Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Trojan.Siggen9.43162

Added to the Dr.Web virus database: 2020-04-29

Virus description added:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 832145' = '<SYSTEM32>\WScript.exe C:\$Recycle.Bin\S-1-5-21-1960123792-2022915161-3775307078-1001\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 177749' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sdhelp\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 507198' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sdinvoker\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 237052' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sdloader\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 330389' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sdraw\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 889182' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SDTrayApp\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 633886' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SeaMonkey\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 324028' = '<SYSTEM32>\WScript.exe %ProgramFiles%\seccenter\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 918338' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SFAgent\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 828707' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sigtool\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 955204' = '<SYSTEM32>\WScript.exe %ProgramFiles%\simpress\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 190396' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SiteCli\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 78265' = '<SYSTEM32>\WScript.exe %ProgramFiles%\skype\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 321824' = '<SYSTEM32>\WScript.exe %ProgramFiles%\skypePM\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 807150' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SmartFTP\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 890662' = '<SYSTEM32>\WScript.exe %ProgramFiles%\smath\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 459159' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Smc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 984074' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SNDSrvc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 655606' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sniffer\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 89679' = '<SYSTEM32>\WScript.exe %ProgramFiles%\so3d\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 568754' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sched\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 878952' = '<SYSTEM32>\WScript.exe %ProgramFiles%\soffice\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 907190' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ScanningProcess\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 705822' = '<SYSTEM32>\WScript.exe %ProgramFiles%\scalc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 446108' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Realmon\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 746982' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Reference Assemblies\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 320619' = '<SYSTEM32>\WScript.exe %ProgramFiles%\register\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 858436' = '<SYSTEM32>\WScript.exe %ProgramFiles%\removeit\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 406300' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Remover\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 466259' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Rescue\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 613225' = '<SYSTEM32>\WScript.exe %ProgramFiles%\rfwmain\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 879298' = '<SYSTEM32>\WScript.exe %ProgramFiles%\RQ\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 897670' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Rtvscan\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 580286' = '<SYSTEM32>\WScript.exe %ProgramFiles%\RuLaunch\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 756742' = '<SYSTEM32>\WScript.exe %ProgramFiles%\RunSetup\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 241960' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Safari\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 680043' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sarcli\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 872081' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sargui\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 214609' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SAVAdminService\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 118604' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SAVMain\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 549381' = '<SYSTEM32>\WScript.exe %ProgramFiles%\savprogress\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 16266' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SAVScan\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 775461' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sbase\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 228399' = '<SYSTEM32>\WScript.exe %ProgramFiles%\scanner\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 924160' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SPAMCFG\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 486961' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SPBBCSvc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 890782' = '<SYSTEM32>\WScript.exe %ProgramFiles%\spider\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 823470' = '<SYSTEM32>\WScript.exe %ProgramFiles%\tgsvcstp\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 459685' = '<SYSTEM32>\WScript.exe %ProgramFiles%\thebat\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 710645' = '<SYSTEM32>\WScript.exe %ProgramFiles%\THGnard\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 916444' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Thunderbird\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 110510' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Tmas\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 31427' = '<SYSTEM32>\WScript.exe %ProgramFiles%\tmlisten\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 946837' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Tmntsrv\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 603620' = '<SYSTEM32>\WScript.exe %ProgramFiles%\TmPfw\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 768046' = '<SYSTEM32>\WScript.exe %ProgramFiles%\uiscan\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 111726' = '<SYSTEM32>\WScript.exe %ProgramFiles%\tmproxy\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 837177' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Totalcmd\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 988508' = '<SYSTEM32>\WScript.exe %ProgramFiles%\tracelog\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 39337' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Traymon\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 309885' = '<SYSTEM32>\WScript.exe %ProgramFiles%\trillian\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 416639' = '<SYSTEM32>\WScript.exe %ProgramFiles%\TrojanGuarder\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 778689' = '<SYSTEM32>\WScript.exe %ProgramFiles%\TrojanHunter\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 333103' = '<SYSTEM32>\WScript.exe %ProgramFiles%\trtddptr\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 685669' = '<SYSTEM32>\WScript.exe %ProgramFiles%\TwelveSky2\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 