Vundo Trojan Removal: Remove Vundo Trojan Forever
Let our support team solve your problem with Vundo Trojan and repair Vundo Trojan right now!
Leave the detailed description of your Vundo Trojan problem in the form below. Our support team will contact you in several minutes and give a step-by-step instruction on how to fix Vundo Trojan problem. Please be specific. Do your best describing the problem. This will help us recommend right and complete Vundo Trojan problem removal solution.
Describe your problem here and we'll contact you in several minutes:
Warning:
1) We hate spam as much as you do. We will not share your email with any third party or publish it anywhere. Your email is used only to contact you and give you Vundo Trojan removal solution.
2) All fields of this form are obligatory.
Threat's profile
|
Name of the threat: Vundo Trojan |
| Command or file name: win18.tmp.exe |
| Threat type: Spyware\trojan |
| Affected OS: Win32 (Windows 9x, Windows XP, Windows Vista, Windows Seven) |
Vundo Trojan intrusion method
Vundo Trojan copies its file(s) to your hard disk. Its typical file name is win18.tmp.exe. Then it creates new startup key with name Vundo Trojan and value win18.tmp.exe. You can also find it in your processes list with name win18.tmp.exe or Vundo Trojan.
If you have further questions about Vundo Trojan, please fill in the form above and we'll contact you shortly.
» Download program to remove Vundo Trojan (Vundo Trojan Removal Tool)
Recommended Solution
If you are not sure what to delete, use our award winning program - Vundo Trojan Removal Tool.
Vundo Trojan Removal Tool will find and fully remove Vundo Trojan and all problems associated with Vundo Trojan virus.
Fast, easy, and handy, Vundo Trojan Removal Tool protects your computer against Vundo Trojan that does harm to your computer and breaks your privacy. Vundo Trojan Removal Tool scans your hard disks and registry and destroys any manifestation of Vundo Trojan. Standard anti-virus software can do nothing against malicious programs like Vundo Trojan. Remove Vundo Trojan straight away!
» Download Vundo Trojan Removal Tool now for free
How to fix Vundo Trojan
This problem can be solved manually by deleting all registry keys and files connected with Vundo Trojan, removing it from starup list and unregistering all corresponding DLLs. Additionally missing DLL's should be restored from distribution in case they are corrupted by Vundo Trojan.
To get rid of Vundo Trojan, you should:
1. Kill the following processes and delete the appropriate files:
no information
Warning: you should delete only those files which checksums are listed as malicious. There may be valid files with the same names in your system. We recommend you to use Vundo Trojan Removal Tool for safe problem solution.
2. Delete the following malicious folders:
• docume~1\hp_adm~1\locals~1\temp\
3. Delete the following malicious registry entries and\or values:
- Key: Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
Value: defender
- Key: ATLDistrib.ATLDistrib
- Key: ATLDistrib.ATLDistrib.1
- Key: CLSID\{00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
- Key: CLSID\{2353FCBC-012D-487B-8BF3-865C0929FBEB}
- Key: CLSID\{39D2FC9B-041C-470E-AE72-F8C001247626}
- Key: CLSID\{3FE36807-69ED-45D1-B9BE-85C0E3F75B6A}
- Key: CLSID\{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}
- Key: CLSID\{5D867A01-9CEC-4f2f-8454-AAAB35550396}
- Key: CLSID\{6DD0BC06-4719-4BA3-BEBC-FBAE6A448152}
- Key: CLSID\{7BF451AC-2010-4804-B256-DB2F0A8D9EB6}
- Key: CLSID\{827DC836-DD9F-4A68-A602-5812EB50A834}
- Key: CLSID\{AF7FCAFB-9FDB-4F5E-BAC6-68BDEE61D6C6}
- Key: CLSID\{B313D637-F405-4052-AC37-E2119AB3C8F8}
- Key: CLSID\{B8B55274-0F9A-41E5-9067-A3539BD9E860}
- Key: CLSID\{CBE0D59D-F985-4AC6-8826-FEE957065D42}
- Key: CLSID\{E92F7930-91D9-C259-A3FA-E53B82752190}
- Key: CLSID\{EFDAC3FE-F44A-4030-8589-1E23BC6573D5}
- Key: CLSID\{FC148228-87E1-4D00-AC06-58DCAA52A4D1}
- Key: mfcoptimizeclass.mfcoptimizeclass
- Key: mfcoptimizeclass.mfcoptimizeclass.1
- Key: msevents.msevents
- Key: MSEvents.MSEvents MSEvents Object
- Key: msevents.msevents.1
- Key: MSEvents.MSEvents.1 MSEvents Object
- Key: SOFTWARE\Classes\ATLDistrib.ATLDistrib
- Key: SOFTWARE\Classes\ATLDistrib.ATLDistrib.1
- Key: SOFTWARE\Classes\CLSID\{00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
- Key: SOFTWARE\Classes\CLSID\{2353FCBC-012D-487B-8BF3-865C0929FBEB}
- Key: SOFTWARE\Classes\CLSID\{39D2FC9B-041C-470E-AE72-F8C001247626}
- Key: SOFTWARE\Classes\CLSID\{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}
- Key: SOFTWARE\Classes\CLSID\{6DD0BC06-4719-4BA3-BEBC-FBAE6A448152}
- Key: SOFTWARE\Classes\CLSID\{7BF451AC-2010-4804-B256-DB2F0A8D9EB6}
- Key: SOFTWARE\Classes\CLSID\{827DC836-DD9F-4A68-A602-5812EB50A834}
- Key: SOFTWARE\Classes\CLSID\{AF7FCAFB-9FDB-4F5E-BAC6-68BDEE61D6C6}
- Key: SOFTWARE\Classes\CLSID\{b8b55274-0f9a-41e5-9067-a3539bd9e860}
- Key: SOFTWARE\Classes\CLSID\{CBE0D59D-F985-4AC6-8826-FEE957065D42}
- Key: SOFTWARE\Classes\CLSID\{E92F7930-91D9-C259-A3FA-E53B82752190}
- Key: SOFTWARE\Classes\CLSID\{FC148228-87E1-4D00-AC06-58DCAA52A4D1}
- Key: SOFTWARE\Classes\MSEvents.MSEvents
- Key: SOFTWARE\Classes\MSEvents.MSEvents MSEvents Object
- Key: SOFTWARE\Classes\MSEvents.MSEvents.1
- Key: SOFTWARE\Classes\MSEvents.MSEvents.1 MSEvents Object
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2353FCBC-012D-487B-8BF3-865C0929FBEB}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39D2FC9B-041C-470E-AE72-F8C001247626}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5D867A01-9CEC-4f2f-8454-AAAB35550396}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{659E147E-BD03-4605-988C-AA6D7EA497CA}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6DD0BC06-4719-4BA3-BEBC-FBAE6A448152}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{79A576C4-B7A9-47EC-B57C-2CE5CA6ECC6A}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7BF451AC-2010-4804-B256-DB2F0A8D9EB6}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{827DC836-DD9F-4A68-A602-5812EB50A834}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8DBF02DA-4360-4A7E-BEA1-347B87816327}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF7FCAFB-9FDB-4F5E-BAC6-68BDEE61D6C6}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B313D637-F405-4052-AC37-E2119AB3C8F8}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B8B55274-0F9A-41E5-9067-A3539BD9E860}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CBE0D59D-F985-4AC6-8826-FEE957065D42}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CE70731D-F28D-4D81-9D61-C8EE60378401}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E92F7930-91D9-C259-A3FA-E53B82752190}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EFDAC3FE-F44A-4030-8589-1E23BC6573D5}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FC148228-87E1-4D00-AC06-58DCAA52A4D1}
