- Connects to the internet without permission
- Slow internet connection
- System crashes
- Annoying Pop-up's
- Slow Computer
Worm.AutoRunWorm.AutoRun is a worm that spreads and infiltrates various systems as a file downloaded unknowingly by a system user when visiting malicious websites. It can also arrive on a system as a file dropped by other malware. This infection is particularly damaging to a computer system because it can fully embed itself within the system, which is the main reason it is given a high priority security risk status by many computer analysts. The fact that this worm can easily enter any PC system via security exploits and flaws, most times without the user’s interaction, means that it is that much easier for it to compromise the system. Unfortunately, to remove Worm.AutoRun you first need to recognize this threat, and that is the biggest struggle that computer users face. The malicious Worm.AutoRun is the kind of malware that is capable of spreading itself by copying itself into computer hard drives, as well as external drives. Infected CDs, DVDs, and USB devices could be used to infect your operating system with this worm. File-sharing networks and open networks are used to spread malicious code often; however, spam emails could be employed to distribute this malware as well. Note that if an infected system is connected to a shared network, all local computers could be infected as well. Once installed, it can silently install malware. A single worm can open a portal via which a ton of malicious infections could slither in! Considering that worms are silent infections, additional malware could be downloaded without permission as well. If that happens, your virtual security could be in grave danger, and so you need to be careful about the malware that could slither in. The devious Worm.AutoRun is likely to be used for the propagation of malicious payloads. Depending on the payload, your operating system might be infected with password-stealing keyloggers, malware dropping Trojans, and other malicious threats. Because there are so many different variants of this worm and because it can be used in different ways, our research team has linked quite a few files to it. You can see the full list below this article, and these are the files you need to look for if you are interested in removing malware manually. Unfortunately, the removal is not easy primarily because the files employed could use the names of authentic files. On top of that, legitimate files, including Windows system files, could be infected to assist malware. In that case, simply removing these files is not an ideal solution. Few of the many files that are associated with Worm.AutoRun include cftmom.exe, cmd.exe, explorer.exe, smss.exe, svchost.exe, and iexplorer.exe. VideoEnhancerSetup.exe, cdccdccafdde.dll, afaadacbadddc.dll, Ikariam Hack.exe, winjpg.jpg, ACERS-SYPE-COMET-SOFEE-ACES.vbs, moz.vbs, and hundreds of other files could be used by or downloaded by Worm.AutoRun. Malicious files could be used to record your keystrokes and log passwords, transmit data collected to remote servers, download additional malware, disable Windows utilities that could help you remove malware, introduce fictitious security notifications, or take over your virtual identity. If you fail to remove every single malicious component active on your computer – including registry entries created or modified by malware – your operating system will be vulnerable to breaches. The problem is that identifying/detecting malware is a complicated task, and few users will be able to find malware themselves without using tools. The first tool we recommend using is a malware scanner. It is essential that you scan your operating system to see which malicious infections have taken over. Since it is unlikely that Worm.AutoRun is the only