563355' = '<SYSTEM32>\WScript.exe %ProgramFiles%\tca\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 810220' = '<SYSTEM32>\WScript.exe %ProgramFiles%\TeaTimer\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 875237' = '<SYSTEM32>\WScript.exe %ProgramFiles%\TBMon\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 312801' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Sysinfo\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 743382' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SymWSC\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 197074' = '<SYSTEM32>\WScript.exe %ProgramFiles%\spidernt\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 448736' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Spiderui\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 913904' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sporder\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 295437' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SpybotSD\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 507223' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sro_client\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 740211' = '<SYSTEM32>\WScript.exe %ProgramFiles%\start_diag\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 623706' = '<SYSTEM32>\WScript.exe %ProgramFiles%\stopsignav\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 663346' = '<SYSTEM32>\WScript.exe %ProgramFiles%\StreetsOlkShim\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 328483' = '<SYSTEM32>\WScript.exe %ProgramFiles%\rcimlby\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 753050' = '<SYSTEM32>\WScript.exe %ProgramFiles%\svcntaux\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 161554' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SubmitFiles\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 93834' = '<SYSTEM32>\WScript.exe %ProgramFiles%\swdoctor\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 272675' = '<SYSTEM32>\WScript.exe %ProgramFiles%\swdsvc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 461922' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sweb\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 904375' = '<SYSTEM32>\WScript.exe %ProgramFiles%\swriter\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 983937' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SymantecRootInstaller\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 211986' = '<SYSTEM32>\WScript.exe %ProgramFiles%\symlcsvc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 65131' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SymProxySvc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 81321' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SymSPort\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 840145' = '<SYSTEM32>\WScript.exe %ProgramFiles%\spiderml\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 907700' = '<SYSTEM32>\WScript.exe %ProgramFiles%\swAgent\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 89546' = '<SYSTEM32>\WScript.exe %ProgramFiles%\tnbutil\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 975053' = '<SYSTEM32>\WScript.exe %ProgramFiles%\RavTimer\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 228884' = '<SYSTEM32>\WScript.exe %ProgramFiles%\qhwscsvc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 813004' = '<SYSTEM32>\WScript.exe %ProgramFiles%\oget\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 919854' = '<SYSTEM32>\WScript.exe %ProgramFiles%\olAddin\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 106323' = '<SYSTEM32>\WScript.exe %ProgramFiles%\OnAccessInstaller\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 213358' = '<SYSTEM32>\WScript.exe %ProgramFiles%\opera\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 330426' = '<SYSTEM32>\WScript.exe %ProgramFiles%\osCheck\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 352207' = '<SYSTEM32>\WScript.exe %ProgramFiles%\outlook\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 105406' = '<SYSTEM32>\WScript.exe %ProgramFiles%\outpost\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 577682' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PartIn\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 402738' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PartIn9x\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 889423' = '<SYSTEM32>\WScript.exe %ProgramFiles%\partinfo\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 481309' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PartInNT\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 737328' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PavFires\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 311738' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PavFnSvr\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 248602' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Pavkre\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 395224' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PavProt\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 271215' = '<SYSTEM32>\WScript.exe %ProgramFiles%\pavProxy\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 133172' = '<SYSTEM32>\WScript.exe %ProgramFiles%\pavprsrv\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 765012' = '<SYSTEM32>\WScript.exe %ProgramFiles%\pavsrv51\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 153855' = '<SYSTEM32>\WScript.exe %ProgramFiles%\pccguide\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 800789' = '<SYSTEM32>\WScript.exe %ProgramFiles%\OfcPfwSvc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 321738' = '<SYSTEM32>\WScript.exe %ProgramFiles%\pccntmon\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 77749' = '<SYSTEM32>\WScript.exe %ProgramFiles%\oaui\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 96993' = '<SYSTEM32>\WScript.exe %ProgramFiles%\NWService\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 571298' = '<SYSTEM32>\WScript.exe %ProgramFiles%\nisoptui\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 394667' = '<SYSTEM32>\WScript.exe %ProgramFiles%\nod\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 120299' = '<SYSTEM32>\WScript.exe %ProgramFiles%\nod32\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 793685' = '<SYSTEM32>\WScript.exe %ProgramFiles%\nod32krn\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 910183' = '<SYSTEM32>\WScript.exe %ProgramFiles%\nod32kui\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 88216' = '<SYSTEM32>\WScript.exe %ProgramFiles%\NotifyHA\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 159038' = '<SYSTEM32>\WScript.exe %ProgramFiles%\notstart\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 569313' = '<SYSTEM32>\WScript.exe %ProgramFiles%\npavtray\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 157764' = '<SYSTEM32>\WScript.exe %ProgramFiles%\npfmsg\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 872085' = '<SYSTEM32>\WScript.exe %ProgramFiles%\NSMdtr\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 477597' = '<SYSTEM32>\WScript.exe %ProgramFiles%\NssServ\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 853138' = '<SYSTEM32>\WScript.exe %ProgramFiles%\NssTray\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 837783' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ntoskrnl\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 487546' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ntrtscan\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 914660' = '<SYSTEM32>\WScript.exe %ProgramFiles%\NTXconfig\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 941608' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Nupgrade\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 