- Key: Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3}
- Key: Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4484D17-60F6-4048-9FA5-05E3BD39BF9B}
- Key: Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1D02A5FF-BD0A-451B-A795-678970117C9A}
- Key: Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3496D13A-609A-407B-B181-8F47B4F28AE9}
- Key: Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DC04109F-FD9B-48EA-A7A8-D079507AB42C}
- Key: CLSID\{0E24427B-DF2A-40EB-980B-A819F5FF3DD0}\InprocServer32
Value: ThreadingModel
- Key: CLSID\{8E13DDE1-E013-47ec-9C4C-27C2F78BDD26}\InprocServer32
Value: ThreadingModel
- Key: CLSID\{8E13DDE1-E013-47ec-9C4C-27C2F78BDD26}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E13DDE1-E013-47ec-9C4C-27C2F78BDD26}
- Key: Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8E13DDE1-E013-47ec-9C4C-27C2F78BDD26}
- Key: Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8E13DDE1-E013-47ec-9C4C-27C2F78BDD26}\iexplore
Value: Count
- Key: Software\Classes\CLSID\{8E13DDE1-E013-47ec-9C4C-27C2F78BDD26}
- Key: Software\Classes\CLSID\{8E13DDE1-E013-47ec-9C4C-27C2F78BDD26}\InprocServer32
Value: TreadingModel
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\vtstq
Value: DllName
- Key: Software\Microsoft\Windows\CurrentVersion\Explorer\Nrowser Helper Object\{8E13DDE1-E013-47ec-9C4C-27C2F78BDD26}
- Key: CLSID\{1D29C7B8-1B3D-4232-B1EB-CB5B4C83D207}\InprocServer32
Value: ThreadingModel
- Key: CLSID\{1D62D124-13A0-4363-84AF-6F7E620F5CFD}\InprocServer32
Value: ThreadingModel
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Run\f9aadabe.exe
- Key: CLSID\{010FF400-8DFB-439D-987B-DCDE5195F4D8}\InprocServer32
Value: ThreadingModel
- Key: Software\Microsoft\UniqData
- Key: CLSID\{E03C740E-BB24-4d3c-B92A-6F84DE1DD99C}\InprocServer32
Value: ThreadingModel
- Key: Software\Microsoft\Juan
- Key: Software\Classes\CLSID\{010FF400-8DFB-439D-987B-DCDE5195F4D8}
- Key: Software\Classes\CLSID\{010FF400-8DFB-439D-987B-DCDE5195F4D8}\InprocServer32
Value: ThreadingModel
- Key: Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{010FF400-8DFB-439D-987B-DCDE5195F4D8}
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbxwuuv
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winexy32
Value: Shutdown
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winmxw32
Value: Asynchronous
- Key: CLSID\{755FF9F2-E2F1-D314-0CAA-09112272C292}\InprocServer32
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Run\a7c2dabe.exe
- Key: Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{755FF9F2-E2F1-D314-0CAA-09112272C292}
- Key: Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{755FF9F2-E2F1-D314-0CAA-09112272C292}\iexplore
Value: Count
- Key: Software\Classes\CLSID\{755FF9F2-E2F1-D314-0CAA-09112272C292}
- Key: Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{755FF9F2-E2F1-D314-0CAA-09112272C292}
- Key: Software\Classes\CLSID\{5C72B95C-8069-C070-0D3A-05CADFAF1F9B}
- Key: Software\Classes\CLSID\{5C72B95C-8069-C070-0D3A-05CADFAF1F9B}\InprocServer32
Value: ThreadingModel
- Key: CLSID\{5C72B95C-8069-C070-0D3A-05CADFAF1F9B}\InprocServer32
Value: ThreadingModel
- Key: CLSID\{5C72B95C-8069-C070-0D3A-05CADFAF1F9B}
- Key: Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C72B95C-8069-C070-0D3A-05CADFAF1F9B}
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mllmj
Value: DLLName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mllmj
Value: Startup
- Key: software\microsoft\windows nt\currentversion\winlogon\notify\mllmj
Value: dllname
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvvtts
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvvtts
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvvtts
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvvtts
Value: Impersonate
- Key: Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E53D879-BC77-45D7-A447-150129621E73}
Value: dcomcfg.exe
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\geede
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\geede
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\geede
Value: Impersonate
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\geede
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\geede
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrzf32
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrzf32
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrzf32
Value: Impersonate
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrzf32
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrzf32
Value: Shutdown
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\geede
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\geede
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\geede
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\geede
Value: Startup
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\geede
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrzf32
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrzf32
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrzf32
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrzf32
Value: Startup
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrzf32
Value: Shutdown
- Key: Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1DDEA0B1-0E4E-4AC2-8FB2-16615D019582}
Value: defender
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awtqn
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awtqn
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awtqn
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awtqn
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awtqn
Value: Startup
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awtqn
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbxyv
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbxyv
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbxyv
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnmjhe
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnmjhe
Value: Logon
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnmjhe
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbxyv
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbxyv
Value: Startup
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbxyv
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnmjhe
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnmjhe
Value: Logon
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnmjhe
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhe
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhe
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhe
Value: Impersonate
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhe
Value: Logon
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhe
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhe
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhe
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhe
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhe
Value: Logon
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhe
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebyv
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebyv
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebyv
Value: Startup
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebyv
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebyv
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebyv
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebyv
Value: Impersonate
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebyv
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebyv
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvssst
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvssst
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvssst
Value: Impersonate
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvssst
Value: Logon
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvssst
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvssst
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvssst
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvssst
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvssst
Value: Logon
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\tuvssst
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winmmt32
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkhhg
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkhhg
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkhhg
Value: Impersonate
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkhhg
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkhhg
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkhhg
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkhhg
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkhhg
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkhhg
Value: Startup
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkhhg
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhg
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhg
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhg
Value: Impersonate
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhg
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhg
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhg
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhg
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhg
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhg
Value: Startup
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhg
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhi
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhi
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhi
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhi
Value: Startup
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkhi
Value: Logoff
- Key: Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E9BED8F7-00FB-4C35-8BDF-5EAF49D6BB45}
Value: {4D25F926-B9FE-4682-BF72-8AB8210D6D75}
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awtqo
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqpq
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqpq
Value: Impersonate
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqpq
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqpq
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqpq
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winbue32
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebyx
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqom
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqom
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqom
Value: Impersonate
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqom
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqom
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqom
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqom
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqom
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqom
Value: Startup
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqom
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\byvus
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\byvus
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\byvus
Value: Impersonate
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\byvus
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\byvus
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winlvw32
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winlvw32
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winlvw32
Value: Impersonate
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winlvw32
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winlvw32
Value: Shutdown
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\byvus
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\byvus
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\byvus
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\byvus
Value: Startup
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\byvus
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winlvw32
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winlvw32
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winlvw32
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winlvw32
Value: Startup
