b8i3l.dat
[%SYSTEM%]\pplogo48x48.ico
[%SYSTEM%]\q10pvbrv.dat
[%SYSTEM%]\rp7oakvm.dat
[%SYSTEM%]\tbps.ini
[%SYSTEM%]\tm97pj39.dat
[%SYSTEM%]\v2kgiq720.dat
[%SYSTEM%]\vnocnh0c.dat
[%SYSTEM%]\WinTools.exe
[%WINDOWS%]\eMusicSetup.exe
[%WINDOWS%]\partypocker.ico
[%WINDOWS%]\partypocker4.ico
[%WINDOWS%]\partypocker6.ico
[%WINDOWS%]\Temp\baAjAGE8.exe
[%WINDOWS%]\Temp\eyDsN5tC.exe
[%WINDOWS%]\Temp\gz0OcFAV.exe
[%WINDOWS%]\Temp\MRobeF0H.exe
[%WINDOWS%]\Temp\muwLPrdj.exe
[%WINDOWS%]\Temp\wTDBBlxh.exe
[%WINDOWS%]\Temp\X2CrBD4t.exe
[%WINDOWS%]\Temp\zemTaXIx.exe
[%PROFILE%]\locals~1\temp\iexploreskins.exe
[%PROFILE_TEMP%]\mso9cbcb.ppt
[%PROFILE_TEMP%]\wintools.exe
[%SYSTEM%]\aaaamon0.exe
[%SYSTEM%]\appmgr00.exe
[%SYSTEM%]\browseui.exe
[%SYSTEM%]\certcli8.exe
[%SYSTEM%]\comcat94.exe
[%SYSTEM%]\msnycl.exe
[%SYSTEM%]\msrolfn.exe
[%SYSTEM%]\spotonbh.dll
[%WINDOWS%]\fash.exe
[%WINDOWS%]\system\spotonbh.dll
[%WINDOWS%]\winmem32.exe

How to detect WebSearch:

Files:
[%PROFILE_TEMP%]\iexploreskins.exe
[%PROFILE_TEMP%]\CAB41633\zwipvbh.wzg
[%PROFILE_TEMP%]\CAB70283\zwipvbh.wzg
[%PROFILE_TEMP%]\CAB94510\zwipvbh.wzg
[%PROFILE_TEMP%]\hotfix.exe
[%PROFILE_TEMP%]\IExploreSkins.exe
[%PROFILE_TEMP%]\msiein\CAB38140.6678994792\IExploreSkins.exe
[%PROFILE_TEMP%]\tbps.exe
[%PROFILE_TEMP%]\temp.fr????
[%PROFILE_TEMP%]\temp.fr????\WToolsC.cfg
[%PROFILE_TEMP%]\temp.fr????\WToolsT.dll
[%PROFILE_TEMP%]\toolbar.dll
[%PROFILE_TEMP%]\WToolsB.dll
[%PROGRAM_FILES%]\Crawler\Toolbar\CTConf.dat
[%PROGRAM_FILES%]\MySearch\bar\1.bin\S4BAR.DLL
[%PROGRAM_FILES%]\MySearch\bar\2.bin\S4BAR.DLL
[%PROGRAM_FILES_COMMON%]\WinTools\WSup.exe
[%PROGRAM_FILES_COMMON%]\WinTools\WToolsA.exe
[%PROGRAM_FILES_COMMON%]\WinTools\WToolsC.cfg
[%PROGRAM_FILES_COMMON%]\WinTools\WToolsD.cfg
[%SYSTEM%]\1lfc8c5t.dat
[%SYSTEM%]\5kc716be.dat
[%SYSTEM%]\5s72altp.dat
[%SYSTEM%]\6v77fbg9.dat
[%SYSTEM%]\ap2nqrd4.dat
[%SYSTEM%]\Cache\EDow_AS2_r.exe
[%SYSTEM%]\gl9kghup.dat
[%SYSTEM%]\gpg4dpeh.dat
[%SYSTEM%]\kqbu0obd.dat
[%SYSTEM%]\m3205dvn.dat
[%SYSTEM%]\na66t24r.dat
[%SYSTEM%]\nl5b8i3l.dat
[%SYSTEM%]\pplogo48x48.ico
[%SYSTEM%]\q10pvbrv.dat
[%SYSTEM%]\rp7oakvm.dat
[%SYSTEM%]\tbps.ini
[%SYSTEM%]\tm97pj39.dat
[%SYSTEM%]\v2kgiq720.dat
[%SYSTEM%]\vnocnh0c.dat
[%SYSTEM%]\WinTools.exe
[%WINDOWS%]\eMusicSetup.exe
[%WINDOWS%]\partypocker.ico
[%WINDOWS%]\partypocker4.ico
[%WINDOWS%]\partypocker6.ico
[%WINDOWS%]\Temp\baAjAGE8.exe
[%WINDOWS%]\Temp\eyDsN5tC.exe
[%WINDOWS%]\Temp\gz0OcFAV.exe
[%WINDOWS%]\Temp\MRobeF0H.exe
[%WINDOWS%]\Temp\muwLPrdj.exe
[%WINDOWS%]\Temp\wTDBBlxh.exe
[%WINDOWS%]\Temp\X2CrBD4t.exe
[%WINDOWS%]\Temp\zemTaXIx.exe
[%PROFILE%]\locals~1\temp\iexploreskins.exe
[%PROFILE_TEMP%]\mso9cbcb.ppt
[%PROFILE_TEMP%]\wintools.exe
[%SYSTEM%]\aaaamon0.exe
[%SYSTEM%]\appmgr00.exe
[%SYSTEM%]\browseui.exe
[%SYSTEM%]\certcli8.exe
[%SYSTEM%]\comcat94.exe
[%SYSTEM%]\msnycl.exe
[%SYSTEM%]\msrolfn.exe
[%SYSTEM%]\spotonbh.dll
[%WINDOWS%]\fash.exe
[%WINDOWS%]\system\spotonbh.dll
[%WINDOWS%]\winmem32.exe
[%PROFILE_TEMP%]\iexploreskins.exe
[%PROFILE_TEMP%]\CAB41633\zwipvbh.wzg
[%PROFILE_TEMP%]\CAB70283\zwipvbh.wzg
[%PROFILE_TEMP%]\CAB94510\zwipvbh.wzg
[%PROFILE_TEMP%]\hotfix.exe
[%PROFILE_TEMP%]\IExploreSkins.exe
[%PROFILE_TEMP%]\msiein\CAB38140.6678994792\IExploreSkins.exe
[%PROFILE_TEMP%]\tbps.exe
[%PROFILE_TEMP%]\temp.fr????
[%PROFILE_TEMP%]\temp.fr????\WToolsC.cfg
[%PROFILE_TEMP%]\temp.fr????\WToolsT.dll
[%PROFILE_TEMP%]\toolbar.dll
[%PROFILE_TEMP%]\WToolsB.dll
[%PROGRAM_FILES%]\Crawler\Toolbar\CTConf.dat
[%PROGRAM_FILES%]\MySearch\bar\1.bin\S4BAR.DLL
[%PROGRAM_FILES%]\MySearch\bar\2.bin\S4BAR.DLL
[%PROGRAM_FILES_COMMON%]\WinTools\WSup.exe
[%PROGRAM_FILES_COMMON%]\WinTools\WToolsA.exe
[%PROGRAM_FILES_COMMON%]\WinTools\WToolsC.cfg
[%PROGRAM_FILES_COMMON%]\WinTools\WToolsD.cfg
[%SYSTEM%]\1lfc8c5t.dat
[%SYSTEM%]\5kc716be.dat
[%SYSTEM%]\5s72altp.dat
[%SYSTEM%]\6v77fbg9.dat
[%SYSTEM%]\ap2nqrd4.dat
[%SYSTEM%]\Cache\EDow_AS2_r.exe
[%SYSTEM%]\gl9kghup.dat
[%SYSTEM%]\gpg4dpeh.dat
[%SYSTEM%]\kqbu0obd.dat
[%SYSTEM%]\m3205dvn.dat
[%SYSTEM%]\na66t24r.dat
[%SYSTEM%]\nl5b8i3l.dat
[%SYSTEM%]\pplogo48x48.ico
[%SYSTEM%]\q10pvbrv.dat
[%SYSTEM%]\rp7oakvm.dat
[%SYSTEM%]\tbps.ini
[%SYSTEM%]\tm97pj39.dat
[%SYSTEM%]\v2kgiq720.dat
[%SYSTEM%]\vnocnh0c.dat
[%SYSTEM%]\WinTools.exe
[%WINDOWS%]\eMusicSetup.exe
[%WINDOWS%]\partypocker.ico
[%WINDOWS%]\partypocker4.ico
[%WINDOWS%]\partypocker6.ico
[%WINDOWS%]\Temp\baAjAGE8.exe
[%WINDOWS%]\Temp\eyDsN5tC.exe
[%WINDOWS%]\Temp\gz0OcFAV.exe
[%WINDOWS%]\Temp\MRobeF0H.exe
[%WINDOWS%]\Temp\muwLPrdj.exe
[%WINDOWS%]\Temp\wTDBBlxh.exe
[%WINDOWS%]\Temp\X2CrBD4t.exe
[%WINDOWS%]\Temp\zemTaXIx.exe
[%PROFILE%]\locals~1\temp\iexploreskins.exe
[%PROFILE_TEMP%]\mso9cbcb.ppt
[%PROFILE_TEMP%]\wintools.exe
[%SYSTEM%]\aaaamon0.exe
[%SYSTEM%]\appmgr00.exe
[%SYSTEM%]\browseui.exe
[%SYSTEM%]\certcli8.exe
[%SYSTEM%]\comcat94.exe
[%SYSTEM%]\msnycl.exe
[%SYSTEM%]\msrolfn.exe
[%SYSTEM%]\spotonbh.dll
[%WINDOWS%]\fash.exe
[%WINDOWS%]\system\spotonbh.dll
[%WINDOWS%]\winmem32.exe

Folders:
[%COMMON_PROGRAMS%]\Web Search Tools
[%PROGRAM_FILES_COMMON%]\wintools
[%PROGRAM_FILES%]\toolbar
[%PROFILE%]\start menu\web search tools
[%PROGRAMS%]\web search tools
[%PROGRAM_FILES%]\common files\wintools
[%PROGRAM_FILES%]\websearch toolbar