623396' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Nvcod\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 227630' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Nvcte\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 653636' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Nvcut\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 290300' = '<SYSTEM32>\WScript.exe %ProgramFiles%\oasrv\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 252355' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PCCPFW\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 845208' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PcCtlCom\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 850036' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PCTAV\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 18566' = '<SYSTEM32>\WScript.exe %ProgramFiles%\pshost\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 657661' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PsImSvc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 829425' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PXAgent\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 234483' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PXConsole\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 695762' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PXL\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 970065' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PXL1\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 110231' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PXReset\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 988012' = '<SYSTEM32>\WScript.exe %ProgramFiles%\pxsupport\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 652775' = '<SYSTEM32>\WScript.exe %ProgramFiles%\RAT\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 897331' = '<SYSTEM32>\WScript.exe %ProgramFiles%\python\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 993198' = '<SYSTEM32>\WScript.exe %ProgramFiles%\qip\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 610839' = '<SYSTEM32>\WScript.exe %ProgramFiles%\qklez\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 463665' = '<SYSTEM32>\WScript.exe %ProgramFiles%\qrtfix\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 475439' = '<SYSTEM32>\WScript.exe %ProgramFiles%\quaranti\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 666864' = '<SYSTEM32>\WScript.exe %ProgramFiles%\quickstart\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 599850' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Ragexe\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 716603' = '<SYSTEM32>\WScript.exe %ProgramFiles%\RagFree\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 306714' = '<SYSTEM32>\WScript.exe %ProgramFiles%\rapget\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 904626' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ps\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 26214' = '<SYSTEM32>\WScript.exe %ProgramFiles%\psctrls\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 602890' = '<SYSTEM32>\WScript.exe %ProgramFiles%\protect\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 241168' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ProcessViewer\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 633898' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PrivateBrowser\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 129797' = '<SYSTEM32>\WScript.exe %ProgramFiles%\pidgin\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 670159' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PM\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 253358' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PM8Flash\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 78405' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PMagic\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 316828' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PMagic9x\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 148372' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PMagicBT\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 950798' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PMagicNT\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 839846' = '<SYSTEM32>\WScript.exe %ProgramFiles%\POLUTIL\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 452909' = '<SYSTEM32>\WScript.exe %ProgramFiles%\RavMon\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 119021' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ppfw\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 721224' = '<SYSTEM32>\WScript.exe %ProgramFiles%\postinstall\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 634769' = '<SYSTEM32>\WScript.exe %ProgramFiles%\pqbw\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 122832' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PqPe\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 805067' = '<SYSTEM32>\WScript.exe %ProgramFiles%\pqpe9x\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 256592' = '<SYSTEM32>\WScript.exe %ProgramFiles%\pqpent\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 594827' = '<SYSTEM32>\WScript.exe %ProgramFiles%\preconfig\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 939193' = '<SYSTEM32>\WScript.exe %ProgramFiles%\preupd\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 516385' = '<SYSTEM32>\WScript.exe %ProgramFiles%\prevsrv\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 891436' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PrevxSetup\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 672894' = '<SYSTEM32>\WScript.exe %ProgramFiles%\pertsk\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 737337' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Pqboot32\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 538187' = '<SYSTEM32>\WScript.exe %ProgramFiles%\una\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 863444' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Uninstall Information\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 918131' = '<SYSTEM32>\WScript.exe %ProgramFiles%\UninstallCAVS\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 599922' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Oracle\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 792192' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Package Cache\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 477529' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Start Menu\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 72581' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Sun\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 21739' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Templates\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 908821' = '<SYSTEM32>\WScript.exe C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 749682' = '<SYSTEM32>\WScript.exe C:\totalcmd\LANGUAGE\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 424273' = '<SYSTEM32>\WScript.exe C:\Users\All Users\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 758484' = '<SYSTEM32>\WScript.exe %WINDIR%\Cursors\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 649706' = '<SYSTEM32>\WScript.exe C:\Users\Default\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 240401' = '<SYSTEM32>\WScript.exe C:\Users\Public\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 92985' = '<SYSTEM32>\WScript.exe %HOMEPATH%\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 470963' = '<SYSTEM32>\WScript.exe %WINDIR%\addins\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 717340' = '<SYSTEM32>\WScript.exe %WINDIR%\AppCompat\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 274779' = '<SYSTEM32>\WScript.exe %WINDIR%\AppPatch\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 400251' = '<SYSTEM32>\WScript.exe %WINDIR%\assembly\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 567965' = '<SYSTEM32>\WScript.exe %WINDIR%\BitLockerDiscoveryVolumeContents\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 619936' = '<SYSTEM32>\WScript.exe %WINDIR%\Branding\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 911617' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Microsoft Toolkit\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 116751' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Mozilla\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 413288' = '<SYSTEM32>\WScript.exe C:\Users\Default User\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 236179' = '<SYSTEM32>\WScript.exe %WINDIR%\CSC\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 661916' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Favorites\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 443048' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Pidgin\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 94479' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\QIP 2012\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 700672' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Reference Assemblies\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 138136' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Steam\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 245116' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Uninstall Information\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 103559' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Winamp\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 677585' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Windows Defender\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 444947' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Windows Mail\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 862038' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Windows Media Player\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 890733' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Windows NT\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 652243' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Windows Photo Viewer\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 762427' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Windows Portable Devices\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 435232' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Windows Sidebar\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 844247' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Adobe\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 22413' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Application Data\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 209779' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Desktop\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 669593' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Documents\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 257150' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Microsoft\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 941903' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\MSBuild\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 692336' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Microsoft Help\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 528970' = '<SYSTEM32>\WScript.exe %WINDIR%\Web\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 15969' = '<SYSTEM32>\WScript.exe %WINDIR%\debug\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 540971' = '<SYSTEM32>\WScript.exe %WINDIR%\RemotePackages\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 45720' = '<SYSTEM32>\WScript.exe %WINDIR%\SchCache\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 563626' = '<SYSTEM32>\WScript.exe %WINDIR%\schemas\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 274251' = '<SYSTEM32>\WScript.exe %WINDIR%\security\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 36845' = '<SYSTEM32>\WScript.exe %WINDIR%\ServiceProfiles\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 3154' = '<SYSTEM32>\WScript.exe %WINDIR%\Setup\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 529459' = '<SYSTEM32>\WScript.exe %WINDIR%\ShellNew\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 112348' = '<SYSTEM32>\WScript.exe %WINDIR%\SoftwareDistribution\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 565767' = '<SYSTEM32>\WScript.exe %WINDIR%\Speech\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 957809' = '<SYSTEM32>\WScript.exe %WINDIR%\DigitalLocker\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 536748' = '<SYSTEM32>\WScript.exe %WINDIR%\system\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 831201' = '<SYSTEM32>\WScript.exe %WINDIR%\SysWOW64\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 909451' = '<SYSTEM32>\WScript.exe %WINDIR%\TAPI\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 254962' = '<SYSTEM32>\WScript.exe %WINDIR%\Tasks\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 665146' = '<SYSTEM32>\WScript.exe %WINDIR%\Temp\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 531946' = '<SYSTEM32>\WScript.exe %WINDIR%\tracing\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 326992' = '<SYSTEM32>\WScript.exe %WINDIR%\twain_32\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 693014' = '<SYSTEM32>\WScript.exe %WINDIR%\Vss\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 574573' = '<SYSTEM32>\WScript.exe %WINDIR%\Registration\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 92120' = '<SYSTEM32>\WScript.exe %WINDIR%\Prefetch\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 88004' = '<SYSTEM32>\WScript.exe %WINDIR%\Resources\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 805855' = '<SYSTEM32>\WScript.exe %WINDIR%\PolicyDefinitions\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 696137' = '<SYSTEM32>\WScript.exe %WINDIR%\PLA\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 426906' = '<SYSTEM32>\WScript.exe %WINDIR%\Downloaded Program Files\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 160739' = '<SYSTEM32>\WScript.exe %WINDIR%\en-US\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 756165' = '<SYSTEM32>\WScript.exe %WINDIR%\Fonts\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 583839' = '<SYSTEM32>\WScript.exe %WINDIR%\Globalization\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 946460' = '<SYSTEM32>\WScript.exe %WINDIR%\Help\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 259172' = '<SYSTEM32>\WScript.exe %WINDIR%\IME\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 306814' = '<SYSTEM32>\WScript.exe %WINDIR%\inf\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 644051' = '<SYSTEM32>\WScript.exe %WINDIR%\Installer\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 269196' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Mozilla Thunderbird\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 879351' = '<SYSTEM32>\WScript.exe %WINDIR%\L2Schemas\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 868301' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Opera\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 496291' = '<SYSTEM32>\WScript.exe %WINDIR%\Logs\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 725759' = '<SYSTEM32>\WScript.exe %WINDIR%\Microsoft.NET\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 494028' = '<SYSTEM32>\WScript.exe %WINDIR%\Migration\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 383984' = '<SYSTEM32>\WScript.exe %WINDIR%\ModemLogs\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 