malicious threat, and it is known that it can help malware slither in without your notice, you might find a few surprises. Even if the removal processes seem simple and straightforward, you must keep in mind that some infections are capable of rooting themselves deep into your operating system. Some of them can even infect original files or use their names to conceal themselves and confuse you about their removal. Overall, the removal of Worm.AutoRun is a complicated task, and it is likely that you will need to eliminate a few other threats. Therefore, our recommendation for you is to acquire automatic malware removal software instead. |
Download Spyware Removal Tool to Remove*
Worm.AutoRun
|
|
How to manually remove Worm.AutoRun
Files associated with Worm.AutoRun infection:
win32.exe
1823.exe
wmpnetwkv9r1.dll
stpass.exe
UniKey.exe
sp.DLL
iturbo.exe
Startup.exe
cftuon.exe
WinSysApp.exe
WinAlert.exe
netsvcs32.exe
test.exe
_ex-68.exe
TNODUP.exe
Ikariam Hack.exe
60DA8.exe
YPfdbKQmYWnOqAL.exe
tMfQnhnjewmTtoH.exe
oKGUvxjzUCiQ4v.exe
lvvm.exe
AB6.exe
7FC.exe
xmlprw32.dll
wondershare.ppt2dvd.pro.6.1.7-MPT.exe
WinDefender.exe
thpm4230316309100063979.tmp
tdx.sys
netbt.sys
MPKView.exe
LhZ47ZN0LkjNp8.exe
gGoRaLwOHp2vcb.exe
fUOfWDexaNHOBg.exe
dfsc.sys
cdrom.sys
bmhost.exe
winggom.exe
wcdplayer.dll
steam.exe
MCFrance_setup.exe
AE947CD1124.exe
kl.exe
sms.exe
SafeDrvll.exe
your name as ringing tone.exe
winusbsmgr.exe
Torchlight.exe
regdrv3.exe
questbrowse169.exe
packobjparse.exe
Neetplwiz.exe
jsodj.exe
inetsw32.dll
fd9ljzev.exe
E510.exe
DailyBibleGuideAuto.exe
casttipv2.exe
Aggr3.exe.exe
2K11Ã=Ȧ+µ¦¦ðÌ©-ã¸.exe
windows_update.exe
questscan145.exe
mdhcp32.dll
ecleaner.exe
wcynsvc.exe
ysbjnkdnroctft.dll
StartupSlowFix.exe
wdt.exe
tasker.exe
MSASCul.exe
java.exe
CORYBJUvgosSXeG.exe
50E0.exe
IDM.exe
Windows32Shield.exe
server.exe
queryscan133.exe
1878.dll
PrintScreenPro.exe
EliStarA.exe
1378.dll
rk.exe
wupyupwctt.exe
vsbntlo.exe
s1.exe
hidprov.exe
facebook.exe
aston.exe
F842.tmp
taipingtianguov1.1.exe
Recycle.Bin.exe
winlogin.exe
nvdisp.exe
KB920872.dll
Chouf-This.exe
vbcs.exe
conhost.exe
Explore.exe
radmin_2.2.exe
msime82.exe
usrsvc.exe
takman.exe
questresult128.exe
wmupd.exe
scanquery129.exe
resultbrowse157.exe
questdns157.exe
questbrowse145.exe
questbrowse143.exe
chkntion.dll
aeevts.exe
ndi.exe
wuauclt.exe
yteryx.exe
igfxtray.exe
igfxbp32.exe
xthvfge.dat
sysam.exe
rundll32 .exe
glovext.dll
eidbkzw.dll
eerxnideomksvirtfpux.dll
AdVantage.exe
hhgwiamd.dll
afido.exe
uvvnx03.dll
JavaUpdatecdr.cpl
yt8a.exe
slideshow.scr
WUpdateAgent.exe
M3MEDINT.EXE
My Web Search Installer(0004af80).exe
m3HighIn.exe
g14iLivid_Setup.exe
SlimFTPd.exe
mkyvyuo.sys
gamexl.exe
explorer.exe:userini.exe
jutched.exe
AnimatedDesktop.exe
msible.dll
codeclib.exe
Microsoft Office PowerPoint 2007.exe
GD.exe
setup.exe
recycle.exe
odloadf1C.dll
mskufed3d.dll
CrackDown.exe
avgtray.exe
autoclk.exe
SFCsrvc.pif
HPWizard.exe
jwkd.exe
agedc.exe
gabpath.exe
wd21552.dll
deWMV1.dll
vsssadmin.exe
spllwow64.exe
hcRlcTgraZ.exe
ultrafx.exe
SetupRun.exe
defender.exe
WarRock.exe
Setup-5.051.exe
securitymanager.exe
oOxKcTW6P.exe
GameMon.des
fgmhduxuerb.exe
6twpfP84As.exe
wins.exe
winfixer.exe
u1006.org.exe
syitm.exe
swchost.exe
Singularity Trainer.exe
SI796_289.exe
SI4b1_231.exe
qsrvq.exe
kbdgrvi.dll
ffe.dll
6to4ex.dll
svrwsc.exe
winspymaster.exe
comsrvr.exe
winjpg.jpg
wing.exe
svchos.exe
remove.exe
AUTOCONVE.EXE
csrcs.exe
windows.exe
x41.exe
wscntfy.exe
SE2011.exe
recyclebin.exe
cpwr.exe
ComboFix.exe
AdobeUpdate.exe
servicess.exe
teoraarate.dll
Skynet Iranoffline v2.3.exe
listener.exe
Sytvsm.exe
zaking.exe
0573500384.exe
027965933.exe
youm_3.dll
javawhelper.dll
ieakeng32.dll
hitblniaffm.exe
d3dim32.dlld8qvq1s32.dllnz083rpp32.dllwm2bx32.dllpy1guijtnmf0d32.dll
arking.exe
acrobatflashhplayer.exe
8rjzl32.dll
Polygon Love 2 V1.1 Launcher v2 Full loli.exe
yoos.b