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winlvw32
Value: Shutdown
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqpm
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqpm
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqpm
Value: Impersonate
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqpm
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqpm
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqpm
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqpm
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqpm
Value: Startup
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqpm
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winldg32
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winldg32
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winldg32
Value: Impersonate
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winldg32
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winldg32
Value: Shutdown
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqpm
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winldg32
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winldg32
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winldg32
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winldg32
Value: Startup
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winldg32
Value: Shutdown
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mljjg
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mljjg
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mljjg
Value: Impersonate
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mljjg
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mljjg
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winexz32
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winexz32
Value: Impersonate
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winexz32
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winexz32
Value: Shutdown
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mljjg
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mljjg
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mljjg
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mljjg
Value: Startup
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mljjg
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winexz32
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winexz32
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winexz32
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winexz32
Value: Startup
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winexz32
Value: Shutdown
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winexz32
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkji
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkji
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkji
Value: Impersonate
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkji
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkji
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winkgg32
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winkgg32
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winkgg32
Value: Impersonate
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winkgg32
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winkgg32
Value: Shutdown
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkji
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkji
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkji
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkji
Value: Startup
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkji
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winkgg32
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winkgg32
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winkgg32
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winkgg32
Value: Startup
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winkgg32
Value: Shutdown
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awvvv
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awvvv
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awvvv
Value: Impersonate
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awvvv
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awvvv
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebyv
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebyv
Value: Logon
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebyv
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awvvv
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awvvv
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awvvv
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awvvv
Value: Startup
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awvvv
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebyv
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebyv
Value: Logon
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebyv
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awtqr
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awtqr
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awtqr
Value: Impersonate
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awtqr
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awtqr
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awtqr
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awtqr
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awtqr
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awtqr
Value: Startup
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awtqr
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winmxw32
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winmxw32
Value: Impersonate
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winmxw32
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winmxw32
Value: Shutdown
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winmxw32
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winmxw32
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winmxw32
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winmxw32
Value: Startup
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winmxw32
Value: Shutdown
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssttq
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssttq
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssttq
Value: Impersonate
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssttq
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssttq
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrkp32
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrkp32
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrkp32
Value: Impersonate
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrkp32
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrkp32
Value: Shutdown
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssttq
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssttq
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssttq
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssttq
Value: Startup
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssttq
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrkp32
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrkp32
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrkp32
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrkp32
Value: Startup
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winrkp32
Value: Shutdown
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\fccabcb
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\fccabcb
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\fccabcb
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\fccabcb
Value: Logon
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\fccabcb
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Value: {0E24427B-DF2A-40EB-980B-A819F5FF3DD0}
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqoomm
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqoomm
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqoomm
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqoomm
Value: Logon
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqoomm
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Value: {8E13DDE1-E013-47ec-9C4C-27C2F78BDD26}
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\vtutt
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\vtutt
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\vtutt
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\vtutt
Value: Logon
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\vtutt
Value: Logoff
- Key: Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8E13DDE1-E013-47ec-9C4C-27C2F78BDD26}\iexplore
Value: Type
- Key: Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8E13DDE1-E013-47ec-9C4C-27C2F78BDD26}\iexplore
Value: Time
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\vtstq
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\vtstq
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\vtstq
Value: Logon
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\vtstq
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnli
Value: DllName
- Key: Software\Microsoft\Internet Explorer\URLSearchHooks
Value: {DCEDF530-38DB-3770-F5AA-601345D83B96}
- Key: Software\Microsoft\Internet Explorer\URLSearchHooks
Value: {4E40F337-6BDB-3173-F3AC-6543B067ABC4}
- Key: Software\Microsoft\Internet Explorer\URLSearchHooks
Value: {976AB789-7337-779B-47F3-70E29A7520C8}
- Key: Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4319425C-80E0-DF4B-CD0A-DF98BD10F690}
Value: {976AB789-7337-779B-47F3-70E29A7520C8}
- Key: Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E40F337-6BDB-3173-F3AC-6543B067ABC4}
Value: {976AB789-7337-779B-47F3-70E29A7520C8}
- Key: Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6BA42B3A-ECDC-ED76-F71B-EB2B569F89C2}
Value: {976AB789-7337-779B-47F3-70E29A7520C8}
- Key: Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{976AB789-7337-779B-47F3-70E29A7520C8}
Value: {976AB789-7337-779B-47F3-70E29A7520C8}
- Key: Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DCEDF530-38DB-3770-F5AA-601345D83B96}
Value: {976AB789-7337-779B-47F3-70E29A7520C8}
- Key: Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35F7813A-AF74-4474-B1DC-7EE6FB6C43C6}
Value: Startup
- Key: Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FB45A990-131B-4741-876C-5B41C297D797}
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mllmj
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mllmj
Value: Impersonate
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mllmj
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mllmj
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mllmj
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mllmj
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvutuvs
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvutuvs
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvutuvs
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvutuvs
Value: Logon
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvutuvs
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winexy32
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winexy32
Value: Impersonate
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winexy32
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winexy32
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\khffebc
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\khffebc
Value: Logon
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\khffebc
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\khffebc
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\khffebc
Value: Asynchronous
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Value: {1D29C7B8-1B3D-4232-B1EB-CB5B4C83D207}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Value: {8E3595C5-6F6D-44B2-BC8B-FA2DAF1EE33C}
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkklkjg
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkklkjg
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkklkjg
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkklkjg
Value: Logon
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkklkjg
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Value: {E8396BDB-A2FD-46C5-8BB1-34C1F7156CDB}
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\khfgefg
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\khfgefg
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\khfgefg
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\khfgefg
Value: Logon
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\khfgefg
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Value: {010FF400-8DFB-439D-987B-DCDE5195F4D8}