567326' = '<SYSTEM32>\WScript.exe %WINDIR%\Offline Web Pages\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 145169' = '<SYSTEM32>\WScript.exe %WINDIR%\Panther\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 965534' = '<SYSTEM32>\WScript.exe %WINDIR%\PCHEALTH\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 30256' = '<SYSTEM32>\WScript.exe %WINDIR%\Performance\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 369922' = '<SYSTEM32>\WScript.exe %WINDIR%\LiveKernelReports\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 823265' = '<SYSTEM32>\WScript.exe %WINDIR%\ehome\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 760433' = '<SYSTEM32>\WScript.exe %WINDIR%\Media\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 49767' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Mozilla Firefox\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 416632' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\mIRC\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 36714' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Microsoft.NET\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 598646' = '<SYSTEM32>\WScript.exe %ProgramFiles%\VisthLic\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 586305' = '<SYSTEM32>\WScript.exe %ProgramFiles%\VisthUpd\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 974339' = '<SYSTEM32>\WScript.exe %ProgramFiles%\vrfwsvc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 194699' = '<SYSTEM32>\WScript.exe %ProgramFiles%\vrmonsvc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 67738' = '<SYSTEM32>\WScript.exe %ProgramFiles%\vrrw32\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 783764' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Vshwin32\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 817755' = '<SYSTEM32>\WScript.exe %ProgramFiles%\vsmon\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 607079' = '<SYSTEM32>\WScript.exe %ProgramFiles%\vsserv\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 252716' = '<SYSTEM32>\WScript.exe %ProgramFiles%\VsStat\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 212473' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Wclose\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 830699' = '<SYSTEM32>\WScript.exe %ProgramFiles%\webfiltr\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 921029' = '<SYSTEM32>\WScript.exe %ProgramFiles%\WebMoney\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 502517' = '<SYSTEM32>\WScript.exe %ProgramFiles%\WebProxy\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 138119' = '<SYSTEM32>\WScript.exe %ProgramFiles%\WebScanX\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 278614' = '<SYSTEM32>\WScript.exe %ProgramFiles%\wil\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 152723' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Winaw32\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 331118' = '<SYSTEM32>\WScript.exe %ProgramFiles%\winbaram\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 718670' = '<SYSTEM32>\WScript.exe %ProgramFiles%\VirusKeeper\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 385925' = '<SYSTEM32>\WScript.exe %ProgramFiles%\viritexp\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 946034' = '<SYSTEM32>\WScript.exe %ProgramFiles%\VistAux\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 708414' = '<SYSTEM32>\WScript.exe %ProgramFiles%\viritsvc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 942335' = '<SYSTEM32>\WScript.exe %ProgramFiles%\VetTray\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 303734' = '<SYSTEM32>\WScript.exe %ProgramFiles%\UPSObMaker\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 203101' = '<SYSTEM32>\WScript.exe %ProgramFiles%\UninstallLSP\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 384573' = '<SYSTEM32>\WScript.exe %ProgramFiles%\unoinfo\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 57137' = '<SYSTEM32>\WScript.exe %ProgramFiles%\unopkg\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 576005' = '<SYSTEM32>\WScript.exe %ProgramFiles%\unp_test\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 847220' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Up2Date\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 237615' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Updater\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 391810' = '<SYSTEM32>\WScript.exe %ProgramFiles%\UpdaterUI\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 140589' = '<SYSTEM32>\WScript.exe %ProgramFiles%\updclient\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 331271' = '<SYSTEM32>\WScript.exe %ProgramFiles%\wincmd32\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 180003' = '<SYSTEM32>\WScript.exe %ProgramFiles%\netxray\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 697658' = '<SYSTEM32>\WScript.exe %ProgramFiles%\upgrepl\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 599433' = '<SYSTEM32>\WScript.exe %ProgramFiles%\UUpd\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 400470' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Vba32ECM\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 207260' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Vba32ifs\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 94691' = '<SYSTEM32>\WScript.exe %ProgramFiles%\vba32ldr\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 696496' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Vba32PP3\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 536285' = '<SYSTEM32>\WScript.exe %ProgramFiles%\VBSNTW\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 768809' = '<SYSTEM32>\WScript.exe %ProgramFiles%\vchk\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 753061' = '<SYSTEM32>\WScript.exe %ProgramFiles%\vcrmon\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 850200' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Uninstaller\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 591157' = '<SYSTEM32>\WScript.exe %ProgramFiles%\USDownloader\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 196631' = '<SYSTEM32>\WScript.exe %ProgramFiles%\winss\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 912294' = '<SYSTEM32>\WScript.exe %ProgramFiles%\WindowList\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 796008' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Windows Media Player\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 206664' = '<SYSTEM32>\WScript.exe %ProgramFiles%\YahooSync\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 811871' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ybclient\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 961278' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Ymsgr_tray\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 805477' = '<SYSTEM32>\WScript.exe %ProgramFiles%\zapro\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 833122' = '<SYSTEM32>\WScript.exe %ProgramFiles%\zatutor\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 756962' = '<SYSTEM32>\WScript.exe %ProgramFiles%\zauninst\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 902618' = '<SYSTEM32>\WScript.exe %ProgramFiles%\zlclient\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 942237' = '<SYSTEM32>\WScript.exe %ProgramFiles%\VirusNews\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 901624' = '<SYSTEM32>\WScript.exe %ProgramFiles%\zonealarm\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 935271' = '<SYSTEM32>\WScript.exe %CommonProgramFiles(x86)%\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 273206' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Google\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 323305' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Internet