Registry Keys:
HKEY_CLASSES_ROOT\btlink.relatedlinksprotocol
HKEY_CLASSES_ROOT\btlink.resprotocol
HKEY_CLASSES_ROOT\clsid\{15ad6789-cdb4-47e1-a9da-992ee8e6bad6}
HKEY_CLASSES_ROOT\clsid\{2c4e6d22-b71f-491f-aad3-b6972a650d50}
HKEY_CLASSES_ROOT\clsid\{310cc549-4541-46a9-940f-52b342a6e682}
HKEY_CLASSES_ROOT\CLSID\{339BB23F-A864-48C0-A59F-29EA915965EC}
HKEY_CLASSES_ROOT\clsid\{3c53010d-97ba-4650-84c5-1a6faa31055e}
HKEY_CLASSES_ROOT\clsid\{69357d4e-bf4d-4651-91e9-52ecd45a0128}
HKEY_CLASSES_ROOT\clsid\{6e21f428-5617-47f7-aed8-b2e1d8fba711}
HKEY_CLASSES_ROOT\clsid\{708be496-e202-497b-bc31-9cf47e3bf8d6}
HKEY_CLASSES_ROOT\CLSID\{8952A998-1E7E-4716-B23D-3DBE03910972}
HKEY_CLASSES_ROOT\clsid\{8b0fa130-0c3d-4cb1-aeb7-2c29da5509a3}
HKEY_CLASSES_ROOT\CLSID\{8DA5457F-A8AA-4CCF-A842-70E6FD274094}
HKEY_CLASSES_ROOT\clsid\{af8b3c81-cd19-45fb-b6be-160d27711de8}
HKEY_CLASSES_ROOT\clsid\{bbf122a7-8a4d-45b5-9e00-0f68bc87c904}
HKEY_CLASSES_ROOT\clsid\{cae0999f-78c5-49dc-9f30-13142aaaaba4}
HKEY_CLASSES_ROOT\clsid\{cd8d1caa-fe4a-45df-a06c-028aaf1821de}
HKEY_CLASSES_ROOT\CLSID\{D6DFF6D8-B94B-4720-B730-1C38C7065C3B}
HKEY_CLASSES_ROOT\CLSID\{FF76A5DA-6158-4439-99FF-EDC1B3FE100C}
HKEY_CLASSES_ROOT\common.buttons
HKEY_CLASSES_ROOT\interface\{234f09fb-fe89-4c6d-9203-31832fc051c3}
HKEY_CLASSES_ROOT\interface\{365b9a54-e613-46e5-9db1-4f91a9de80bd}
HKEY_CLASSES_ROOT\interface\{618be527-b7f5-417c-bc51-98fdc2d6de61}
HKEY_CLASSES_ROOT\interface\{66c22569-f05c-4a70-a142-763b337e1002}
HKEY_CLASSES_ROOT\interface\{6f59d850-a155-4930-98ae-689a2bc7b8e8}
HKEY_CLASSES_ROOT\interface\{7b8bd940-b1ef-460c-85a2-9acaaf7f9303}
HKEY_CLASSES_ROOT\interface\{99aa88d1-d9d3-410a-be9e-044f94c183da}
HKEY_CLASSES_ROOT\interface\{c380566d-f343-42ab-987b-6b38a1a35747}
HKEY_CLASSES_ROOT\interface\{d1951679-1d52-43fc-9585-0737143585f5}
HKEY_CLASSES_ROOT\interface\{f273d4ea-2025-4410-8408-251a0cd46be7}
HKEY_CLASSES_ROOT\PROTOCOLS\Handler\tpro
HKEY_CLASSES_ROOT\protocols\name-space handler\res
HKEY_CLASSES_ROOT\radio.radioplayer
HKEY_CLASSES_ROOT\tbps.plugincfgobj
HKEY_CLASSES_ROOT\tbps.pluginconfig
HKEY_CLASSES_ROOT\tbps.plugindown
HKEY_CLASSES_ROOT\tbps.plugindownadd
HKEY_CLASSES_ROOT\tbps.pluginevents
HKEY_CLASSES_ROOT\tbps.plugininst
HKEY_CLASSES_ROOT\tbps.pluginserver
HKEY_CLASSES_ROOT\tbps.toolbarscript
HKEY_CLASSES_ROOT\toolbar.itoolbarscriptclass
HKEY_CLASSES_ROOT\toolbar.resprotocol
HKEY_CLASSES_ROOT\typelib\{37ac49e3-e906-4bd8-ae83-d0f7fb48fd17}
HKEY_CLASSES_ROOT\typelib\{b23b3add-84b1-414a-92b9-0cabe5a781f4}
HKEY_CURRENT_USER\software\btiein
HKEY_CURRENT_USER\software\btlink
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\software\toolbar
HKEY_LOCAL_MACHINE\software\btiein
HKEY_LOCAL_MACHINE\software\btlink
HKEY_LOCAL_MACHINE\software\classes\clsid\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb}
HKEY_LOCAL_MACHINE\software\classes\interface\{1d4db7d1-6ec9-47a3-bd87-1e41684e07bb}
HKEY_LOCAL_MACHINE\software\classes\interface\{1d4db7d3-6ec9-47a3-bd87-1e41684e07bb}
HKEY_LOCAL_MACHINE\software\classes\interface\{bd6f129a-08db-4cc5-a75a-f2ab79e55b6e}
HKEY_LOCAL_MACHINE\software\classes\toolbar.itoolbarscriptclass
HKEY_LOCAL_MACHINE\software\classes\typelib\{1d4db7d0-6ec9-47a3-bd87-1e41684e07bb}
HKEY_LOCAL_MACHINE\software\classes\typelib\{8992b6ca-b8c9-4aed-bf89-0a17f6296a06}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{26E8361F-BCE7-4F75-A347-98C88B418322}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{87067F04-DE4C-4688-BC3C-4FCF39D609E7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{87766247-311C-43B4-8499-3D5FEC94A183}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8952A998-1E7E-4716-B23D-3DBE03910972}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8DA5457F-A8AA-4CCF-A842-70E6FD274094}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D6DFF6D8-B94B-4720-B730-1C38C7065C3B}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\installer\userdata\sto
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:\windows\downloaded program files\qdow_as2.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\hauto_uninstall
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\ttool_uninstall
HKEY_LOCAL_MACHINE\software\toolbar
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tbpssvc
HKEY_USERS\.default\software\toolbar
HKEY_CLASSES_ROOT\btieinscriptconfigproj.btieinscriptc
HKEY_CLASSES_ROOT\btieinscriptconfigproj.btieinscriptconfig
HKEY_CLASSES_ROOT\clsid\{001dae60-95c0-11d3-924e-009027950886}
HKEY_CLASSES_ROOT\clsid\{26e8361f-bce7-4f75-a347-98c88b418322}
HKEY_CLASSES_ROOT\clsid\{339bb23f-a864-48c0-a59f-29ea915965ec}
HKEY_CLASSES_ROOT\clsid\{356639aa-e878-40ff-b2f8-e22fa87df389}
HKEY_CLASSES_ROOT\clsid\{63b78bc1-a711-4d46-ad2f-c581ac420d41}
HKEY_CLASSES_ROOT\clsid\{8952a998-1e7e-4716-b23d-3dbe03910972}
HKEY_CLASSES_ROOT\clsid\{8da5457f-a8aa-4ccf-a842-70e6fd274094}
HKEY_CLASSES_ROOT\clsid\{cabcf5e7-0c79-4f1c-909d-b9cf68fed746}
HKEY_CLASSES_ROOT\clsid\{d6dff6d8-b94b-4720-b730-1c38c7065c3b}
HKEY_CLASSES_ROOT\clsid\{f1616b86-9288-489d-b71a-0ccf2f1a89da}
HKEY_CLASSES_ROOT\clsid\{fb45c451-b0e9-4407-bb6a-9361013f3e9a}
HKEY_CLASSES_ROOT\clsid\{ff76a5da-6158-4439-99ff-edc1b3fe100c}
HKEY_CLASSES_ROOT\interface\{26e8361f-bce7-4f75-a347-98c88b418321}
HKEY_CLASSES_ROOT\protocols\handler\relatedlinks
HKEY_CLASSES_ROOT\protocols\handler\tpro
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{001dae60-95c0-11d3-924e-009027950886}
HKEY_CLASSES_ROOT\ssaver.saverobj
HKEY_CLASSES_ROOT\typelib\{5cf68a06-673d-4619-a805-c8fc9ac611dd}
HKEY_CLASSES_ROOT\typelib\{db9a4e78-35df-4a54-b6c5-c5190ceaf949}
HKEY_LOCAL_MACHINE\software\classes\clsid\{001dae60-95c0-11d3-924e-009027950886}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{26e8361f-bce7-4f75-a347-98c88b418322}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{87067f04-de4c-4688-bc3c-4fcf39d609e7}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{001dae60-95c0-11d3-924e-009027950886}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{63b78bc1-a711-4d46-ad2f-c581ac420d41}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{87766247-311c-43b4-8499-3d5fec94a183}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{8952a998-1e7e-4716-b23d-3dbe03910972}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{8da5457f-a8aa-4ccf-a842-70e6fd274094}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{d6dff6d8-b94b-4720-b730-1c38c7065c3b}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\[%WINDOWS%]\downloaded program files\qdow_as2.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\btlink_dll

Registry Values:
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_CURRENT_USER\software\microsoft\internet explorer\urlsearchhooks
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_USERS\.default\software\microsoft\internet explorer\urlsearchhooks
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\software\microsoft\internet explorer\main
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser
HKEY_CURRENT_USER\software\microsoft\internet explorer\urlsearchhooks
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\search
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\search
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\search
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\search
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\urlsearchhooks
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex\0001
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list

Removing WebSearch:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Bancos.FZT Trojan Removal instruction

Vundo Trojan

Removing Vundo
Categories: Trojan,Adware,BHO,Backdoor,Toolbar,Downloader
This category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.
Adware are programs that facilitate delivery for advertising content
to the user and in some cases gather information from the user's computer,
including information related to Internet browser usage or other computer habits
The BHO (Browser Helper Object) waits for the user to post personal information to a monitored website.
As this information is entered by the user, it is captured by the BHO and sent back to the attacker.
Backdoors are the most dangerous type of Trojans and the most popular.
Backdoors open infected machines to external control via Internet.
They function in the same way as legal remote administration programs used by system administrators.
This makes them difficult to detect.

Backdoors are installed and launched without the consent of the user of computer.
Often the backdoor will not be visible in the log of active programs.

Once a backdoor has been successfully launched, the computer is wide open.
Backdoor functions can include:


  • Launching/ deleting files

  • Sending/ receiving files

  • Deleting data

  • Displaying notification

  • Rebooting the machine

  • Executing files




Backdoors are used by virus writers to detect and download confidential information,
execute malicious code, destroy data, include the machine in bot networks and so forth.
Backdoors combine the functionality of most other types of in one package.

Backdoors have one especially dangerous sub-class: variants that can propagate like worms.
Toolbar presents itself as a helpful add-on for Internet Explorer but it is a real pest.
It replaces your start page, continuosly open a number of pop up windows and so on.
The downloader either launches the new malware or registers it to enable autorun
according to the local operating system requirements.

Vundo Also known as:

[Kaspersky]AdWare.Win32.Virtumonde.fp,AdWare.Win32.Virtumonde.jp,AdWare.Win32.SecToolBar.h,AdWare.Win32.Virtumonde.aju,AdWare.Win32.Virtumonde.aqi,Trojan.Win32.Agent.ctk;
[McAfee]Vundo;
[Panda]Spyware/Virtumonde,Adware/Gator;
[Computer Associates]Win32.Vundo,Win32.Vundo.H,Win32/Vundo!Trojan,Win32/Vundo.DLL!Trojan,Win32.Vundo.O,Win32/Vundo.522752!Trojan;
[Other]Win32/Vundo,Mal/Behav-099,Trojan.Vundo,Win32/Vundo!generic,Win32/Vundo.CI,Win32/Vundo.CM,TROJ_VUNDO.AWA,Vundo.gen32,Win32/Vundo.GT,Vundo.gen49,Trojan.Awax,Win32/Darksma.GU,Troj/BHO-DZ,Win32/Vundo.GW,Win32/Vundo.GX,Win32/Vundo.HL,Vundo.gen4l

Visible Symptoms:
Files in system folders:
[%PROFILE_TEMP%]\ipatnu.dat
[%PROFILE_TEMP%]\patch302.exe
[%PROFILE_TEMP%]\tenbv.dat
[%PROFILE_TEMP%]\tmp1.tmp.exe
[%PROFILE_TEMP%]\tmp13C.tmp.exe
[%PROFILE_TEMP%]\tmp183.tmp.exe
[%PROFILE_TEMP%]\tmp19.tmp.exe
[%PROFILE_TEMP%]\tmp1A0.tmp.exe
[%PROFILE_TEMP%]\tmp1E7.tmp.exe
[%PROFILE_TEMP%]\tmp2A.tmp.exe
[%PROFILE_TEMP%]\tmp3D.tmp.exe
[%PROFILE_TEMP%]\tmp3E0.tmp.exe
[%PROFILE_TEMP%]\tmp3E6.tmp.exe
[%PROFILE_TEMP%]\tmp3EE.tmp.exe
[%PROFILE_TEMP%]\tmp68.tmp.exe
[%PROFILE_TEMP%]\tmp6A.tmp.exe
[%PROFILE_TEMP%]\tmp89.tmp.exe
[%PROFILE_TEMP%]\tmp8C.tmp.exe
[%PROFILE_TEMP%]\tmpBE.tmp.exe
[%PROFILE_TEMP%]\tmpC3.tmp.exe
[%PROFILE_TEMP%]\tmpD0.tmp.exe
[%PROFILE_TEMP%]\tmpE0.tmp.exe
[%SYSTEM%]\awvtu.dll
[%SYSTEM%]\hjllm.bak1
[%SYSTEM%]\hjllm.ini
[%SYSTEM%]\MC2O3MVV.F2B
[%SYSTEM%]\mlljh.dll
[%SYSTEM%]\pmkhe.dll
[%WINDOWS%]\awtuut.dll
[%WINDOWS%]\cbxxvw.dll
[%WINDOWS%]\ddbawv.dll
[%WINDOWS%]\effcyv.dll
[%WINDOWS%]\gebxxx.dll
[%WINDOWS%]\geeebc.dll
[%WINDOWS%]\hggdcb.dll
[%WINDOWS%]\iihife.dll
[%WINDOWS%]\iiihec.dll
[%WINDOWS%]\khgedb.dll
[%WINDOWS%]\ljijkk.dll
[%WINDOWS%]\mlifgh.dll
[%WINDOWS%]\nnmmnk.dll
[%WINDOWS%]\opmmlk.dll
[%WINDOWS%]\opmmmk.dll
[%WINDOWS%]\oponll.dll
[%WINDOWS%]\qonkll.dll
[%WINDOWS%]\rqommn.dll
[%WINDOWS%]\rqrsrr.dll
[%WINDOWS%]\tutuvw.dll
[%WINDOWS%]\urssss.dll
[%WINDOWS%]\vtuuro.dll
[%WINDOWS%]\xxxyyy.dll
[%WINDOWS%]\yaabxw.dll
[%WINDOWS%]\yabbca.dll
[%WINDOWS%]\yaxyab.dll
[%PROFILE_TEMP%]\nursar.dat
[%PROFILE_TEMP%]\patch321.exe
[%PROFILE_TEMP%]\svci.exe
[%PROFILE_TEMP%]\VMTEMP.TMP
[%SYSTEM%]\cidrules.dll
[%SYSTEM%]\jiijyilm.dll
[%SYSTEM%]\khfecdb.dll
[%SYSTEM%]\svci.exe
[%WINDOWS%]\inf\psdrv.exe
[%WINDOWS%]\inf\vrdsp.ini
[%PROFILE_TEMP%]\ipatnu.dat
[%PROFILE_TEMP%]\patch302.exe
[%PROFILE_TEMP%]\tenbv.dat
[%PROFILE_TEMP%]\tmp1.tmp.exe
[%PROFILE_TEMP%]\tmp13C.tmp.exe
[%PROFILE_TEMP%]\tmp183.tmp.exe
[%PROFILE_TEMP%]\tmp19.tmp.exe
[%PROFILE_TEMP%]\tmp1A0.tmp.exe
[%PROFILE_TEMP%]\tmp1E7.tmp.exe
[%PROFILE_TEMP%]\tmp2A.tmp.exe
[%PROFILE_TEMP%]\tmp3D.tmp.exe
[%PROFILE_TEMP%]\tmp3E0.tmp.exe
[%PROFILE_TEMP%]\tmp3E6.tmp.exe
[%PROFILE_TEMP%]\tmp3EE.tmp.exe
[%PROFILE_TEMP%]\tmp68.tmp.exe
[%PROFILE_TEMP%]\tmp6A.tmp.exe
[%PROFILE_TEMP%]\tmp89.tmp.exe
[%PROFILE_TEMP%]\tmp8C.tmp.exe
[%PROFILE_TEMP%]\tmpBE.tmp.exe
[%PROFILE_TEMP%]\tmpC3.tmp.exe
[%PROFILE_TEMP%]\tmpD0.tmp.exe
[%PROFILE_TEMP%]\tmpE0.tmp.exe
[%SYSTEM%]\awvtu.dll
[%SYSTEM%]\hjllm.bak1
[%SYSTEM%]\hjllm.ini
[%SYSTEM%]\MC2O3MVV.F2B
[%SYSTEM%]\mlljh.dll
[%SYSTEM%]\pmkhe.dll
[%WINDOWS%]\awtuut.dll
[%WINDOWS%]\cbxxvw.dll
[%WINDOWS%]\ddbawv.dll
[%WINDOWS%]\effcyv.dll
[%WINDOWS%]\gebxxx.dll
[%WINDOWS%]\geeebc.dll
[%WINDOWS%]\hggdcb.dll
[%WINDOWS%]\iihife.dll
[%WINDOWS%]\iiihec.dll
[%WINDOWS%]\khgedb.dll
[%WINDOWS%]\ljijkk.dll
[%WINDOWS%]\mlifgh.dll
[%WINDOWS%]\nnmmnk.dll
[%WINDOWS%]\opmmlk.dll
[%WINDOWS%]\opmmmk.dll
[%WINDOWS%]\oponll.dll
[%WINDOWS%]\qonkll.dll
[%WINDOWS%]\rqommn.dll
[%WINDOWS%]\rqrsrr.dll
[%WINDOWS%]\tutuvw.dll
[%WINDOWS%]\urssss.dll
[%WINDOWS%]\vtuuro.dll
[%WINDOWS%]\xxxyyy.dll
[%WINDOWS%]\yaabxw.dll
[%WINDOWS%]\yabbca.dll
[%WINDOWS%]\yaxyab.dll
[%PROFILE_TEMP%]\nursar.dat
[%PROFILE_TEMP%]\patch321.exe
[%PROFILE_TEMP%]\svci.exe
[%PROFILE_TEMP%]\VMTEMP.TMP
[%SYSTEM%]\cidrules.dll
[%SYSTEM%]\jiijyilm.dll
[%SYSTEM%]\khfecdb.dll
[%SYSTEM%]\svci.exe
[%WINDOWS%]\inf\psdrv.exe
[%WINDOWS%]\inf\vrdsp.ini