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ddcyxyv
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ddcyxyv
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ddcyxyv
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ddcyxyv
Value: Logon
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ddcyxyv
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winwil32
Value: DllName
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winwil32
Value: Impersonate
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winwil32
Value: Startup
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winwil32
Value: Shutdown
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebcywx
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebcywx
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebcywx
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebcywx
Value: Logon
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\gebcywx
Value: Logoff
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Value: {EB56076C-EEB4-4FB9-BE89-04A5B6980A8E}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{E03C740E-BB24-4D3C-B92A-6F84DE1DD99C}\iexplore
Value: Type
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{E03C740E-BB24-4D3C-B92A-6F84DE1DD99C}\iexplore
Value: Count
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{E03C740E-BB24-4D3C-B92A-6F84DE1DD99C}\iexplore
Value: Time
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{158692C3-C204-4BA7-9257-561E5DDE33C3}\iexplore
Value: Type
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{158692C3-C204-4BA7-9257-561E5DDE33C3}\iexplore
Value: Count
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{158692C3-C204-4BA7-9257-561E5DDE33C3}\iexplore
Value: Time
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{46A4E9D9-B30E-452A-8157-DBBEC8573B03}\iexplore
Value: Count
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{46A4E9D9-B30E-452A-8157-DBBEC8573B03}\iexplore
Value: Time
- Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winwil32
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbxwuuv
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbxwuuv
Value: Logon
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbxwuuv
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbxwuuv
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvuturo
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvuturo
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvuturo
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvuturo
Value: Logon
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvuturo
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wineij32
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvuuspo
Value: Asynchronous
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvuuspo
Value: DllName
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvuuspo
Value: Impersonate
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvuuspo
Value: Logon
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvuuspo
Value: Logoff
- Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winhoq32
Value: DllName
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
Value: {2C9E0FF5-9562-4EB6-B405-71F896EB9C08}
- Key: Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{755FF9F2-E2F1-D314-0CAA-09112272C292}\iexplore
Value: Type
- Key: Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{755FF9F2-E2F1-D314-0CAA-09112272C292}\iexplore
Value: Time
Warning: If value is listed for some registry entries, you should only clear these values and leave keys with such values untouched. We recommend you to use Vundo Trojan Removal Tool for safe problem solution.
Here are the descriptions of problems connected with Vundo Trojan and win18.tmp.exe we received earlier:
error could not open module winexi32.rom
Problem Summary: error could not open module winexi32.rom
Upon startup, I get the error message listed above.
Our support has contacted the author of this message, Randy, and helped to solve his problem.
error could not open module winexi32.rom
Problem Summary: error could not open module winexi32.rom
error could not open module winexi32.rom
Our support has contacted the author of this message, killuash, and helped to solve his problem.
winmxw32.rom trojan was removed but runDLL is notifying still
Problem Summary: winmxw32.rom trojan was removed but runDLL is notifying still
when i start my computer with a message:\r\n\"runDLL\r\nthere was a problem starting winmxw32.rom\r\nthe specified module could not be found\".\r\n\r\nwhere to delete the line to stop it?\r\n
Our support has contacted the author of this message, Alex, and helped to solve his problem.
startup error
Problem Summary: startup error
error could not open module winexi32.rom
Our support has contacted the author of this message, Adam Trott, and helped to solve his problem.
winexi32 from specified module could not found
Problem Summary: winexi32 from specified module could not found
winexi32 from specified module could not found
Our support has contacted the author of this message, abdelhak, and helped to solve his problem.
startup error
Problem Summary: startup error
error could not open module winexi32.rom
Our support has contacted the author of this message, Himanshu, and helped to solve his problem.
rundll. error load winrxy32.rom
Problem Summary: rundll. error load winrxy32.rom
rundll. error load winrxy32.rom, i always find this error whenever i boot my computer. it displays when the computer load desktop
Our support has contacted the author of this message, sheharyar, and helped to solve his problem.
error message
Problem Summary: error message
error loading winxnz32.rom \r\nThis message always shows up when i boot my cumputer, How can i fix this problem?
Our support has contacted the author of this message, juan esparza, and helped to solve his problem.
vundo.TE detected and now cannot run .exe, cannot find rundll32.exe
Problem Summary: vundo.TE detected and now cannot run .exe, cannot find rundll32.exe
on Feb 3rd, I think we were hacked. Someone logged in as guest and within the hour F-Protect detected packed\\W32\\Vundo.TE ... Then \'Your PC Protector\' appeared on the desktop. Now, any .exe files look for programs to run them, most control panel items cannot find SYSTEM32\\rundll32.exe, and I cannot run msconfig. Help!