Explorer\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 418797' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\K-Lite Codec Pack\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 82457' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Microsoft Analysis Services\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 178573' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Microsoft Office\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 816432' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Microsoft Visual Studio .NET 2003\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 561730' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Microsoft Visual Studio 8\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 513757' = '<SYSTEM32>\WScript.exe %ProgramFiles%\wsm\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 34183' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Adobe\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 633681' = '<SYSTEM32>\WScript.exe %ProgramFiles%\YahooMessenger\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 895415' = '<SYSTEM32>\WScript.exe %ProgramFiles%\xcommsvr\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 496058' = '<SYSTEM32>\WScript.exe %ProgramFiles%\wsftpgui\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 1653' = '<SYSTEM32>\WScript.exe %ProgramFiles%\wsctool\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 669389' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Windows NT\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 74574' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Windows Photo Viewer\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 720531' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Windows Portable Devices\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 385628' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Windows Sidebar\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 18938' = '<SYSTEM32>\WScript.exe %ProgramFiles%\windump\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 920704' = '<SYSTEM32>\WScript.exe %ProgramFiles%\WinMail\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 747816' = '<SYSTEM32>\WScript.exe %ProgramFiles%\WinRAR\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 862279' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Windows Defender\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 856752' = '<SYSTEM32>\WScript.exe %ProgramFiles%\winroute\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 620660' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Windows Journal\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 864433' = '<SYSTEM32>\WScript.exe %ProgramFiles%\winssnotify\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 682829' = '<SYSTEM32>\WScript.exe %ProgramFiles%\WLLoginProxy\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 594618' = '<SYSTEM32>\WScript.exe %ProgramFiles%\wlmail\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 291808' = '<SYSTEM32>\WScript.exe %ProgramFiles%\wltuser\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 840071' = '<SYSTEM32>\WScript.exe %ProgramFiles%\woool\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 463287' = '<SYSTEM32>\WScript.exe %ProgramFiles%\wow\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 227122' = '<SYSTEM32>\WScript.exe %ProgramFiles%\WrAdmin\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 722666' = '<SYSTEM32>\WScript.exe %ProgramFiles%\WrCtrl\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 458005' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Windows Mail\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 812390' = '<SYSTEM32>\WScript.exe %ProgramFiles%\writespid\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 736210' = '<SYSTEM32>\WScript.exe %ProgramFiles%\wish\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 817591' = '<SYSTEM32>\WScript.exe <SYSTEM32>\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 539296' = '<SYSTEM32>\WScript.exe %ProgramFiles%\NetstatViewer\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 994972' = '<SYSTEM32>\WScript.exe %ProgramFiles%\MVC\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 942073' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CavQ\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 394464' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CAVSCons\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 597045' = '<SYSTEM32>\WScript.exe %ProgramFiles%\cavse\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 497542' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CavSn\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 708831' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CavSub\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 24121' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CAVSubmit\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 168279' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CavUMAS\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 653225' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CavUserUpd\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 883628' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Cavvl\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 824192' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ccapp\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 44677' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ccEvtMgr\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 444196' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CCleaner\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 500217' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ccProxy\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 255919' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ccSetMgr\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 155012' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CEmRep\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 146639' = '<SYSTEM32>\WScript.exe %ProgramFiles%\chrome\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 542545' = '<SYSTEM32>\WScript.exe %ProgramFiles%\clamscan\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 929960' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ClamTray\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 979812' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ClamWin\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 717565' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Cavoar\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 381465' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Claw95\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 63336' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CavMUD\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 734172' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CavEmSrv\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 504297' = '<SYSTEM32>\WScript.exe %ProgramFiles%\bdmcon\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 150846' = '<SYSTEM32>\WScript.exe %ProgramFiles%\bdnews\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 686236' = '<SYSTEM32>\WScript.exe %ProgramFiles%\bdoesrv\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 92455' = '<SYSTEM32>\WScript.exe %ProgramFiles%\bdss\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 524129' = '<SYSTEM32>\WScript.exe %ProgramFiles%\bdsubmit\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 215618' = '<SYSTEM32>\WScript.exe %ProgramFiles%\bdsubmitwiz\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 369118' = '<SYSTEM32>\WScript.exe %ProgramFiles%\BDSurvey\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 662218' = '<SYSTEM32>\WScript.exe %ProgramFiles%\bdswitch\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 