How to detect Vundo:

Files:
[%PROFILE_TEMP%]\ipatnu.dat
[%PROFILE_TEMP%]\patch302.exe
[%PROFILE_TEMP%]\tenbv.dat
[%PROFILE_TEMP%]\tmp1.tmp.exe
[%PROFILE_TEMP%]\tmp13C.tmp.exe
[%PROFILE_TEMP%]\tmp183.tmp.exe
[%PROFILE_TEMP%]\tmp19.tmp.exe
[%PROFILE_TEMP%]\tmp1A0.tmp.exe
[%PROFILE_TEMP%]\tmp1E7.tmp.exe
[%PROFILE_TEMP%]\tmp2A.tmp.exe
[%PROFILE_TEMP%]\tmp3D.tmp.exe
[%PROFILE_TEMP%]\tmp3E0.tmp.exe
[%PROFILE_TEMP%]\tmp3E6.tmp.exe
[%PROFILE_TEMP%]\tmp3EE.tmp.exe
[%PROFILE_TEMP%]\tmp68.tmp.exe
[%PROFILE_TEMP%]\tmp6A.tmp.exe
[%PROFILE_TEMP%]\tmp89.tmp.exe
[%PROFILE_TEMP%]\tmp8C.tmp.exe
[%PROFILE_TEMP%]\tmpBE.tmp.exe
[%PROFILE_TEMP%]\tmpC3.tmp.exe
[%PROFILE_TEMP%]\tmpD0.tmp.exe
[%PROFILE_TEMP%]\tmpE0.tmp.exe
[%SYSTEM%]\awvtu.dll
[%SYSTEM%]\hjllm.bak1
[%SYSTEM%]\hjllm.ini
[%SYSTEM%]\MC2O3MVV.F2B
[%SYSTEM%]\mlljh.dll
[%SYSTEM%]\pmkhe.dll
[%WINDOWS%]\awtuut.dll
[%WINDOWS%]\cbxxvw.dll
[%WINDOWS%]\ddbawv.dll
[%WINDOWS%]\effcyv.dll
[%WINDOWS%]\gebxxx.dll
[%WINDOWS%]\geeebc.dll
[%WINDOWS%]\hggdcb.dll
[%WINDOWS%]\iihife.dll
[%WINDOWS%]\iiihec.dll
[%WINDOWS%]\khgedb.dll
[%WINDOWS%]\ljijkk.dll
[%WINDOWS%]\mlifgh.dll
[%WINDOWS%]\nnmmnk.dll
[%WINDOWS%]\opmmlk.dll
[%WINDOWS%]\opmmmk.dll
[%WINDOWS%]\oponll.dll
[%WINDOWS%]\qonkll.dll
[%WINDOWS%]\rqommn.dll
[%WINDOWS%]\rqrsrr.dll
[%WINDOWS%]\tutuvw.dll
[%WINDOWS%]\urssss.dll
[%WINDOWS%]\vtuuro.dll
[%WINDOWS%]\xxxyyy.dll
[%WINDOWS%]\yaabxw.dll
[%WINDOWS%]\yabbca.dll
[%WINDOWS%]\yaxyab.dll
[%PROFILE_TEMP%]\nursar.dat
[%PROFILE_TEMP%]\patch321.exe
[%PROFILE_TEMP%]\svci.exe
[%PROFILE_TEMP%]\VMTEMP.TMP
[%SYSTEM%]\cidrules.dll
[%SYSTEM%]\jiijyilm.dll
[%SYSTEM%]\khfecdb.dll
[%SYSTEM%]\svci.exe
[%WINDOWS%]\inf\psdrv.exe
[%WINDOWS%]\inf\vrdsp.ini
[%PROFILE_TEMP%]\ipatnu.dat
[%PROFILE_TEMP%]\patch302.exe
[%PROFILE_TEMP%]\tenbv.dat
[%PROFILE_TEMP%]\tmp1.tmp.exe
[%PROFILE_TEMP%]\tmp13C.tmp.exe
[%PROFILE_TEMP%]\tmp183.tmp.exe
[%PROFILE_TEMP%]\tmp19.tmp.exe
[%PROFILE_TEMP%]\tmp1A0.tmp.exe
[%PROFILE_TEMP%]\tmp1E7.tmp.exe
[%PROFILE_TEMP%]\tmp2A.tmp.exe
[%PROFILE_TEMP%]\tmp3D.tmp.exe
[%PROFILE_TEMP%]\tmp3E0.tmp.exe
[%PROFILE_TEMP%]\tmp3E6.tmp.exe
[%PROFILE_TEMP%]\tmp3EE.tmp.exe
[%PROFILE_TEMP%]\tmp68.tmp.exe
[%PROFILE_TEMP%]\tmp6A.tmp.exe
[%PROFILE_TEMP%]\tmp89.tmp.exe
[%PROFILE_TEMP%]\tmp8C.tmp.exe
[%PROFILE_TEMP%]\tmpBE.tmp.exe
[%PROFILE_TEMP%]\tmpC3.tmp.exe
[%PROFILE_TEMP%]\tmpD0.tmp.exe
[%PROFILE_TEMP%]\tmpE0.tmp.exe
[%SYSTEM%]\awvtu.dll
[%SYSTEM%]\hjllm.bak1
[%SYSTEM%]\hjllm.ini
[%SYSTEM%]\MC2O3MVV.F2B
[%SYSTEM%]\mlljh.dll
[%SYSTEM%]\pmkhe.dll
[%WINDOWS%]\awtuut.dll
[%WINDOWS%]\cbxxvw.dll
[%WINDOWS%]\ddbawv.dll
[%WINDOWS%]\effcyv.dll
[%WINDOWS%]\gebxxx.dll
[%WINDOWS%]\geeebc.dll
[%WINDOWS%]\hggdcb.dll
[%WINDOWS%]\iihife.dll
[%WINDOWS%]\iiihec.dll
[%WINDOWS%]\khgedb.dll
[%WINDOWS%]\ljijkk.dll
[%WINDOWS%]\mlifgh.dll
[%WINDOWS%]\nnmmnk.dll
[%WINDOWS%]\opmmlk.dll
[%WINDOWS%]\opmmmk.dll
[%WINDOWS%]\oponll.dll
[%WINDOWS%]\qonkll.dll
[%WINDOWS%]\rqommn.dll
[%WINDOWS%]\rqrsrr.dll
[%WINDOWS%]\tutuvw.dll
[%WINDOWS%]\urssss.dll
[%WINDOWS%]\vtuuro.dll
[%WINDOWS%]\xxxyyy.dll
[%WINDOWS%]\yaabxw.dll
[%WINDOWS%]\yabbca.dll
[%WINDOWS%]\yaxyab.dll
[%PROFILE_TEMP%]\nursar.dat
[%PROFILE_TEMP%]\patch321.exe
[%PROFILE_TEMP%]\svci.exe
[%PROFILE_TEMP%]\VMTEMP.TMP
[%SYSTEM%]\cidrules.dll
[%SYSTEM%]\jiijyilm.dll
[%SYSTEM%]\khfecdb.dll
[%SYSTEM%]\svci.exe
[%WINDOWS%]\inf\psdrv.exe
[%WINDOWS%]\inf\vrdsp.ini

Folders:
[%PROGRAM_FILES%]\earn

Registry Keys:
HKEY_CLASSES_ROOT\atlevents.atlevents
HKEY_CLASSES_ROOT\atlevents.atlevents.1
HKEY_CLASSES_ROOT\CLSID\{1AE6D7D5-0C28-4DB6-9FD1-33B870A4C5F2}
HKEY_CLASSES_ROOT\dosspecfolder.dosspecfolder
HKEY_CLASSES_ROOT\dosspecfolder.dosspecfolder.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\vtsqo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1AE6D7D5-0C28-4DB6-9FD1-33B870A4C5F2}
HKEY_CLASSES_ROOT\clsid\{0612f71e-934b-4d92-b8e8-2e29ea78eb03}
HKEY_CLASSES_ROOT\clsid\{13589181-4f0d-4553-b9f8-b4b72172c139}
HKEY_CLASSES_ROOT\clsid\{1ae6d7d5-0c28-4db6-9fd1-33b870a4c5f2}
HKEY_CLASSES_ROOT\clsid\{2316230a-c89c-4bcc-95c2-66659ac7a775}
HKEY_CLASSES_ROOT\clsid\{2538878e-873a-48e7-85a6-c53acd0da915}
HKEY_CLASSES_ROOT\clsid\{2c80ead3-74cd-4700-83a4-aa878cd1c03c}\inprocserver32
HKEY_CLASSES_ROOT\clsid\{8109af33-6949-4833-8881-43dcc232b7b2}
HKEY_CLASSES_ROOT\clsid\{bb54de33-e539-4749-bfac-cc49617e8f2a}
HKEY_CLASSES_ROOT\clsid\{d6964fd8-3af1-4a2a-abb7-3d0c62924fd6}
HKEY_CURRENT_USER\software\microsoft\sysupd
HKEY_CURRENT_USER\software\microsoft\windowsupd
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\catw
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmkhe
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psdrv
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqrsrr
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtsqo
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\windku32
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{0612f71e-934b-4d92-b8e8-2e29ea78eb03}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{1ae6d7d5-0c28-4db6-9fd1-33b870a4c5f2}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{2316230a-c89c-4bcc-95c2-66659ac7a775}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{2538878e-873a-48e7-85a6-c53acd0da915}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{8109af33-6949-4833-8881-43dcc232b7b2}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{d6964fd8-3af1-4a2a-abb7-3d0c62924fd6}
HKEY_LOCAL_MACHINE\software\targetsoft

Registry Values:
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CLASSES_ROOT\clsid\{5ac8b218-35b8-4923-9887-2f52657f8d5c}\inprocserver32
HKEY_CLASSES_ROOT\clsid\{849b9523-785f-4014-9caf-079fb4a74c61}\inprocserver32
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce

Removing Vundo:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
CWS.AFF.IEDLL Hijacker Information
Frethog.ACT Trojan Information
Removing Win.AOL.Cindi Trojan
VBS.Rekun Trojan Symptoms

ActiveX Malware Malware

Removing ActiveX Malware
Categories: Malware
Malware includes a range of programs that do not threaten computers directly,
but are used to create viruses or Trojans, or used to carry out illegal activities
such as DoS attacks and breaking into other computers.