Our support has contacted the author of this message, Linda, and helped to solve his problem.
Getting \
Problem Summary: Getting \
Everytime i start my machine getting this error\r\n\"Error loading winxnz32.rom\". Specific module could not be found.\r\n\r\nPlease help me to resolve this.
Our support has contacted the author of this message, Gopinath, and helped to solve his problem.
error message
Problem Summary: error message
Everytime I switch my computer on. I get an error message with winxnz32. can you tell me how to delete this and what that is?
thankyou
KOYAR
Our support has contacted the author of this message, Koyar, and helped to solve his problem.
the specified module could not be found
Problem Summary: the specified module could not be found
error loading wineij32.rom
the specified module could not be found
Our support has contacted the author of this message, daniel bonilla, and helped to solve his problem.
winubg32.rom
Problem Summary: winubg32.rom
i need to know about this virus. its coming when i boot my laptop.how to delete this.
Our support has contacted the author of this message, R.SARAN, and helped to solve his problem.
Possible virus
Problem Summary: Possible virus
When I turn my laptop, a message in Windows that says \"Error loading winvyl32.rom, Can not find the specified module..\" The file says exactly winvyl32.rom not winwil32.rom as I have seen on other pages. Please help me correct this problem. Thank you. The operating system I have is \"Windows Vista Home Basic\"
Our support has contacted the author of this message, Guillermo Martinez, and helped to solve his problem.
winlvw32.rom
Problem Summary: winlvw32.rom
winlvw32.rom module cannot be found. this message always pop-up whenever i start my pc.
Our support has contacted the author of this message, art, and helped to solve his problem.
Weird Pop-up help
Problem Summary: Weird Pop-up help
everytime i restart my computer, i get a popup with an error message about winmxw32.com. the popup says that it cannot find the file.
how can i resolve this problem?
Our support has contacted the author of this message, Jensen, and helped to solve his problem.
winlvw32.rom
Problem Summary: winlvw32.rom
mensaje de error al iniciar el PC en el que dice que facta el archivo winlvw32.rom
Our support has contacted the author of this message, Francisco Luis Monje Puerto, and helped to solve his problem.
winexz32.rom
Problem Summary: winexz32.rom
When I start my computer, i get this error message saying \"winexz.rom\" cannot be found. How to do get rid of this?
Our support has contacted the author of this message, Simon Pete, and helped to solve his problem.
RunDLL
Problem Summary: RunDLL
X Error loading winwil32.rom
The specified module could not be found.
What is this mean?
Thanks
Our support has contacted the author of this message, roland, and helped to solve his problem.
winmxw32.rom popup
Problem Summary: winmxw32.rom popup
Hi,
everytime i restart my computer, i get a popup with an error message about winmxw32.com. the popup says that it cannot find the file.
how can i resolve this problem?
thank you,
Armelle
Our support has contacted the author of this message, armelle, and helped to solve his problem.
winkgg32.rom is a missing dll file
Problem Summary: winkgg32.rom is a missing dll file
Hi guys,
When i login to windows i get a RunDLL error pop up saying error loading wunkgg32.rom the specified module could not be found. is there a way that i can get rid of this when it pops up.
I am currently running vista ultimate sp1 64bit
Our support has contacted the author of this message, Gene, and helped to solve his problem.
Spyware detected on Your computer
Problem Summary: Spyware detected on Your computer
i am using avast updated on my computer , and spybot search and destroy , and when i search for problems , it told me that i have a Vundo spyware , and its unable to fix it
Our support has contacted the author of this message, Jack Smadi, and helped to solve his problem.
Vundo Trojan Juan
Problem Summary: Vundo Trojan Juan
I keep deleting this vundo trojan but it keeps coming back and starting again.
Our support has contacted the author of this message, ADAM WILTSHIRE, and helped to solve his problem.
This problem often comes with: remove zlob trojan
Next threat: VX2 Tag »
Learn more about Vundo Trojan and win18.tmp.exe »
« Back to catalog
Related topics
People that have problem with vundo-trojan often request this additional information:
Solution: 3410
|