209614' = '<SYSTEM32>\WScript.exe %ProgramFiles%\bdwizreg\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 224836' = '<SYSTEM32>\WScript.exe %ProgramFiles%\blackd\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 394441' = '<SYSTEM32>\WScript.exe %ProgramFiles%\blackice\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 677313' = '<SYSTEM32>\WScript.exe %ProgramFiles%\blindman\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 141136' = '<SYSTEM32>\WScript.exe %ProgramFiles%\BTIni\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 749851' = '<SYSTEM32>\WScript.exe %ProgramFiles%\BTIniNT\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 110655' = '<SYSTEM32>\WScript.exe %ProgramFiles%\cabalmain\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 904891' = '<SYSTEM32>\WScript.exe %ProgramFiles%\cafix\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 579741' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CavApp\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 320021' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CaVasm\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 992187' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CavAUD\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 920267' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Cavmr\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 960381' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Claw95cf\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 559511' = '<SYSTEM32>\WScript.exe %ProgramFiles%\cleaner\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 691992' = '<SYSTEM32>\WScript.exe %ProgramFiles%\cleaner3\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 220968' = '<SYSTEM32>\WScript.exe %ProgramFiles%\DrVirus\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 506020' = '<SYSTEM32>\WScript.exe %ProgramFiles%\DrvMap\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 417650' = '<SYSTEM32>\WScript.exe %ProgramFiles%\drwadins\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 569906' = '<SYSTEM32>\WScript.exe %ProgramFiles%\drweb\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 889200' = '<SYSTEM32>\WScript.exe %ProgramFiles%\drweb32w\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 290630' = '<SYSTEM32>\WScript.exe %ProgramFiles%\drweb386\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 945900' = '<SYSTEM32>\WScript.exe %ProgramFiles%\drwebscd\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 588915' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Drwebupw\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 918032' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ewidoctrl\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 270892' = '<SYSTEM32>\WScript.exe %ProgramFiles%\drwebwcl\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 28093' = '<SYSTEM32>\WScript.exe %ProgramFiles%\DVD Maker\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 246876' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ecmd\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 833388' = '<SYSTEM32>\WScript.exe %ProgramFiles%\egni\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 32774' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ehsniffer\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 495346' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ekrn\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 112939' = '<SYSTEM32>\WScript.exe %ProgramFiles%\elementclient\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 681731' = '<SYSTEM32>\WScript.exe %ProgramFiles%\etherd\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 398145' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Eudora\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 460861' = '<SYSTEM32>\WScript.exe %ProgramFiles%\dpatrolq\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 74795' = '<SYSTEM32>\WScript.exe %ProgramFiles%\drvctl\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 948892' = '<SYSTEM32>\WScript.exe %ProgramFiles%\dnf\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 670919' = '<SYSTEM32>\WScript.exe %ProgramFiles%\dislite\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 364508' = '<SYSTEM32>\WScript.exe %ProgramFiles%\DirectFTP\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 934937' = '<SYSTEM32>\WScript.exe %ProgramFiles%\clrcche\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 163430' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CMain\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 547470' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CMGrdian\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 374292' = '<SYSTEM32>\WScript.exe %CommonProgramFiles%\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 394498' = '<SYSTEM32>\WScript.exe %ProgramFiles%\copyx64\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 519367' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Courier\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 525801' = '<SYSTEM32>\WScript.exe %ProgramFiles%\cpd\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 550872' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CSendTo\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 307317' = '<SYSTEM32>\WScript.exe %ProgramFiles%\bdagent\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 866885' = '<SYSTEM32>\WScript.exe %ProgramFiles%\custinstall\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 780042' = '<SYSTEM32>\WScript.exe %ProgramFiles%\cssexc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 503243' = '<SYSTEM32>\WScript.exe %ProgramFiles%\cuteftp\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 60868' = '<SYSTEM32>\WScript.exe %ProgramFiles%\DBConvert\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 860587' = '<SYSTEM32>\WScript.exe %ProgramFiles%\DBTool\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 981147' = '<SYSTEM32>\WScript.exe %ProgramFiles%\defensewall\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 247823' = '<SYSTEM32>\WScript.exe %ProgramFiles%\DefWatch\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 223' = '<SYSTEM32>\WScript.exe %ProgramFiles%\dekaron\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 773237' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Digsby\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 301057' = '<SYSTEM32>\WScript.exe %ProgramFiles%\digsby-app\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 692437' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CliSvc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 220795' = '<SYSTEM32>\WScript.exe %ProgramFiles%\custsetup\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 79394' = '<SYSTEM32>\WScript.exe %ProgramFiles%\drwreg\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 295198' = '<SYSTEM32>\WScript.exe %ProgramFiles%\BackWeb-4476822\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 821160' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgwizfw\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 95185' = '<SYSTEM32>\WScript.exe %ProgramFiles%\AhnSD\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 308480' = '<SYSTEM32>\WScript.exe %ProgramFiles%\aim6\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 47438' = '<SYSTEM32>\WScript.exe %ProgramFiles%\aimpro\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 631530' = '<SYSTEM32>\WScript.exe %ProgramFiles%\airdefense\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 663862' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ALMon\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 650545' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ALsvc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 126959' = '<SYSTEM32>\WScript.exe %ProgramFiles%\amon\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 