Visible Symptoms:
Files in system folders:
[%PROGRAM_FILES%]\AWS\WeatherBug\MiniBugTransporter.dll
[%PROGRAM_FILES%]\Microsoft File Transfer Manager\ftm_en-us.xml
[%PROGRAM_FILES%]\Microsoft File Transfer Manager\ftm_LanguageList.xml
[%PROGRAM_FILES%]\Microsoft File Transfer Manager\grTransferCtrl.dll
[%PROGRAM_FILES%]\Microsoft File Transfer Manager\grTransferMgr.dll
[%PROGRAM_FILES%]\Microsoft File Transfer Manager\TransferMgr.exe
[%SYSTEM%]\adwerkz.dll
[%SYSTEM%]\asycfilt.dll
[%SYSTEM%]\AxConfig.dll
[%SYSTEM%]\back.gif
[%SYSTEM%]\brix6ie.ocx
[%SYSTEM%]\BSTIEPrintCtl1.dll
[%SYSTEM%]\comcat.dll
[%SYSTEM%]\dialer_activex.ocx
[%SYSTEM%]\egaccess4_1058.dll
[%SYSTEM%]\egaccess4_1060.dll
[%SYSTEM%]\egaccess4_1063.dll
[%SYSTEM%]\egaccess4_1064.dll
[%SYSTEM%]\EGCOMSERVICE2.dll
[%SYSTEM%]\EGCOMSERVICE_1045.dll
[%SYSTEM%]\eglivecam_1027.dll
[%SYSTEM%]\hyundai_key.bmp
[%SYSTEM%]\ieaccess2.dll
[%SYSTEM%]\INICRYPTOSDK.dll
[%SYSTEM%]\ksfc_key.bmp
[%SYSTEM%]\lgcard_key.bmp
[%SYSTEM%]\LiveService_4.dll
[%SYSTEM%]\mfc42.dll
[%SYSTEM%]\Msinet.ocx
[%SYSTEM%]\msstkprp.dll
[%SYSTEM%]\msvbvm60.dll
[%SYSTEM%]\msvcrt.dll
[%SYSTEM%]\npcopyv.exe
[%SYSTEM%]\npdown.dll
[%SYSTEM%]\npdownv.exe
[%SYSTEM%]\npdown_.dll
[%SYSTEM%]\npkagt.exe
[%SYSTEM%]\npkcnt4.sys
[%SYSTEM%]\npkcrypt.dll
[%SYSTEM%]\npkcrypt.sys
[%SYSTEM%]\npkcrypt.vxd
[%SYSTEM%]\npkcsvc.exe
[%SYSTEM%]\npkcusb.sys
[%SYSTEM%]\npkcx.ocx
[%SYSTEM%]\npkeyc.sys
[%SYSTEM%]\npkeycs.sys
[%SYSTEM%]\npkeysdk.dll
[%SYSTEM%]\npkpdb.dll
[%SYSTEM%]\npkSvcUpdate.exe
[%SYSTEM%]\npkuninst.exe
[%SYSTEM%]\npnv3uninst.exe
[%SYSTEM%]\npx.ocx
[%SYSTEM%]\np_chs.ini
[%SYSTEM%]\np_eng.ini
[%SYSTEM%]\np_jpn.ini
[%SYSTEM%]\np_kor.ini
[%SYSTEM%]\ObjSafe.tlb
[%SYSTEM%]\oleaut32.dll
[%SYSTEM%]\olepro32.dll
[%SYSTEM%]\P2ECOM.dll
[%SYSTEM%]\psapi.dll
[%SYSTEM%]\regobj.dll
[%SYSTEM%]\RSAG726D.dll
[%SYSTEM%]\RSAG726E.dll
[%SYSTEM%]\safe.tlb
[%SYSTEM%]\stdole2.tlb
[%SYSTEM%]\svcsysnet32.dll
[%SYSTEM%]\tintel.dll
[%SYSTEM%]\toolbar.dll
[%SYSTEM%]\update.txt
[%SYSTEM%]\Vbshell.tlb
[%SYSTEM%]\version.txt
[%SYSTEM%]\vrdown.dll
[%SYSTEM%]\vrunzip.dll
[%SYSTEM%]\vviewer.ocx
[%SYSTEM%]\WinATS.dll
[%WINDOWS%]\amm06.ocx
[%WINDOWS%]\Bernadette.dll
[%WINDOWS%]\CBBasis.xml
[%WINDOWS%]\CBVersion.txt
[%WINDOWS%]\cpbrkpie.ocx
[%WINDOWS%]\Downloaded Program Files\ActiveSecurity.ocx
[%WINDOWS%]\Downloaded Program Files\actsetup.dll
[%WINDOWS%]\Downloaded Program Files\AktiveSekurity.ocx
[%WINDOWS%]\Downloaded Program Files\amm06.ocx
[%WINDOWS%]\Downloaded Program Files\AXDownloader.dll
[%WINDOWS%]\Downloaded Program Files\ax_mjpeg.ocx
[%WINDOWS%]\Downloaded Program Files\Bol Downloader.ocx
[%WINDOWS%]\Downloaded Program Files\BrowserAccelerator.dll
[%WINDOWS%]\downloaded program files\clientax.dll
[%WINDOWS%]\Downloaded Program Files\comload.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.10\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.10\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.11\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.12\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.12\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.14\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.14\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.15\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.15\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.17\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.18\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.18\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.19\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\dlhelper.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\d_loader.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\ftm_en-us.xml
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\ftm_LanguageList.xml
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\grTransferCtrl.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\HDPlugin1101.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\Install.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\IWCHECK.DLL
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\MSJavX86.exe,DanaInfo=PRT-ST01.kp.org,CT=java+
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\popcaploader.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\RdxIE.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\rnd_soft.php
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\securelogin.ocx
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\TransferMgr.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UDC6_0001_D19M2808NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UDC6_0001_D21M0303NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UPRP_0001_D21M2103NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\USDR6V_0001_D18M3107NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UWAS6_0001_N68M2301NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UWAS6_0001_N69M0703NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\xpreload.ocx
[%WINDOWS%]\Downloaded Program Files\CONFLICT.20\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.21\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.22\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.24\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.25\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.26\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.27\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.28\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.29\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.2\MSJavX86.exe,DanaInfo=PRT-ST01.kp.org,CT=java+
[%WINDOWS%]\Downloaded Program Files\CONFLICT.2\RdxIE.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.2\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.2\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.2\USDR6_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.3\MSJavX86.exe,DanaInfo=PRT-ST01.kp.org,CT=java+
[%WINDOWS%]\Downloaded Program Files\CONFLICT.3\popcaploader.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.3\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.3\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.4\popcaploader.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.4\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.4\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.4\UDC6_0001_D19M2808NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.4\USDR6_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.5\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.5\USDR6_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.6\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.6\USDR6_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.7\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.8\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.8\USDR6_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.9\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\downloaded program files\cpnmgr.dll
[%WINDOWS%]\Downloaded Program Files\cscmv4x.dll
[%WINDOWS%]\Downloaded Program Files\csetup.dll
[%WINDOWS%]\Downloaded Program Files\Customtoolbar.exe
[%WINDOWS%]\Downloaded Program Files\Dhsigned.ocx
[%WINDOWS%]\Downloaded Program Files\dialxs.ocx
[%WINDOWS%]\Downloaded Program Files\dlhelper.dll
[%WINDOWS%]\Downloaded Program Files\downloader.ocx
[%WINDOWS%]\Downloaded Program Files\dwnldr.dll
[%WINDOWS%]\Downloaded Program Files\ffav.dll
[%WINDOWS%]\Downloaded Program Files\ForbesDownloader.ocx
[%WINDOWS%]\Downloaded Program Files\ftm_en-us.xml
[%WINDOWS%]\Downloaded Program Files\ftm_LanguageList.xml
[%WINDOWS%]\Downloaded Program Files\gdownloader.ocx
[%WINDOWS%]\Downloaded Program Files\gigexagent.dll
[%WINDOWS%]\Downloaded Program Files\grTransferCtrl.dll
[%WINDOWS%]\Downloaded Program Files\grTransferMgr.dll
[%WINDOWS%]\Downloaded Program Files\HbInstIE.dll
[%WINDOWS%]\Downloaded Program Files\HWAudio.dll
[%WINDOWS%]\Downloaded Program Files\HWReal.exe
[%WINDOWS%]\Downloaded Program Files\HWUtils.dll
[%WINDOWS%]\Downloaded Program Files\Install.dll
[%WINDOWS%]\Downloaded Program Files\internazionale_ver4.ocx
[%WINDOWS%]\Downloaded Program Files\int_ver32b.ocx
[%WINDOWS%]\Downloaded Program Files\int_ver34.ocx
[%WINDOWS%]\Downloaded Program Files\ISTactivex.dll
[%WINDOWS%]\Downloaded Program Files\IWCHECK.DLL
[%WINDOWS%]\Downloaded Program Files\MaConnect.dll
[%WINDOWS%]\Downloaded Program Files\MailAlertUpgrade_MAIL.exe
[%WINDOWS%]\Downloaded Program Files\mail_mcea115.exe
[%WINDOWS%]\Downloaded Program Files\MediaGatewayX.dll
[%WINDOWS%]\Downloaded Program Files\MiniBugTransporter.dll
[%WINDOWS%]\Downloaded Program Files\miniclipGameLoader.dll
[%WINDOWS%]\Downloaded Program Files\MSJavX86.exe,DanaInfo=PRT-ST01.kp.org,CT=java+
[%WINDOWS%]\Downloaded Program Files\npkxsite.ocx
[%WINDOWS%]\Downloaded Program Files\npx.ocx
[%WINDOWS%]\Downloaded Program Files\OTXMedia.dll
[%WINDOWS%]\Downloaded Program Files\popcaploader.dll
[%WINDOWS%]\Downloaded Program Files\PopupSh.ocx
[%WINDOWS%]\Downloaded Program Files\RdxIE.dll
[%WINDOWS%]\Downloaded Program Files\rnd_soft.php
[%WINDOWS%]\Downloaded Program Files\SAIX.dll
[%WINDOWS%]\Downloaded Program Files\securelogin.ocx
[%WINDOWS%]\Downloaded Program Files\setup.exe
[%WINDOWS%]\Downloaded Program Files\setup_mcnear_online.EXE
[%WINDOWS%]\Downloaded Program Files\SSCHECK.DLL
[%WINDOWS%]\Downloaded Program Files\SSP.ocx
[%WINDOWS%]\Downloaded Program Files\TAMUScanLauncher.EXE
[%WINDOWS%]\Downloaded Program Files\Toolbar_cobrand.EXE
[%WINDOWS%]\Downloaded Program Files\TransferMgr.exe
[%WINDOWS%]\Downloaded Program Files\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6M_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6V_0001_D19M1009NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6Y_0001_D13M0707NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6Y_0001_D19M0809NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6_0001_D19M2808NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6_0001_D21M0303NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6_0001_D21M1601NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6_0001_D22M1709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6_4444_D21M0303NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UERS_9999_N91S2507NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UERT_0001_D18M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UERT_0001_D19M2109NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UniDist.ocx
[%WINDOWS%]\Downloaded Program Files\UPRP_0001_D21M1501NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UPRP_0001_D21M2103NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6T_0001_D18M3107NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6T_0001_N19M1105NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6V_0001_D18M3107NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6V_0001_N19M2604NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6Y_0001_D13M1007NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6Y_0001_D18M1608NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6Y_0001_D18M3107NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6_0001_D08M0404NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6_7777_BHLP0611NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6_9999_N18M1603NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UWA6PY_0001_N91M2107NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UWA7P_0001_N91M0809NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UWAS7_0001_N99M3108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\videox.dll
[%WINDOWS%]\Downloaded Program Files\VLoading.dll
[%WINDOWS%]\Downloaded Program Files\WebP2PInstaller.dll
[%WINDOWS%]\Downloaded Program Files\WebP2PInstaller2.dll
[%WINDOWS%]\Downloaded Program Files\website.dll
[%WINDOWS%]\Downloaded Program Files\xpreload.ocx
[%WINDOWS%]\Downloaded Program Files\ysbactivex.dll
[%WINDOWS%]\eg_auth_1045.dll
[%WINDOWS%]\eg_auth_1046.dll
[%WINDOWS%]\Iseult.dll
[%WINDOWS%]\mdkiaf.exe
[%WINDOWS%]\MediaConnect.ocx