wuaucldt.exe
FastUv32.dll
6to4v32.dll
4801640.dll
14582312.dll
crazya.exe
webcam.exe
VideoEnhancerSetup.exe
SmitfraudFix.exe
klifoko.sys
ctbr.dll
McaUpdate.exe
Flash_Disinfector.exe
domain.exe
VirusRemoval_PERO.vbs
UjBright_Antivirus.vbs
tumauini.vbs
solution.vbs
RJN_Burner.vbs
moz.vbs
killVBS.vbs
d.vbs
astig.vbs
AdobeCS4.vbs
ACERS-SYPE-COMET-SOFEE-ACES.vbs
999.vbs
SysAnti.exe
SafeDrvsss.exe
SafeDrvee.exe
SafeDrv.exe
nodqq.exe
csrsc.exe
autorun.inf
win32osf.exe
XP-6A3A0D20.EXE
ohydy.exe
winlog.exe
ahr.exe
sWx.exe
Application Datasvchost.exe
winlogon.exe
cftu.exe
XP-84978424.EXE
M7K1H3A6.vbs
XP-DCB3C72C.EXE
UbiRg.exe
XP-2D39A46D.EXE
rundll56.exe
XP-C6BBD855.EXE
XP-822A840F.EXE
XP-38B8CEBE.EXE
XP-8FF03DFF.EXE
XP-8F09BDB0.EXE
rundli32.exe
sysdiag64.exe
userinit.exe
XP-364C086F.EXE
XP-5C37B42E.EXE
XP-C748D768.EXE
XP-17010165.EXE
XP-042EC9AF.EXE
XP-A252657D.EXE
XP-D41D8CD9.EXE
XP-C8889B57.EXE
XP-AA54AD69.EXE
XP-6BB4378C.EXE
XP-E7D6DD34.EXE
XP-3451AFB8.EXE
XP-F09415CE.EXE
XP-12B7E2EE.EXE
XP-12C950AE.EXE
XP-85A6D8DD.EXE
XP-904B231F.EXE
XP-F180A41E.EXE
XP-2B689D56.EXE
XP-21470116.EXE
XP-5ADC2FB8.EXE
XP-CE0B6B01.EXE
XP-0EF5525C.EXE
XP-CE734A3C.EXE
XP-F3603667.EXE
XP-F787D259.EXE
XP-4D887B29.EXE
XP-C8C16F42.EXE
XP-6CF365E3.EXE
XP-87B203C2.EXE
XP-172566D2.EXE
XP-DDA58EAE.EXE
XP-337B8E53.EXE
XP-5ED4BC61.EXE
XP-E044478C.EXE
XP-D754771A.EXE
XP-3E5A95DF.EXE
XP-590822A9.EXE
XP-CF959062.EXE
XP-09A09F1E.EXE
iexplorer.exe
system.exe
lsass.exe
JACKsmall.exe
CSRSS.exe
services.exe
WindowsLive.exe
8EBE6FCF.DLL
cvasds0.dll
herss.exe
6FB219.EXE
83B2C82D.DLL
tsay.exe
userini.exe
kislab.exe
fffddeabacfda.dll
windowsmp.exe
explorcr.exe
init.exe
guangd.exe
aebfcbddecdfffeca.dll
scvhost.exe
vshost32.exe
smss.exe
KEYBOARD.exe
fuwuqi.exe
Win24DLL.exe
afaadacbadddc.dll
kvtrwkcc.exe
fool1.dll
SVCHOST32.EXE
scrss.exe
Thumbs.exe
svchots.exe
SilentSoftech.exe
winsys.exe
Syswin.exe
BEA23C.EXE
XP-30ABA011.EXE
qbbtqcy.exe
XP-71F06FE8.EXE
XP-EA1E4442.EXE
GuelmimG.bat
Mixa.exe
MAgent.exe
cftmon.exe
ipilrws.exe
systtray.exe
cftmom.exe
cmd.exe
explorer.exe
spools.exe
SVCHOST.exe
Msmsgs.exe
cvlu.exe
E05A84.EXE
XP-27EE4BE0.EXE
FlashGuard.exe
msupdt.exe
Imgtask.exe
ntdetect.com
xxz[1].exe
edbeacdefdfbd.dll
cdccdccafdde.dll
Worm.AutoRun DLL's to remove:
sp.DLL
8EBE6FCF.DLL
83B2C82D.DLL
xmlprw32.dll
wcdplayer.dll
inetsw32.dll
mdhcp32.dll
ysbjnkdnroctft.dll
1878.dll
1378.dll
KB920872.dll
chkntion.dll
glovext.dll
eidbkzw.dll
eerxnideomksvirtfpux.dll
hhgwiamd.dll
uvvnx03.dll
msible.dll
odloadf1C.dll
mskufed3d.dll
wd21552.dll
deWMV1.dll
kbdgrvi.dll
ffe.dll
6to4ex.dll
teoraarate.dll
youm_3.dll
javawhelper.dll
ieakeng32.dll
d3dim32.dlld8qvq1s32.dllnz083rpp32.dllwm2bx32.dllpy1guijtnmf0d32.dll
8rjzl32.dll
FastUv32.dll
6to4v32.dll
4801640.dll
14582312.dll
ctbr.dll
cvasds0.dll
fffddeabacfda.dll
aebfcbddecdfffeca.dll
afaadacbadddc.dll
fool1.dll
Worm.AutoRun processes to kill:
win32.exe
1823.exe
stpass.exe
M3MEDINT.EXE
AUTOCONVE.EXE
BEA23C.EXE
XP-30ABA011.EXE
XP-6A3A0D20.EXE
XP-71F06FE8.EXE
XP-EA1E4442.EXE
XP-27EE4BE0.EXE
XP-84978424.EXE
XP-DCB3C72C.EXE
XP-2D39A46D.EXE
XP-C6BBD855.EXE
XP-822A840F.EXE
XP-38B8CEBE.EXE
XP-8FF03DFF.EXE
XP-8F09BDB0.EXE
XP-364C086F.EXE
XP-5C37B42E.EXE
XP-C748D768.EXE
XP-17010165.EXE
XP-042EC9AF.EXE
XP-A252657D.EXE
XP-D41D8CD9.EXE
XP-C8889B57.EXE
XP-AA54AD69.EXE
XP-6BB4378C.EXE
XP-E7D6DD34.EXE
XP-3451AFB8.EXE
XP-F09415CE.EXE
XP-12B7E2EE.EXE
XP-12C950AE.EXE
XP-85A6D8DD.EXE
XP-904B231F.EXE
XP-F180A41E.EXE
XP-2B689D56.EXE
XP-21470116.EXE
XP-5ADC2FB8.EXE
XP-CE0B6B01.EXE
XP-0EF5525C.EXE
XP-CE734A3C.EXE
XP-F3603667.EXE
XP-F787D259.EXE
XP-4D887B29.EXE
XP-C8C16F42.EXE
XP-6CF365E3.EXE
XP-87B203C2.EXE
XP-172566D2.EXE
XP-DDA58EAE.EXE
XP-337B8E53.EXE
XP-5ED4BC61.EXE
XP-E044478C.EXE
XP-D754771A.EXE
XP-3E5A95DF.EXE
XP-590822A9.EXE
XP-CF959062.EXE
XP-09A09F1E.EXE
6FB219.EXE
SVCHOST32.EXE
E05A84.EXE
UniKey.exe
iturbo.exe
Startup.exe
