| ..\Software\Microsoft\Windows\CurrentVersion\Run\\"win"\"%win.sys32%\win.exe" |
| ..\Software\Microsoft\active setup\installed components\{06a73f9d-4b01-c1a3-82b0-0b1f237a75cb}\(Default) |
| ..\Software\Microsoft\active setup\installed components\{3cb6989c-0329-b7a6-1e6b-3290383e5391}\(Default) |
| ..\Software\Microsoft\Windows\CurrentVersion\Run\\"java"\"%root%\input\13985_backdoor.win32.poison.aec_20091219\3b20a45c.exe" |
| ..\Software\Microsoft\active setup\installed components\{f1c4d7e2-0f41-8e8b-1332-9b881b467c17}\(Default) |
| ..\Software\Microsoft\active setup\installed components\{b8d82cf3-1b06-a86e-9874-29fc381e93ca}\(Default) |
| ..\Software\Microsoft\active setup\installed components\{84285b49-8e2b-8a6e-e033-06d8eca4f328}\(Default) |
| ..\Software\Microsoft\active setup\installed components\{3db782d7-aacc-3a9d-eaad-a3de73e8dd8f}\(Default) |
| ..\Software\Microsoft\Windows\CurrentVersion\Run\\"mishal"\"%das.au.ls%\temp\server.exe" |
| ..\Software\Microsoft\Windows\CurrentVersion\Run\\"fa912be3"\"%root%\docume~1\admin\locals~1\temp\ixp000.tmp\0.exe" |