[%WINDOWS%]\minigolf_affiliate.exe
[%PROGRAM_FILES%]\AWS\WeatherBug\MiniBugTransporter.dll
[%PROGRAM_FILES%]\Microsoft File Transfer Manager\ftm_en-us.xml
[%PROGRAM_FILES%]\Microsoft File Transfer Manager\ftm_LanguageList.xml
[%PROGRAM_FILES%]\Microsoft File Transfer Manager\grTransferCtrl.dll
[%PROGRAM_FILES%]\Microsoft File Transfer Manager\grTransferMgr.dll
[%PROGRAM_FILES%]\Microsoft File Transfer Manager\TransferMgr.exe
[%SYSTEM%]\adwerkz.dll
[%SYSTEM%]\asycfilt.dll
[%SYSTEM%]\AxConfig.dll
[%SYSTEM%]\back.gif
[%SYSTEM%]\brix6ie.ocx
[%SYSTEM%]\BSTIEPrintCtl1.dll
[%SYSTEM%]\comcat.dll
[%SYSTEM%]\dialer_activex.ocx
[%SYSTEM%]\egaccess4_1058.dll
[%SYSTEM%]\egaccess4_1060.dll
[%SYSTEM%]\egaccess4_1063.dll
[%SYSTEM%]\egaccess4_1064.dll
[%SYSTEM%]\EGCOMSERVICE2.dll
[%SYSTEM%]\EGCOMSERVICE_1045.dll
[%SYSTEM%]\eglivecam_1027.dll
[%SYSTEM%]\hyundai_key.bmp
[%SYSTEM%]\ieaccess2.dll
[%SYSTEM%]\INICRYPTOSDK.dll
[%SYSTEM%]\ksfc_key.bmp
[%SYSTEM%]\lgcard_key.bmp
[%SYSTEM%]\LiveService_4.dll
[%SYSTEM%]\mfc42.dll
[%SYSTEM%]\Msinet.ocx
[%SYSTEM%]\msstkprp.dll
[%SYSTEM%]\msvbvm60.dll
[%SYSTEM%]\msvcrt.dll
[%SYSTEM%]\npcopyv.exe
[%SYSTEM%]\npdown.dll
[%SYSTEM%]\npdownv.exe
[%SYSTEM%]\npdown_.dll
[%SYSTEM%]\npkagt.exe
[%SYSTEM%]\npkcnt4.sys
[%SYSTEM%]\npkcrypt.dll
[%SYSTEM%]\npkcrypt.sys
[%SYSTEM%]\npkcrypt.vxd
[%SYSTEM%]\npkcsvc.exe
[%SYSTEM%]\npkcusb.sys
[%SYSTEM%]\npkcx.ocx
[%SYSTEM%]\npkeyc.sys
[%SYSTEM%]\npkeycs.sys
[%SYSTEM%]\npkeysdk.dll
[%SYSTEM%]\npkpdb.dll
[%SYSTEM%]\npkSvcUpdate.exe
[%SYSTEM%]\npkuninst.exe
[%SYSTEM%]\npnv3uninst.exe
[%SYSTEM%]\npx.ocx
[%SYSTEM%]\np_chs.ini
[%SYSTEM%]\np_eng.ini
[%SYSTEM%]\np_jpn.ini
[%SYSTEM%]\np_kor.ini
[%SYSTEM%]\ObjSafe.tlb
[%SYSTEM%]\oleaut32.dll
[%SYSTEM%]\olepro32.dll
[%SYSTEM%]\P2ECOM.dll
[%SYSTEM%]\psapi.dll
[%SYSTEM%]\regobj.dll
[%SYSTEM%]\RSAG726D.dll
[%SYSTEM%]\RSAG726E.dll
[%SYSTEM%]\safe.tlb
[%SYSTEM%]\stdole2.tlb
[%SYSTEM%]\svcsysnet32.dll
[%SYSTEM%]\tintel.dll
[%SYSTEM%]\toolbar.dll
[%SYSTEM%]\update.txt
[%SYSTEM%]\Vbshell.tlb
[%SYSTEM%]\version.txt
[%SYSTEM%]\vrdown.dll
[%SYSTEM%]\vrunzip.dll
[%SYSTEM%]\vviewer.ocx
[%SYSTEM%]\WinATS.dll
[%WINDOWS%]\amm06.ocx
[%WINDOWS%]\Bernadette.dll
[%WINDOWS%]\CBBasis.xml
[%WINDOWS%]\CBVersion.txt
[%WINDOWS%]\cpbrkpie.ocx
[%WINDOWS%]\Downloaded Program Files\ActiveSecurity.ocx
[%WINDOWS%]\Downloaded Program Files\actsetup.dll
[%WINDOWS%]\Downloaded Program Files\AktiveSekurity.ocx
[%WINDOWS%]\Downloaded Program Files\amm06.ocx
[%WINDOWS%]\Downloaded Program Files\AXDownloader.dll
[%WINDOWS%]\Downloaded Program Files\ax_mjpeg.ocx
[%WINDOWS%]\Downloaded Program Files\Bol Downloader.ocx
[%WINDOWS%]\Downloaded Program Files\BrowserAccelerator.dll
[%WINDOWS%]\downloaded program files\clientax.dll
[%WINDOWS%]\Downloaded Program Files\comload.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.10\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.10\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.11\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.12\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.12\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.14\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.14\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.15\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.15\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.17\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.18\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.18\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.19\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\dlhelper.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\d_loader.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\ftm_en-us.xml
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\ftm_LanguageList.xml
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\grTransferCtrl.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\HDPlugin1101.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\Install.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\IWCHECK.DLL
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\MSJavX86.exe,DanaInfo=PRT-ST01.kp.org,CT=java+
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\popcaploader.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\RdxIE.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\rnd_soft.php
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\securelogin.ocx
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\TransferMgr.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UDC6_0001_D19M2808NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UDC6_0001_D21M0303NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UPRP_0001_D21M2103NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\USDR6V_0001_D18M3107NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UWAS6_0001_N68M2301NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UWAS6_0001_N69M0703NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\xpreload.ocx
[%WINDOWS%]\Downloaded Program Files\CONFLICT.20\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.21\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.22\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.24\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.25\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.26\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.27\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.28\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.29\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.2\MSJavX86.exe,DanaInfo=PRT-ST01.kp.org,CT=java+
[%WINDOWS%]\Downloaded Program Files\CONFLICT.2\RdxIE.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.2\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.2\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.2\USDR6_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.3\MSJavX86.exe,DanaInfo=PRT-ST01.kp.org,CT=java+
[%WINDOWS%]\Downloaded Program Files\CONFLICT.3\popcaploader.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.3\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.3\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.4\popcaploader.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.4\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.4\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.4\UDC6_0001_D19M2808NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.4\USDR6_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.5\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.5\USDR6_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.6\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.6\USDR6_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.7\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.8\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.8\USDR6_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.9\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\downloaded program files\cpnmgr.dll
[%WINDOWS%]\Downloaded Program Files\cscmv4x.dll
[%WINDOWS%]\Downloaded Program Files\csetup.dll
[%WINDOWS%]\Downloaded Program Files\Customtoolbar.exe
[%WINDOWS%]\Downloaded Program Files\Dhsigned.ocx
[%WINDOWS%]\Downloaded Program Files\dialxs.ocx
[%WINDOWS%]\Downloaded Program Files\dlhelper.dll
[%WINDOWS%]\Downloaded Program Files\downloader.ocx
[%WINDOWS%]\Downloaded Program Files\dwnldr.dll
[%WINDOWS%]\Downloaded Program Files\ffav.dll
[%WINDOWS%]\Downloaded Program Files\ForbesDownloader.ocx
[%WINDOWS%]\Downloaded Program Files\ftm_en-us.xml
[%WINDOWS%]\Downloaded Program Files\ftm_LanguageList.xml
[%WINDOWS%]\Downloaded Program Files\gdownloader.ocx
[%WINDOWS%]\Downloaded Program Files\gigexagent.dll
[%WINDOWS%]\Downloaded Program Files\grTransferCtrl.dll
[%WINDOWS%]\Downloaded Program Files\grTransferMgr.dll
[%WINDOWS%]\Downloaded Program Files\HbInstIE.dll
[%WINDOWS%]\Downloaded Program Files\HWAudio.dll
[%WINDOWS%]\Downloaded Program Files\HWReal.exe
[%WINDOWS%]\Downloaded Program Files\HWUtils.dll
[%WINDOWS%]\Downloaded Program Files\Install.dll
[%WINDOWS%]\Downloaded Program Files\internazionale_ver4.ocx
[%WINDOWS%]\Downloaded Program Files\int_ver32b.ocx
[%WINDOWS%]\Downloaded Program Files\int_ver34.ocx
[%WINDOWS%]\Downloaded Program Files\ISTactivex.dll
[%WINDOWS%]\Downloaded Program Files\IWCHECK.DLL
[%WINDOWS%]\Downloaded Program Files\MaConnect.dll
[%WINDOWS%]\Downloaded Program Files\MailAlertUpgrade_MAIL.exe
[%WINDOWS%]\Downloaded Program Files\mail_mcea115.exe
[%WINDOWS%]\Downloaded Program Files\MediaGatewayX.dll
[%WINDOWS%]\Downloaded Program Files\MiniBugTransporter.dll
[%WINDOWS%]\Downloaded Program Files\miniclipGameLoader.dll
[%WINDOWS%]\Downloaded Program Files\MSJavX86.exe,DanaInfo=PRT-ST01.kp.org,CT=java+
[%WINDOWS%]\Downloaded Program Files\npkxsite.ocx
[%WINDOWS%]\Downloaded Program Files\npx.ocx
[%WINDOWS%]\Downloaded Program Files\OTXMedia.dll
[%WINDOWS%]\Downloaded Program Files\popcaploader.dll
[%WINDOWS%]\Downloaded Program Files\PopupSh.ocx
[%WINDOWS%]\Downloaded Program Files\RdxIE.dll
[%WINDOWS%]\Downloaded Program Files\rnd_soft.php
[%WINDOWS%]\Downloaded Program Files\SAIX.dll
[%WINDOWS%]\Downloaded Program Files\securelogin.ocx
[%WINDOWS%]\Downloaded Program Files\setup.exe
[%WINDOWS%]\Downloaded Program Files\setup_mcnear_online.EXE
[%WINDOWS%]\Downloaded Program Files\SSCHECK.DLL
[%WINDOWS%]\Downloaded Program Files\SSP.ocx
[%WINDOWS%]\Downloaded Program Files\TAMUScanLauncher.EXE
[%WINDOWS%]\Downloaded Program Files\Toolbar_cobrand.EXE
[%WINDOWS%]\Downloaded Program Files\TransferMgr.exe
[%WINDOWS%]\Downloaded Program Files\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6M_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6V_0001_D19M1009NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6Y_0001_D13M0707NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6Y_0001_D19M0809NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6_0001_D19M2808NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6_0001_D21M0303NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6_0001_D21M1601NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6_0001_D22M1709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6_4444_D21M0303NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UERS_9999_N91S2507NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UERT_0001_D18M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UERT_0001_D19M2109NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UniDist.ocx
[%WINDOWS%]\Downloaded Program Files\UPRP_0001_D21M1501NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UPRP_0001_D21M2103NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6T_0001_D18M3107NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6T_0001_N19M1105NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6V_0001_D18M3107NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6V_0001_N19M2604NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6Y_0001_D13M1007NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6Y_0001_D18M1608NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6Y_0001_D18M3107NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6_0001_D08M0404NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6_7777_BHLP0611NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6_9999_N18M1603NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UWA6PY_0001_N91M2107NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UWA7P_0001_N91M0809NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UWAS7_0001_N99M3108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\videox.dll
[%WINDOWS%]\Downloaded Program Files\VLoading.dll
[%WINDOWS%]\Downloaded Program Files\WebP2PInstaller.dll
[%WINDOWS%]\Downloaded Program Files\WebP2PInstaller2.dll
[%WINDOWS%]\Downloaded Program Files\website.dll
[%WINDOWS%]\Downloaded Program Files\xpreload.ocx
[%WINDOWS%]\Downloaded Program Files\ysbactivex.dll
[%WINDOWS%]\eg_auth_1045.dll
[%WINDOWS%]\eg_auth_1046.dll
[%WINDOWS%]\Iseult.dll
[%WINDOWS%]\mdkiaf.exe
[%WINDOWS%]\MediaConnect.ocx
[%WINDOWS%]\minigolf_affiliate.exe