cftuon.exe
WinSysApp.exe
WinAlert.exe
netsvcs32.exe
test.exe
_ex-68.exe
TNODUP.exe
Ikariam Hack.exe
60DA8.exe
YPfdbKQmYWnOqAL.exe
tMfQnhnjewmTtoH.exe
oKGUvxjzUCiQ4v.exe
lvvm.exe
AB6.exe
7FC.exe
wondershare.ppt2dvd.pro.6.1.7-MPT.exe
WinDefender.exe
MPKView.exe
LhZ47ZN0LkjNp8.exe
gGoRaLwOHp2vcb.exe
fUOfWDexaNHOBg.exe
bmhost.exe
winggom.exe
steam.exe
MCFrance_setup.exe
AE947CD1124.exe
kl.exe
sms.exe
SafeDrvll.exe
your name as ringing tone.exe
winusbsmgr.exe
Torchlight.exe
regdrv3.exe
questbrowse169.exe
packobjparse.exe
Neetplwiz.exe
jsodj.exe
fd9ljzev.exe
E510.exe
DailyBibleGuideAuto.exe
casttipv2.exe
Aggr3.exe.exe
2K11Ã=Ȧ+µ¦¦ðÌ©-ã¸.exe
windows_update.exe
questscan145.exe
ecleaner.exe
wcynsvc.exe
StartupSlowFix.exe
wdt.exe
tasker.exe
MSASCul.exe
java.exe
CORYBJUvgosSXeG.exe
50E0.exe
IDM.exe
Windows32Shield.exe
server.exe
queryscan133.exe
PrintScreenPro.exe
EliStarA.exe
rk.exe
wupyupwctt.exe
vsbntlo.exe
s1.exe
hidprov.exe
facebook.exe
aston.exe
taipingtianguov1.1.exe
Recycle.Bin.exe
winlogin.exe
nvdisp.exe
Chouf-This.exe
vbcs.exe
conhost.exe
Explore.exe
radmin_2.2.exe
msime82.exe
usrsvc.exe
takman.exe
questresult128.exe
wmupd.exe
scanquery129.exe
resultbrowse157.exe
questdns157.exe
questbrowse145.exe
questbrowse143.exe
aeevts.exe
ndi.exe
wuauclt.exe
yteryx.exe
igfxtray.exe
igfxbp32.exe
sysam.exe
rundll32 .exe
AdVantage.exe
afido.exe
yt8a.exe
WUpdateAgent.exe
My Web Search Installer(0004af80).exe
m3HighIn.exe
g14iLivid_Setup.exe
SlimFTPd.exe
gamexl.exe
explorer.exe:userini.exe
jutched.exe
AnimatedDesktop.exe
codeclib.exe
Microsoft Office PowerPoint 2007.exe
GD.exe
setup.exe
recycle.exe
CrackDown.exe
avgtray.exe
autoclk.exe
HPWizard.exe
jwkd.exe
agedc.exe
gabpath.exe
vsssadmin.exe
spllwow64.exe
hcRlcTgraZ.exe
ultrafx.exe
SetupRun.exe
defender.exe
WarRock.exe
Setup-5.051.exe
securitymanager.exe
oOxKcTW6P.exe
fgmhduxuerb.exe
6twpfP84As.exe
wins.exe
winfixer.exe
u1006.org.exe
syitm.exe
swchost.exe
Singularity Trainer.exe
SI796_289.exe
SI4b1_231.exe
qsrvq.exe
svrwsc.exe
winspymaster.exe
comsrvr.exe
wing.exe
svchos.exe
remove.exe
csrcs.exe
windows.exe
x41.exe
wscntfy.exe
SE2011.exe
recyclebin.exe
cpwr.exe
ComboFix.exe
AdobeUpdate.exe
servicess.exe
Skynet Iranoffline v2.3.exe
listener.exe
Sytvsm.exe
zaking.exe
0573500384.exe
027965933.exe
hitblniaffm.exe
arking.exe
acrobatflashhplayer.exe
Polygon Love 2 V1.1 Launcher v2 Full loli.exe
wuaucldt.exe
crazya.exe
webcam.exe
VideoEnhancerSetup.exe
SmitfraudFix.exe
McaUpdate.exe
Flash_Disinfector.exe
domain.exe
SysAnti.exe
SafeDrvsss.exe
SafeDrvee.exe
SafeDrv.exe
nodqq.exe
csrsc.exe
SearchSettingsProtection.exe
win32osf.exe
ohydy.exe
winlog.exe
ahr.exe
sWx.exe
Application Datasvchost.exe
winlogon.exe
cftu.exe
UbiRg.exe
rundll56.exe
rundli32.exe
sysdiag64.exe
userinit.exe
iexplorer.exe
system.exe
lsass.exe
JACKsmall.exe
CSRSS.exe
services.exe
WindowsLive.exe
herss.exe
tsay.exe
userini.exe
kislab.exe
windowsmp.exe
explorcr.exe
init.exe
guangd.exe
scvhost.exe
vshost32.exe
smss.exe
KEYBOARD.exe
fuwuqi.exe
Win24DLL.exe
kvtrwkcc.exe
scrss.exe
Thumbs.exe
svchots.exe
SilentSoftech.exe
winsys.exe
Syswin.exe
qbbtqcy.exe
Mixa.exe
MAgent.exe
cftmon.exe
ipilrws.exe
systtray.exe
cftmom.exe
cmd.exe
explorer.exe
spools.exe
SVCHOST.exe
Msmsgs.exe
cvlu.exe
FlashGuard.exe
msupdt.exe
Imgtask.exe
xxz[1].exe
edbeacdefdfbd.dll
cdccdccafdde.dll
Remove Worm.AutoRun registry entries:
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ userini
HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Win32Update
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINLOGON\NOTIFY\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\aebfcbddec
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINLOGON\NOTIFY\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\aebfcbddecdfffeca
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINLOGON\NOTIFY\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\afaadacbad
