- C:\WINDOWS\cGlwbw\command.exe
- C:\Programme\Network Monitor\netmon.exe
- C:\Programme\JavaCore\JavaCore.exe
- O4 - HKLM\..\Run: [outlook] C:\Programme\outlook\outlook.exe /auto
- O4 - HKLM\..\Run: [winlog] winlog.exe
- O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu1000137.exe 61A847B5BBF72813329B385771FE01F0B3E35B6638993F4661 AA4EBD86D67C56389B284534F310F3 D1DC7E4638E8323A15806F97BDE4417E6FD967002BA754E2C2 832213319C26033AAC
- O4 - HKLM\..\Run: [{09-9C-C6-6D-DW}] C:\WINDOWS\system32\jownw64j.exe DWram
- O4 - HKLM\..\Run: [g]eeV\mWhjlnspB] C:\WINDOWS\system32\pcntpkdn.exe DWram
- O4 - HKLM\..\Run: [8ce09cc2] rundll32.exe "C:\WINDOWS\system32\mqevbfho.dll",b
- O4 - HKLM\..\Run: [BM8fd3af5e] Rundll32.exe "C:\WINDOWS\system32\erkuubom.dll",s
- O4 - HKLM\..\RunServices: [winlog] winlog.exe
- O4 - HKCU\..\Run: [Twain] C:\Programme\Twain\Twain.exe
- O4 - HKCU..Run: [JavaCore] C:Programme\JavaCore\JavaCore.exe
- O4 - Startup: Deewoo.lnk = C:\WINDOWS\system32\pcntpkdn.exe
- O4 - Startup: DW_Start.lnk = C:\WINDOWS\system32\jownw64j.exe
- O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\cGlwbw\command.exe
- O23 - Service: Network Monitor - Unknown owner - C:\Programme\Network Monitor\netmon.exe