How to detect ActiveX Malware:

Files:
[%PROGRAM_FILES%]\AWS\WeatherBug\MiniBugTransporter.dll
[%PROGRAM_FILES%]\Microsoft File Transfer Manager\ftm_en-us.xml
[%PROGRAM_FILES%]\Microsoft File Transfer Manager\ftm_LanguageList.xml
[%PROGRAM_FILES%]\Microsoft File Transfer Manager\grTransferCtrl.dll
[%PROGRAM_FILES%]\Microsoft File Transfer Manager\grTransferMgr.dll
[%PROGRAM_FILES%]\Microsoft File Transfer Manager\TransferMgr.exe
[%SYSTEM%]\adwerkz.dll
[%SYSTEM%]\asycfilt.dll
[%SYSTEM%]\AxConfig.dll
[%SYSTEM%]\back.gif
[%SYSTEM%]\brix6ie.ocx
[%SYSTEM%]\BSTIEPrintCtl1.dll
[%SYSTEM%]\comcat.dll
[%SYSTEM%]\dialer_activex.ocx
[%SYSTEM%]\egaccess4_1058.dll
[%SYSTEM%]\egaccess4_1060.dll
[%SYSTEM%]\egaccess4_1063.dll
[%SYSTEM%]\egaccess4_1064.dll
[%SYSTEM%]\EGCOMSERVICE2.dll
[%SYSTEM%]\EGCOMSERVICE_1045.dll
[%SYSTEM%]\eglivecam_1027.dll
[%SYSTEM%]\hyundai_key.bmp
[%SYSTEM%]\ieaccess2.dll
[%SYSTEM%]\INICRYPTOSDK.dll
[%SYSTEM%]\ksfc_key.bmp
[%SYSTEM%]\lgcard_key.bmp
[%SYSTEM%]\LiveService_4.dll
[%SYSTEM%]\mfc42.dll
[%SYSTEM%]\Msinet.ocx
[%SYSTEM%]\msstkprp.dll
[%SYSTEM%]\msvbvm60.dll
[%SYSTEM%]\msvcrt.dll
[%SYSTEM%]\npcopyv.exe
[%SYSTEM%]\npdown.dll
[%SYSTEM%]\npdownv.exe
[%SYSTEM%]\npdown_.dll
[%SYSTEM%]\npkagt.exe
[%SYSTEM%]\npkcnt4.sys
[%SYSTEM%]\npkcrypt.dll
[%SYSTEM%]\npkcrypt.sys
[%SYSTEM%]\npkcrypt.vxd
[%SYSTEM%]\npkcsvc.exe
[%SYSTEM%]\npkcusb.sys
[%SYSTEM%]\npkcx.ocx
[%SYSTEM%]\npkeyc.sys
[%SYSTEM%]\npkeycs.sys
[%SYSTEM%]\npkeysdk.dll
[%SYSTEM%]\npkpdb.dll
[%SYSTEM%]\npkSvcUpdate.exe
[%SYSTEM%]\npkuninst.exe
[%SYSTEM%]\npnv3uninst.exe
[%SYSTEM%]\npx.ocx
[%SYSTEM%]\np_chs.ini
[%SYSTEM%]\np_eng.ini
[%SYSTEM%]\np_jpn.ini
[%SYSTEM%]\np_kor.ini
[%SYSTEM%]\ObjSafe.tlb
[%SYSTEM%]\oleaut32.dll
[%SYSTEM%]\olepro32.dll
[%SYSTEM%]\P2ECOM.dll
[%SYSTEM%]\psapi.dll
[%SYSTEM%]\regobj.dll
[%SYSTEM%]\RSAG726D.dll
[%SYSTEM%]\RSAG726E.dll
[%SYSTEM%]\safe.tlb
[%SYSTEM%]\stdole2.tlb
[%SYSTEM%]\svcsysnet32.dll
[%SYSTEM%]\tintel.dll
[%SYSTEM%]\toolbar.dll
[%SYSTEM%]\update.txt
[%SYSTEM%]\Vbshell.tlb
[%SYSTEM%]\version.txt
[%SYSTEM%]\vrdown.dll
[%SYSTEM%]\vrunzip.dll
[%SYSTEM%]\vviewer.ocx
[%SYSTEM%]\WinATS.dll
[%WINDOWS%]\amm06.ocx
[%WINDOWS%]\Bernadette.dll
[%WINDOWS%]\CBBasis.xml
[%WINDOWS%]\CBVersion.txt
[%WINDOWS%]\cpbrkpie.ocx
[%WINDOWS%]\Downloaded Program Files\ActiveSecurity.ocx
[%WINDOWS%]\Downloaded Program Files\actsetup.dll
[%WINDOWS%]\Downloaded Program Files\AktiveSekurity.ocx
[%WINDOWS%]\Downloaded Program Files\amm06.ocx
[%WINDOWS%]\Downloaded Program Files\AXDownloader.dll
[%WINDOWS%]\Downloaded Program Files\ax_mjpeg.ocx
[%WINDOWS%]\Downloaded Program Files\Bol Downloader.ocx
[%WINDOWS%]\Downloaded Program Files\BrowserAccelerator.dll
[%WINDOWS%]\downloaded program files\clientax.dll
[%WINDOWS%]\Downloaded Program Files\comload.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.10\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.10\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.11\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.12\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.12\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.14\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.14\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.15\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.15\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.17\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.18\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.18\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.19\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\dlhelper.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\d_loader.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\ftm_en-us.xml
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\ftm_LanguageList.xml
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\grTransferCtrl.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\HDPlugin1101.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\Install.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\IWCHECK.DLL
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\MSJavX86.exe,DanaInfo=PRT-ST01.kp.org,CT=java+
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\popcaploader.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\RdxIE.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\rnd_soft.php
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\securelogin.ocx
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\TransferMgr.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UDC6_0001_D19M2808NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UDC6_0001_D21M0303NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UPRP_0001_D21M2103NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\USDR6V_0001_D18M3107NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UWAS6_0001_N68M2301NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UWAS6_0001_N69M0703NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\xpreload.ocx
[%WINDOWS%]\Downloaded Program Files\CONFLICT.20\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.21\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.22\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.24\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.25\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.26\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.27\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.28\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.29\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.2\MSJavX86.exe,DanaInfo=PRT-ST01.kp.org,CT=java+
[%WINDOWS%]\Downloaded Program Files\CONFLICT.2\RdxIE.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.2\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.2\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.2\USDR6_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.3\MSJavX86.exe,DanaInfo=PRT-ST01.kp.org,CT=java+
[%WINDOWS%]\Downloaded Program Files\CONFLICT.3\popcaploader.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.3\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.3\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.4\popcaploader.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.4\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.4\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.4\UDC6_0001_D19M2808NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.4\USDR6_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.5\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.5\USDR6_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.6\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.6\USDR6_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.7\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.8\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.8\USDR6_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.9\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\downloaded program files\cpnmgr.dll
[%WINDOWS%]\Downloaded Program Files\cscmv4x.dll
[%WINDOWS%]\Downloaded Program Files\csetup.dll
[%WINDOWS%]\Downloaded Program Files\Customtoolbar.exe
[%WINDOWS%]\Downloaded Program Files\Dhsigned.ocx
[%WINDOWS%]\Downloaded Program Files\dialxs.ocx
[%WINDOWS%]\Downloaded Program Files\dlhelper.dll
[%WINDOWS%]\Downloaded Program Files\downloader.ocx
[%WINDOWS%]\Downloaded Program Files\dwnldr.dll
[%WINDOWS%]\Downloaded Program Files\ffav.dll
[%WINDOWS%]\Downloaded Program Files\ForbesDownloader.ocx
[%WINDOWS%]\Downloaded Program Files\ftm_en-us.xml
[%WINDOWS%]\Downloaded Program Files\ftm_LanguageList.xml
[%WINDOWS%]\Downloaded Program Files\gdownloader.ocx
[%WINDOWS%]\Downloaded Program Files\gigexagent.dll
[%WINDOWS%]\Downloaded Program Files\grTransferCtrl.dll
[%WINDOWS%]\Downloaded Program Files\grTransferMgr.dll
[%WINDOWS%]\Downloaded Program Files\HbInstIE.dll
[%WINDOWS%]\Downloaded Program Files\HWAudio.dll
[%WINDOWS%]\Downloaded Program Files\HWReal.exe
[%WINDOWS%]\Downloaded Program Files\HWUtils.dll
[%WINDOWS%]\Downloaded Program Files\Install.dll
[%WINDOWS%]\Downloaded Program Files\internazionale_ver4.ocx
[%WINDOWS%]\Downloaded Program Files\int_ver32b.ocx
[%WINDOWS%]\Downloaded Program Files\int_ver34.ocx
[%WINDOWS%]\Downloaded Program Files\ISTactivex.dll
[%WINDOWS%]\Downloaded Program Files\IWCHECK.DLL
[%WINDOWS%]\Downloaded Program Files\MaConnect.dll
[%WINDOWS%]\Downloaded Program Files\MailAlertUpgrade_MAIL.exe
[%WINDOWS%]\Downloaded Program Files\mail_mcea115.exe
[%WINDOWS%]\Downloaded Program Files\MediaGatewayX.dll
[%WINDOWS%]\Downloaded Program Files\MiniBugTransporter.dll
[%WINDOWS%]\Downloaded Program Files\miniclipGameLoader.dll
[%WINDOWS%]\Downloaded Program Files\MSJavX86.exe,DanaInfo=PRT-ST01.kp.org,CT=java+
[%WINDOWS%]\Downloaded Program Files\npkxsite.ocx
[%WINDOWS%]\Downloaded Program Files\npx.ocx
[%WINDOWS%]\Downloaded Program Files\OTXMedia.dll
[%WINDOWS%]\Downloaded Program Files\popcaploader.dll
[%WINDOWS%]\Downloaded Program Files\PopupSh.ocx
[%WINDOWS%]\Downloaded Program Files\RdxIE.dll
[%WINDOWS%]\Downloaded Program Files\rnd_soft.php
[%WINDOWS%]\Downloaded Program Files\SAIX.dll
[%WINDOWS%]\Downloaded Program Files\securelogin.ocx
[%WINDOWS%]\Downloaded Program Files\setup.exe
[%WINDOWS%]\Downloaded Program Files\setup_mcnear_online.EXE
[%WINDOWS%]\Downloaded Program Files\SSCHECK.DLL
[%WINDOWS%]\Downloaded Program Files\SSP.ocx
[%WINDOWS%]\Downloaded Program Files\TAMUScanLauncher.EXE
[%WINDOWS%]\Downloaded Program Files\Toolbar_cobrand.EXE
[%WINDOWS%]\Downloaded Program Files\TransferMgr.exe
[%WINDOWS%]\Downloaded Program Files\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6M_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6V_0001_D19M1009NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6Y_0001_D13M0707NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6Y_0001_D19M0809NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6_0001_D19M2808NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6_0001_D21M0303NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6_0001_D21M1601NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6_0001_D22M1709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6_4444_D21M0303NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UERS_9999_N91S2507NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UERT_0001_D18M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UERT_0001_D19M2109NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UniDist.ocx
[%WINDOWS%]\Downloaded Program Files\UPRP_0001_D21M1501NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UPRP_0001_D21M2103NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6T_0001_D18M3107NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6T_0001_N19M1105NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6V_0001_D18M3107NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6V_0001_N19M2604NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6Y_0001_D13M1007NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6Y_0001_D18M1608NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6Y_0001_D18M3107NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6_0001_D08M0404NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6_7777_BHLP0611NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6_9999_N18M1603NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UWA6PY_0001_N91M2107NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UWA7P_0001_N91M0809NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UWAS7_0001_N99M3108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\videox.dll
[%WINDOWS%]\Downloaded Program Files\VLoading.dll
[%WINDOWS%]\Downloaded Program Files\WebP2PInstaller.dll
[%WINDOWS%]\Downloaded Program Files\WebP2PInstaller2.dll
[%WINDOWS%]\Downloaded Program Files\website.dll
[%WINDOWS%]\Downloaded Program Files\xpreload.ocx
[%WINDOWS%]\Downloaded Program Files\ysbactivex.dll
[%WINDOWS%]\eg_auth_1045.dll
[%WINDOWS%]\eg_auth_1046.dll
[%WINDOWS%]\Iseult.dll
[%WINDOWS%]\mdkiaf.exe
[%WINDOWS%]\MediaConnect.ocx
[%WINDOWS%]\minigolf_affiliate.exe
[%PROGRAM_FILES%]\AWS\WeatherBug\MiniBugTransporter.dll