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINLOGON\NOTIFY\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\afaadacbadddc
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINLOGON\NOTIFY\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\fffddeabac
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINLOGON\NOTIFY\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINLOGON\NOTIFY\fffddeabacfda
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINLOGON\USERINIT\ userinit
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE\ msfsa
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 6FB219
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Adobe Reader Updater
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ antihost
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ App
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ autoload
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ BEA23C
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ cftmom
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ cftu
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ CTFMON.EXE
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Discovery
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ DsNiu
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ E05A84
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ egrrgdk
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ explorcr
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ eYvUrwsWmuzcTI
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ FlashGuard
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ghost9
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ GuelmimG
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Hotfix-KB996914673
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ IEXPLORER
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ igfxtras
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ImgTask
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Kaspersky Lab
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ MAgent
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ MKH
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Msmsgs
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ MsnMsgs
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ MyApp
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ NetworkReportingTag
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ngcxjsi
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ntuser
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ NVIDIA Media Center Library
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ PHIME2008
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ REG_NAME
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ run32
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ RunJava2
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Services
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ SilentSoftech
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ smss
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ soe1
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Svchost
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ sysdiag64.exe
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ SysUtils
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Syswin
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Thumbs
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Update
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ userini
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Userinit
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Virus
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Win32 Console
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Windows DriversUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Windows Generic Host Process
