..\System\CurrentControlSet\Services\SharedAccess\Parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List\"%DAS.AU.LS%\Temp\BACKDOOR.WIN32.AGENT.XR.EXE"\"%DAS.AU.LS%\Temp\BACKDOOR.WIN32.AGENT.XR.EXE:*:Enabled:BACKDOOR.WIN32.AGENT.XR.EXE" |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"RkBellExe"\"%WIN.SYS32%\realched.exe" |
..\System\CurrentControlSet\Services\xadx\(Default) |
..\Software\Microsoft\Windows\CurrentVersion\Run\\"kernell32"\"%win%\services.exe" |
..\Software\araf15\(Default) |
..\Software\Classes\iepl.iepl\(Default) |
..\Software\Classes\iepl.iepl.1\(Default) |
..\Software\Classes\Clsid\{0612f71e-934b-4d92-b8e8-2e29ea78eb03}\(Default) |
..\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0612F71E-934B-4D92-B8E8-2E29EA78EB03}\(Default) |