[%PROGRAM_FILES%]\Microsoft File Transfer Manager\ftm_en-us.xml
[%PROGRAM_FILES%]\Microsoft File Transfer Manager\ftm_LanguageList.xml
[%PROGRAM_FILES%]\Microsoft File Transfer Manager\grTransferCtrl.dll
[%PROGRAM_FILES%]\Microsoft File Transfer Manager\grTransferMgr.dll
[%PROGRAM_FILES%]\Microsoft File Transfer Manager\TransferMgr.exe
[%SYSTEM%]\adwerkz.dll
[%SYSTEM%]\asycfilt.dll
[%SYSTEM%]\AxConfig.dll
[%SYSTEM%]\back.gif
[%SYSTEM%]\brix6ie.ocx
[%SYSTEM%]\BSTIEPrintCtl1.dll
[%SYSTEM%]\comcat.dll
[%SYSTEM%]\dialer_activex.ocx
[%SYSTEM%]\egaccess4_1058.dll
[%SYSTEM%]\egaccess4_1060.dll
[%SYSTEM%]\egaccess4_1063.dll
[%SYSTEM%]\egaccess4_1064.dll
[%SYSTEM%]\EGCOMSERVICE2.dll
[%SYSTEM%]\EGCOMSERVICE_1045.dll
[%SYSTEM%]\eglivecam_1027.dll
[%SYSTEM%]\hyundai_key.bmp
[%SYSTEM%]\ieaccess2.dll
[%SYSTEM%]\INICRYPTOSDK.dll
[%SYSTEM%]\ksfc_key.bmp
[%SYSTEM%]\lgcard_key.bmp
[%SYSTEM%]\LiveService_4.dll
[%SYSTEM%]\mfc42.dll
[%SYSTEM%]\Msinet.ocx
[%SYSTEM%]\msstkprp.dll
[%SYSTEM%]\msvbvm60.dll
[%SYSTEM%]\msvcrt.dll
[%SYSTEM%]\npcopyv.exe
[%SYSTEM%]\npdown.dll
[%SYSTEM%]\npdownv.exe
[%SYSTEM%]\npdown_.dll
[%SYSTEM%]\npkagt.exe
[%SYSTEM%]\npkcnt4.sys
[%SYSTEM%]\npkcrypt.dll
[%SYSTEM%]\npkcrypt.sys
[%SYSTEM%]\npkcrypt.vxd
[%SYSTEM%]\npkcsvc.exe
[%SYSTEM%]\npkcusb.sys
[%SYSTEM%]\npkcx.ocx
[%SYSTEM%]\npkeyc.sys
[%SYSTEM%]\npkeycs.sys
[%SYSTEM%]\npkeysdk.dll
[%SYSTEM%]\npkpdb.dll
[%SYSTEM%]\npkSvcUpdate.exe
[%SYSTEM%]\npkuninst.exe
[%SYSTEM%]\npnv3uninst.exe
[%SYSTEM%]\npx.ocx
[%SYSTEM%]\np_chs.ini
[%SYSTEM%]\np_eng.ini
[%SYSTEM%]\np_jpn.ini
[%SYSTEM%]\np_kor.ini
[%SYSTEM%]\ObjSafe.tlb
[%SYSTEM%]\oleaut32.dll
[%SYSTEM%]\olepro32.dll
[%SYSTEM%]\P2ECOM.dll
[%SYSTEM%]\psapi.dll
[%SYSTEM%]\regobj.dll
[%SYSTEM%]\RSAG726D.dll
[%SYSTEM%]\RSAG726E.dll
[%SYSTEM%]\safe.tlb
[%SYSTEM%]\stdole2.tlb
[%SYSTEM%]\svcsysnet32.dll
[%SYSTEM%]\tintel.dll
[%SYSTEM%]\toolbar.dll
[%SYSTEM%]\update.txt
[%SYSTEM%]\Vbshell.tlb
[%SYSTEM%]\version.txt
[%SYSTEM%]\vrdown.dll
[%SYSTEM%]\vrunzip.dll
[%SYSTEM%]\vviewer.ocx
[%SYSTEM%]\WinATS.dll
[%WINDOWS%]\amm06.ocx
[%WINDOWS%]\Bernadette.dll
[%WINDOWS%]\CBBasis.xml
[%WINDOWS%]\CBVersion.txt
[%WINDOWS%]\cpbrkpie.ocx
[%WINDOWS%]\Downloaded Program Files\ActiveSecurity.ocx
[%WINDOWS%]\Downloaded Program Files\actsetup.dll
[%WINDOWS%]\Downloaded Program Files\AktiveSekurity.ocx
[%WINDOWS%]\Downloaded Program Files\amm06.ocx
[%WINDOWS%]\Downloaded Program Files\AXDownloader.dll
[%WINDOWS%]\Downloaded Program Files\ax_mjpeg.ocx
[%WINDOWS%]\Downloaded Program Files\Bol Downloader.ocx
[%WINDOWS%]\Downloaded Program Files\BrowserAccelerator.dll
[%WINDOWS%]\downloaded program files\clientax.dll
[%WINDOWS%]\Downloaded Program Files\comload.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.10\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.10\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.11\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.12\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.12\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.14\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.14\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.15\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.15\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.17\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.18\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.18\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.19\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\dlhelper.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\d_loader.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\ftm_en-us.xml
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\ftm_LanguageList.xml
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\grTransferCtrl.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\HDPlugin1101.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\Install.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\IWCHECK.DLL
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\MSJavX86.exe,DanaInfo=PRT-ST01.kp.org,CT=java+
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\popcaploader.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\RdxIE.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\rnd_soft.php
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\securelogin.ocx
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\TransferMgr.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UDC6_0001_D19M2808NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UDC6_0001_D21M0303NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UPRP_0001_D21M2103NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\USDR6V_0001_D18M3107NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UWAS6_0001_N68M2301NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\UWAS6_0001_N69M0703NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.1\xpreload.ocx
[%WINDOWS%]\Downloaded Program Files\CONFLICT.20\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.21\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.22\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.24\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.25\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.26\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.27\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.28\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.29\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.2\MSJavX86.exe,DanaInfo=PRT-ST01.kp.org,CT=java+
[%WINDOWS%]\Downloaded Program Files\CONFLICT.2\RdxIE.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.2\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.2\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.2\USDR6_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.3\MSJavX86.exe,DanaInfo=PRT-ST01.kp.org,CT=java+
[%WINDOWS%]\Downloaded Program Files\CONFLICT.3\popcaploader.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.3\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.3\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.4\popcaploader.dll
[%WINDOWS%]\Downloaded Program Files\CONFLICT.4\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.4\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.4\UDC6_0001_D19M2808NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.4\USDR6_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.5\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.5\USDR6_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.6\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.6\USDR6_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.7\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.8\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.8\USDR6_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\CONFLICT.9\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\downloaded program files\cpnmgr.dll
[%WINDOWS%]\Downloaded Program Files\cscmv4x.dll
[%WINDOWS%]\Downloaded Program Files\csetup.dll
[%WINDOWS%]\Downloaded Program Files\Customtoolbar.exe
[%WINDOWS%]\Downloaded Program Files\Dhsigned.ocx
[%WINDOWS%]\Downloaded Program Files\dialxs.ocx
[%WINDOWS%]\Downloaded Program Files\dlhelper.dll
[%WINDOWS%]\Downloaded Program Files\downloader.ocx
[%WINDOWS%]\Downloaded Program Files\dwnldr.dll
[%WINDOWS%]\Downloaded Program Files\ffav.dll
[%WINDOWS%]\Downloaded Program Files\ForbesDownloader.ocx
[%WINDOWS%]\Downloaded Program Files\ftm_en-us.xml
[%WINDOWS%]\Downloaded Program Files\ftm_LanguageList.xml
[%WINDOWS%]\Downloaded Program Files\gdownloader.ocx
[%WINDOWS%]\Downloaded Program Files\gigexagent.dll
[%WINDOWS%]\Downloaded Program Files\grTransferCtrl.dll
[%WINDOWS%]\Downloaded Program Files\grTransferMgr.dll
[%WINDOWS%]\Downloaded Program Files\HbInstIE.dll
[%WINDOWS%]\Downloaded Program Files\HWAudio.dll
[%WINDOWS%]\Downloaded Program Files\HWReal.exe
[%WINDOWS%]\Downloaded Program Files\HWUtils.dll
[%WINDOWS%]\Downloaded Program Files\Install.dll
[%WINDOWS%]\Downloaded Program Files\internazionale_ver4.ocx
[%WINDOWS%]\Downloaded Program Files\int_ver32b.ocx
[%WINDOWS%]\Downloaded Program Files\int_ver34.ocx
[%WINDOWS%]\Downloaded Program Files\ISTactivex.dll
[%WINDOWS%]\Downloaded Program Files\IWCHECK.DLL
[%WINDOWS%]\Downloaded Program Files\MaConnect.dll
[%WINDOWS%]\Downloaded Program Files\MailAlertUpgrade_MAIL.exe
[%WINDOWS%]\Downloaded Program Files\mail_mcea115.exe
[%WINDOWS%]\Downloaded Program Files\MediaGatewayX.dll
[%WINDOWS%]\Downloaded Program Files\MiniBugTransporter.dll
[%WINDOWS%]\Downloaded Program Files\miniclipGameLoader.dll
[%WINDOWS%]\Downloaded Program Files\MSJavX86.exe,DanaInfo=PRT-ST01.kp.org,CT=java+
[%WINDOWS%]\Downloaded Program Files\npkxsite.ocx
[%WINDOWS%]\Downloaded Program Files\npx.ocx
[%WINDOWS%]\Downloaded Program Files\OTXMedia.dll
[%WINDOWS%]\Downloaded Program Files\popcaploader.dll
[%WINDOWS%]\Downloaded Program Files\PopupSh.ocx
[%WINDOWS%]\Downloaded Program Files\RdxIE.dll
[%WINDOWS%]\Downloaded Program Files\rnd_soft.php
[%WINDOWS%]\Downloaded Program Files\SAIX.dll
[%WINDOWS%]\Downloaded Program Files\securelogin.ocx
[%WINDOWS%]\Downloaded Program Files\setup.exe
[%WINDOWS%]\Downloaded Program Files\setup_mcnear_online.EXE
[%WINDOWS%]\Downloaded Program Files\SSCHECK.DLL
[%WINDOWS%]\Downloaded Program Files\SSP.ocx
[%WINDOWS%]\Downloaded Program Files\TAMUScanLauncher.EXE
[%WINDOWS%]\Downloaded Program Files\Toolbar_cobrand.EXE
[%WINDOWS%]\Downloaded Program Files\TransferMgr.exe
[%WINDOWS%]\Downloaded Program Files\UDC6M_0001_D19M0709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6M_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6V_0001_D19M1009NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6Y_0001_D13M0707NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6Y_0001_D19M0809NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6_0001_D19M1908NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6_0001_D19M2808NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6_0001_D21M0303NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6_0001_D21M1601NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6_0001_D22M1709NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UDC6_4444_D21M0303NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UERS_9999_N91S2507NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UERT_0001_D18M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UERT_0001_D19M2109NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UniDist.ocx
[%WINDOWS%]\Downloaded Program Files\UPRP_0001_D21M1501NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UPRP_0001_D21M2103NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6T_0001_D18M3107NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6T_0001_N19M1105NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6V_0001_D18M3107NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6V_0001_N19M2604NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6Y_0001_D13M1007NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6Y_0001_D18M1608NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6Y_0001_D18M3107NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6_0001_D08M0404NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6_0001_D19M2108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6_7777_BHLP0611NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\USDR6_9999_N18M1603NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UWA6PY_0001_N91M2107NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UWA7P_0001_N91M0809NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\UWAS7_0001_N99M3108NetInstaller.exe
[%WINDOWS%]\Downloaded Program Files\videox.dll
[%WINDOWS%]\Downloaded Program Files\VLoading.dll
[%WINDOWS%]\Downloaded Program Files\WebP2PInstaller.dll
[%WINDOWS%]\Downloaded Program Files\WebP2PInstaller2.dll
[%WINDOWS%]\Downloaded Program Files\website.dll
[%WINDOWS%]\Downloaded Program Files\xpreload.ocx
[%WINDOWS%]\Downloaded Program Files\ysbactivex.dll
[%WINDOWS%]\eg_auth_1045.dll
[%WINDOWS%]\eg_auth_1046.dll
[%WINDOWS%]\Iseult.dll
[%WINDOWS%]\mdkiaf.exe
[%WINDOWS%]\MediaConnect.ocx
[%WINDOWS%]\minigolf_affiliate.exe