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Windows Live
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Windows Services
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Windows Update
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ windowsmp
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-042EC9AF
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-09A09F1E
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-0EF5525C
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-12B7E2EE
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-12C950AE
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-17010165
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-172566D2
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-21470116
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-27EE4BE0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-2B689D56
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-2D39A46D
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-30ABA011
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-337B8E53
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-3451AFB8
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-364C086F
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-38B8CEBE
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-3E5A95DF
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-4D887B29
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-590822A9
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-5ADC2FB8
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-5C37B42E
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-5ED4BC61
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-6BB4378C
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-6CF365E3
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-71F06FE8
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-822A840F
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-84978424
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-85A6D8DD
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-87B203C2
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-8F09BDB0
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-8FF03DFF
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-904B231F
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-A252657D
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-AA54AD69
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-C6BBD855
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-C748D768
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-C8889B57
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-C8C16F42
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-CE0B6B01
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-CE734A3C
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-CF959062
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-D41D8CD9
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-D754771A
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-DCB3C72C
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-DDA58EAE
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-E044478C
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-E7D6DD34
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-EA1E4442
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-F09415CE
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-F180A41E
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-F3603667
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ XP-F787D259
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cdccdccafdde
Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\edbeacdefdfbd
RUNNING PROGRAM\cftmon.exe
RUNNING PROGRAM\explorer.exe
RUNNING PROGRAM\kvtrwkcc.exe
RUNNING PROGRAM\winlogon.exe
Comments
thnk you