Registry Keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{00000000-0000-0000-0000-000020030000}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{00000000-0000-0000-0000-000020040000}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{00000000-0000-0000-0000-100000000003}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{00000000-0000-0000-0000-100005000004}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{00000005-0000-0000-0000-100005000004}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{00000EF1-0786-4633-87C6-1AA7A44296DA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{018B7EC3-EECA-11D3-8E71-0000E82C6C0D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{01BE5BD7-B2DD-48B3-A759-59265A91E787}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{02C20140-76F8-4763-83D5-B660107B7A90}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{037B3D58-D14A-4C41-BDFD-BD779B0B97BA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{03C543A1-C090-418F-A1D0-FB96380D601D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{03F998B2-0E00-11D3-A498-00104B6EB52E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{04CCFF26-7D52-4E42-BF6A-F8ECE0896EB7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{04F414E9-E352-4BC3-963D-7BFE5A5F31A9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0594AF7E-573B-40DF-8165-E47AB2EAEFE8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{05CE4481-8015-11D3-9811-C4DA9F000000}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0733B8F9-8B52-4693-A9FA-829E12D27F78}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{07637823-C894-4A52-B3F9-5D777FD8E36A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{07C9CFC7-DE33-4A0C-9FFB-CDFBA843B157}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0837121A-6472-43BD-8A40-D9221FF1C4CE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{084F552D-19EB-4668-9788-984CBC781A8F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0873478E-E67A-4876-B0A9-9A36D3AB3602}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0878B424-1F95-4E26-B5AB-F0D349D89650}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0878F049-D33E-45E0-A157-C36A6683CF25}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{093F9CF8-0DE1-491C-95D5-5EC257BD4CA3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{09F1ADAC-76D8-4D0F-99A5-5C907DADB988}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0AB5CBCF-6984-4122-BCF7-BE33BF5B1CF1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0B682CC1-FB40-4006-A5DD-99EDD3C9095D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0D1011B3-89C8-4F8E-8693-BB970E2E81E0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0D62A517-E7C6-4E1F-A577-07D4AC549A48}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0DA910BC-6919-489E-B584-D9A4AAC7B8DE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0E4796D6-A990-4372-9069-72FBDB4AE868}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0F9B4CA4-A30F-480A-841D-69B45C50A8F8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{0FFFFFFF-0FFF-0FFF-0FFF-0FFFFFFFFFFF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{10000000-1000-0000-0000-000000000000}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{10000000-1000-0000-1000-000000000000}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1000026A-8230-4DD4-BE4F-6889D1E74167}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{10003000-1000-0000-1000-000000000000}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{10A1B95D-5E35-4935-8BC3-D43E81E8105E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{11010101-1001-1111-1000-110263637096}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{11111111-1111-1111-1111-111111111111}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{11111111-1111-1111-1111-111111111732}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{11111111-1111-1111-1111-111111113456}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{11111111-1111-1111-1111-111111113457}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{11111111-1111-1111-1111-111191113457}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{11111111-1111-1111-1111-511111113457}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{11111111-1111-1111-1111-511111113458}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{11111111-1111-1111-1111-511111193457}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{11111111-1111-1111-1111-511111193458}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{11BF0E2B-4229-4ADC-9C11-1C6968731018}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1230CB21-C88D-11CF-B347-000000000000}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{12345678-1234-1234-1234-123456789123}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{12398DD6-40AA-4C40-A4EC-A42CFC0DE797}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{12589FA1-C456-11CE-BF01-10AA1055595A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{12E5E9D9-4366-45D9-BA41-D0BCD55AD8CF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{14A3221B-1678-1982-A355-7263B1281987}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{15589FA1-C456-11CE-BF01-00AA0055595A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{15C3C7A4-9676-11D3-9799-0060087190B9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1604DF98-D1A5-44FE-844A-98D6FD0518D0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1678F7E1-C422-11D0-AD7D-00400515CAAA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{17BFC8DA-B4D6-4DB9-AA40-1CD32EDA9845}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1954A4B1-9627-4CF2-A041-58AA2045CB35}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{197AB1D7-A7DD-4C86-A938-1FCC0DB21B85}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1C78AB3F-A857-482E-80C0-3A1E5238A565}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1C955F3B-5B32-4393-A05D-24B4970CD2A1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1CD49DC9-FD88-41FA-B892-47E037267D45}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D0D9077-3798-49BB-9058-393499174D5D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D2DCA0D-B30F-40AD-9690-087105F214EC}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D6711C8-7154-40BB-8380-3DEA45B69CBF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D870C86-AA3C-4451-81E4-71D480A1A652}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1E89F686-B78D-4C85-9EFC-3474516E3FE2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1EB17D1C-141D-4D9D-91CB-24D99215851D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{201D3DA8-B495-4A3B-BEE8-6D8DDCCC5762}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2048B51E-8D74-4762-82CE-B48CF545EEEA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{205FF73B-CA67-11D5-99DD-444553540000}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{205FF73B-CA67-11D5-99DD-444553540002}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{205FF73B-CA67-11D5-99DD-444553540006}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{22A88341-AFCB-45F0-A856-C2BAE74F878E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{23232323-2323-2323-2323-232323291122}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{24311111-1111-1121-1111-111191113457}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{26098EA2-C95D-48EA-89B4-63C5A63BD42F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{261EE805-4893-45A3-8E9E-AD90914CB39A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{26D73573-F1B3-48C9-A989-E6CE071957A1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{26E8361F-BCE7-4F75-A347-98C88B418322}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{26FD5192-A97C-4B48-A5D7-2420CFDCFDF2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{288C5F13-7E52-4ADA-A32E-F5BF9D125F99}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{28F00B0F-DC4E-11D3-ABEC-005004A44EEB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2A3DFC59-8A87-49A1-85D1-42903410911F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2A91CEB1-37F5-424C-997C-4C38A3677CD8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2ABE804B-4D3A-41BF-A172-304627874B45}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2AEEAC34-FD74-4142-B891-4B05C0C03C87}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2C38A62E-D257-40E8-8BB7-5624E38FEB0A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2D6A91CF-37C6-4EB2-A8D8-F65F1DB14ECE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2E4A92AB-F2C0-456A-9935-B715439790D7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2F5B39C5-C6F5-447A-A946-48B382C53985}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{30000273-8230-4DD4-BE4F-6889D1E74167}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{31DDC1FD-CEA3-4837-A6DC-87E67015ADC9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{33331111-1111-1111-1111-611111193423}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{33331111-1111-1111-1111-611111193429}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{33331111-1111-1111-1111-611111193457}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{33331111-1111-1111-1111-611111193458}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{33331111-1234-1111-1111-615111193427}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{34805D32-AD89-469E-8503-A5666AEE4333}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{359F7E49-1EA0-4671-92E9-61E32FE25C5E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{35B7E48B-9D81-4C6C-9578-5FD4F620D886}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{35F59C80-C1F2-4EEA-9981-686C7D5A9277}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{3616F4B5-F6AD-4E67-966A-C218673648A0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{386A771C-E96A-421F-8BA7-32F1B706892F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{3A7FE611-1994-4EF1-A09F-99456752289D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{3DAD912E-D2B9-4323-B7C9-7F2C5CC0C57B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{400429E4-BED4-472E-93BF-F85AB8565DFF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4129EA54-F04E-11D3-BF96-00C04F0E7BE2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{41D13E9A-BB94-402A-8502-AFA78526B63D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{41F31718-2B9D-4F76-85E2-DD11BBA99F8D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{421A63BA-4632-43E0-A942-3B4AB645BE51}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2D240-B23C-11D6-8C73-70A05DC10000}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{43331111-1111-1111-1111-611111195622}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{469C7080-8EC8-43A6-AD97-45848113743C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4AD73894-A895-4FC2-B233-299867E08753}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4C226336-4032-489F-9674-67E74225979B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4E15D681-1D20-11D4-8B72-000021DA1956}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4E7BD74F-2B8D-469E-DEFA-EB76B1D5FA7D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4EE301F2-2A6A-4BE0-9FBD-97CDAA40E3E4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{4FA3D392-9349-4D85-8FB9-18733534CFE3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{505098FD-5D61-4BC2-9B82-F969D0E932A2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{50AD557E-3426-41FD-AFDD-2AF39BB1C387}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{50BD5CDA-4BA8-4048-8FAA-763F222E41D8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{532217E3-860C-4EEE-8BBD-3F342DCD9AE9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{549F957E-2F89-11D6-8CFE-00C04F52B225}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{54C75FB0-6B8B-4278-BF7B-77036F15A69E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{5526B4C6-63D6-41A1-9783-0FABF529859A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{556DDE35-E955-11D0-A707-000000521958}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{56336BCB-3D8A-11D6-A00B-0050DA18DE71}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{5C3A9EA6-4068-46B8-8B5A-692FB10607B1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{5C7F15E1-F31A-44FD-AA1A-2EC63AAFFD3A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{5E8FD788-C323-4357-AB76-7CBCEFBA573C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{5E92F538-B50B-46C5-9C5F-C6EECED3F6C6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{5F3B3060-09E0-44C6-86F7-BC7B02B57BEE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{5F4D3335-3194-4167-85AE-E7325F2695EF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{5FD9726A-4977-449D-8352-25FDD8A510B5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{624321F1-0581-49D8-99BD-2E952C2DF31B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{65E7DB1D-0101-4100-BD66-C5C78C917F93}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{666DDE35-E955-11D0-A707-000000521958}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{666E4D35-E955-11D0-A707-000000521958}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{683DFF0F-331F-44D2-B69B-46D7BFB58F32}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{6986A6CF-9D58-11D6-91C2-00E02964E8E3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{6D5FCFCB-FA6C-4CFB-9918-5F0A9F7365F2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{70522FA2-4656-11D5-B0E9-0050DAC24E8F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{71CBDCD9-0830-4470-A890-35D364DA352C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{72A58725-2635-4725-8C53-676DFD1FEB8D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{731918D2-517A-47E2-886A-3BC1380C591D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{73F0FD85-BD47-4A95-86D1-DE38860462C1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{74CD40EA-EF77-4BAD-808A-B5982DA73F20}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7504F0D5-644A-4103-9D02-95488B6CB9A1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7589EEE6-E336-11D4-8A7E-EE1D971D9B47}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{75D1F3B2-2A21-11D7-97B9-0010DC2A6243}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{771A1334-6B08-4A6B-AEDC-CF994BA2CEBE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{79B96C72-C0D0-4DC8-BC7E-9F314A918228}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7AA32FC7-133B-4AE7-998E-CED0D9829B12}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7C559105-9ECF-42B8-B3F7-832E75EDD959}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7CA3D0A3-7E2E-4AAB-A75E-FAB8ECA8BD95}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7D40ADF2-AD68-4959-ACEC-DA96BF5E6EB7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7EB15626-CB8E-4174-8A72-C055B12B4310}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7EB2A76C-97AE-4CF3-9C6A-EA0F61F137E1}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{80F1B906-D066-11D3-AD70-009027B8ADBC}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{82774781-8F4E-11D1-AB1C-0000F8773BF0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{832F1D48-1D15-4E0D-8E37-4D5822C3537B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{841A9192-5690-11D4-A258-0040954A01BE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8522F9B3-38C5-4AA4-AE40-7401F1BBC851}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{85D1F3B2-2A21-11D7-97B9-0010DC2A6243}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{861FDA2A-2B57-4BDA-8B8B-305C9D5D8604}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{869518C3-FBA5-4D75-8A14-7047437E9498}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{86EEF11E-FF16-48CE-B1A2-474B663041A9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{87067F04-DE4C-4688-BC3C-4FCF39D609E7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{87D1A6EF-8CBC-458A-84B5-0333562418CD}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{886DDE35-E955-11D0-A707-000000521958}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{886DDE35-E955-11D0-A707-000000881958}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{88C51E90-8E9C-4C96-8A45-574D88B63FAF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{88D758A3-D33B-45FD-91E3-67749B4057FA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8A0DCBDB-6E20-489C-9041-C1E8A0352E75}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8C875948-9C60-4381-9248-0DF180542D53}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FCDF9D9-A28B-480F-8C3D-581F119A8AB8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{907CA0E5-CE84-11D6-9508-02608CDD2846}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{91433D86-9F27-402C-B5E3-DEBDD122C339}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{94F5DCB7-816C-4B94-A2C1-856C6E323C5B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{95460ABD-946A-46FF-9F56-268718323EEE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{9656B666-992F-4D74-8588-8CA69E97D90C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{972BB342-14A7-4660-83C1-51DDBEE171DB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{97B79133-88F0-45F0-8D57-0F2EF27D9C66}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{986DDE35-E955-11D0-A707-000000521958}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{99410CDE-6F16-42ce-9D49-3807F78F0287}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{99802379-7362-40E2-9D28-8A3B9AF880B7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{9A19966F-AE0E-4699-8CCE-9B6F5F1C352C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{9AC54695-69A4-46F1-BE10-10C74F9520D5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{9DBAFCCF-592F-FFFF-FFFF-00608CEC297B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{9DBAFCCF-592F-FFFF-FFFF-00608CEC297C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{9E1089BC-1AE8-4685-8D77-6721E5C318A8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{9E98E84C-79E1-49C3-82EB-798FCD552EFB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{9EB320CE-BE1D-4304-A081-4B4665414BEF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{A0EAC162-A012-4AD8-B2E1-D5A0BBBCDA51}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{A1426AC5-8CE5-4A00-B71E-011D35709AC6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{A1A961DA-2BA6-4032-859E-01AC35357163}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{A1C392A2-B274-46DB-89BE-1FBD476B9C93}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{A1DC3241-B122-195F-B21A-000000000000}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{A27AD582-5BE5-4C2D-82F0-48B24FE02040}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{A45F39DC-3608-4237-8F0E-139F1BC49464}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{A47693D1-7E2A-4DE3-9907-310C5D310B5F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{A51DEDCD-20F7-11D4-98A5-00C0CA130748}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{A7532940-DB22-4B10-BE6A-B467E5330745}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{A7EA8AD2-287F-11D3-B120-006008C39542}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{ABD45F35-2E4C-44C0-A075-6EF1DE75398E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{AD7FAFB0-16D6-40C3-AF27-585D6E6453FD}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{AED98630-0251-4E83-917D-43A23D66D507}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{AF7410C1-FBA3-415E-800A-4110CED40536}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{AFDBB6D0-6B96-419C-8BC6-FF0B99368C0B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{B10031B2-F184-4803-9A88-D239C0641D70}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{B2B0AEDF-7CDF-4792-BB67-7654AD1E1B13}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{B4831DED-3A57-4CC6-9E4B-0E7C5B08DBF4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{B4E0F9CB-BC06-4A33-BBB3-F75F16B6FF5E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{B73BC7C7-858B-49FA-BBDB-74DD77D1D9F3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{B7E76C25-791F-432E-BDB7-748D01A93FC2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{B94B4225-E02E-4D3F-BADB-026F1E2F3AD7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{BA14D944-0D8C-4F16-A950-6E53EEBB558F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{BA749BC1-143E-430D-B1DA-1D2AF67A3658}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{BAB3E70B-A847-4A88-ACFC-778FCCC00287}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{BADA82CB-BF48-4D76-9611-78E2C6F49F03}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{BD3653E4-884B-43C4-970B-670802501B7F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{BD419ACD-B41C-49D9-8ADF-CCA159052515}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{BE5A7132-329F-4319-B781-2A83BFE51534}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{BFC9677B-8006-4336-9D49-2C797AEFCB9E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{C0B285F6-DB2B-4908-9C58-F6D95397D747}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{C1C2AC28-5E4B-4228-B7A0-05E986FFCE14}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{C2481ED1-9896-4D49-AE90-69858DFDE446}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{C56CE781-A6FC-4706-8B32-6EB4622155DF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{C6760A07-A574-4705-B113-7856315922C3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{C7B05B62-C8D7-438C-840B-4994DAAA8EEE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CA034DCC-A580-4333-B52F-15F98C42E04C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CC110316-5BE7-4AAA-AEDD-1A5B147BE34C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CD89AB62-B70C-43CF-AC83-C7BB55C3DA43}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CDCBE0F1-D13A-4F86-A963-3A272D3ABA7E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CEFB7B49-9652-464F-8AFD-A577C0500F39}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CFCB7308-782F-11D4-BE27-000102598CE4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D18B7EC3-EECA-11D3-8E71-0000E82C6C0D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D19781C5-2051-44F8-8445-DDC82933C191}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D53B810F-6219-11D4-95B6-0040950375E7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D6FCA8ED-4715-43DE-9BD2-2789778A5B09}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D7BF3304-138B-4DD5-86EE-491BB6A2286C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D8B94E9A-A34B-4253-BF48-C7CB7F2CFDB0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D94AAA2A-C415-42E3-82B6-49FAB4EBFFE9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{DA9A0B1E-9B7B-11D3-B8A4-00C04F79641C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{DB893839-10F0-4AF9-92FA-B23528F530AF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{DBAE7000-01EC-4162-8FEB-8A27AC937CA0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{DCB709B4-4142-411A-8E9F-F265AE2B7BDE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{DD8C9372-35FD-4F7D-8CE4-909ABCFAB2C5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{DDFFA75A-E81D-4454-89FC-B9FD0631E726}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{DECEAAA2-370A-49BB-9362-68C3A58DDC62}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{DF7A9F1F-E06B-4BE7-A27E-1BE7EA5AFC1C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E055C02E-6258-40FF-80A7-3BDA52FACAD7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E0CE16CB-741C-4B24-8D04-A817856E07F4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E114CD5B-17CE-4807-890E-7B1EDF9F2E5E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E19AB99F-AEC4-4B40-A5CA-F69D22522D77}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E1D20694-74D9-472D-AF03-08C26173A67F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E24E8472-89B7-479F-8AD8-BBD7206A6A02}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2F2B9D0-96B9-4B25-B90C-636ECB207D18}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E3F7205F-2AE0-4BF0-816B-2D24A5F20EC7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E473A65C-8087-49A3-AFFD-C5BC4A10669B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E62A47D8-74B1-4A93-963A-E5E43B7CC5C2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E7AE1661-EBEB-492B-AE0D-860DF24174C6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E8EDB60C-951E-4130-93DC-FAF1AD25F8E7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E9670165-86FE-4C34-8C4B-D3158DDC5D92}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{EC51659D-721F-4CBF-9CEA-5E776D89CEA9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{EE2589EB-7FC8-44DB-A892-573F2C4B41E0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{EF4DCD99-D26B-44A4-BA77-CFDCC97E7291}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{EF86873F-04C2-4A95-A373-5703C08EFC7B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{EF98AF7B-1F54-4079-91BC-3996DEABA45A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{EFB22865-F3BC-4309-ADFA-C8E078A7F762}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{F0230524-9D39-4E84-8452-41C592961EA7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{F48EAB92-8BCE-4C77-BE98-D10060BD8590}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{F5192746-22D6-41BD-9D2D-1E75D14FBD3C}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{F57D17AE-CE37-4BC8-B232-EA57747BE5E7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{F72BC3F0-6C20-4793-9DDA-258589D8A907}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{F760CB9E-C60F-4A89-890E-FAE8B849493E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{F919FBD3-A96B-4679-AF26-F551439BB5FD}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FA13A9FA-CA9B-11D2-9780-00104B242EA3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FA1D6D8F-C6ED-4752-8512-A33283240130}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FA83E942-B796-46DE-9155-1632ECC5473B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FAFF0003-0A01-121A-A1C9-08032B23E0CC}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FDDCE9FF-1FC6-413C-80B1-37B101FDA1D4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FE1A240F-B247-4E06-A600-30E28F5AF3A0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FE4BBEA8-1EFD-4B8A-BD1B-341CCDBEEAA6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FE6A3E85-0F6C-49AD-8843-68FF44E7EEA9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FF3F0F03-0F01-131A-A3F9-08F02B23E0CC}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FF65677A-8977-48CA-916A-DFF81B037DF3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FFFF0003-0001-101A-A3C9-08002B23E0CC}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FFFF0003-0001-101A-A3C9-08002B23E0CD}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FFFF0003-0001-101A-A3C9-08002B2F49FB}

Removing ActiveX Malware:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Spy.Agent.ln Trojan Removal instruction
Perfect.Keylogger Spyware Cleaner
ServU.based Backdoor Removal