325830' = '<SYSTEM32>\WScript.exe %ProgramFiles%\amsn\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 32378' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Anti-Trojan\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 440748' = '<SYSTEM32>\WScript.exe %ProgramFiles%\AntiVirus\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 319093' = '<SYSTEM32>\WScript.exe %ProgramFiles%\AolTbServer\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 311195' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Armor2net\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 640980' = '<SYSTEM32>\WScript.exe %ProgramFiles%\armorsurf\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 170851' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ash\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 711060' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashAvast\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 638467' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashAvSrv\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 399640' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashchest\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 923434' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashDisp\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 617618' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashDug\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 354210' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ageofconan\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 675873' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashEnhcd\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 267726' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Agb5\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 27701' = '<SYSTEM32>\WScript.exe %ProgramFiles%\AckWin32\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 134304' = '<SYSTEM32>\WScript.exe C:\Far2\Addons\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 33347' = '<SYSTEM32>\WScript.exe C:\Far2\Documentation\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 783666' = '<SYSTEM32>\WScript.exe C:\Far2\Encyclopedia\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 377863' = '<SYSTEM32>\WScript.exe C:\Far2\FExcept\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 497311' = '<SYSTEM32>\WScript.exe C:\Far2\Plugins\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 120352' = '<SYSTEM32>\WScript.exe C:\Far2\PluginSDK\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 244575' = '<SYSTEM32>\WScript.exe C:\MSOCache\All Users\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 79364' = '<SYSTEM32>\WScript.exe C:\PerfLogs\Admin\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 390122' = '<SYSTEM32>\WScript.exe %ProgramFiles%\360tray\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 699975' = '<SYSTEM32>\WScript.exe %ProgramFiles%\a2cmd\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 981535' = '<SYSTEM32>\WScript.exe %ProgramFiles%\a2guard\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 690995' = '<SYSTEM32>\WScript.exe %ProgramFiles%\a2HiJackFree\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 337700' = '<SYSTEM32>\WScript.exe %ProgramFiles%\a2scan\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 759827' = '<SYSTEM32>\WScript.exe %ProgramFiles%\a2service\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 344215' = '<SYSTEM32>\WScript.exe %ProgramFiles%\a2start\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 226244' = '<SYSTEM32>\WScript.exe %ProgramFiles%\a2upd\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 112080' = '<SYSTEM32>\WScript.exe %ProgramFiles%\a2wizard\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 546307' = '<SYSTEM32>\WScript.exe %ProgramFiles%\aavshield\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 905920' = '<SYSTEM32>\WScript.exe %ProgramFiles%\About\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 497991' = '<SYSTEM32>\WScript.exe %ProgramFiles%\AdMunch\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 266184' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashLogV\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 637522' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashMaiSv\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 784190' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashPopWz\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 952583' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avginet\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 8747' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgnpdln\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 129255' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgnpsvc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 838228' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgrssvc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 687321' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgscan\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 649502' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgupden\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 922078' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgupsvc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 564495' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgvv\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 47274' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avsynmgr\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 444311' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgw\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 329224' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avinitnt\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 826701' = '<SYSTEM32>\WScript.exe %ProgramFiles%\AvkServ\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 456767' = '<SYSTEM32>\WScript.exe %ProgramFiles%\AVKService\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 636575' = '<SYSTEM32>\WScript.exe %ProgramFiles%\AVKWCtl\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 574630' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avnotify\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 265530' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avpcc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 865132' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avpm\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 486921' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avscan\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 938730' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgemc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 371471' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgfwsrv\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 48737' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgdiag\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 585981' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgcc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 361429' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgamsvr\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 74413' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashServ\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 624213' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashsimp2\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 839987' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashSimpl\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 534645' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashSkPcc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 612229' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashSkPck\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 332297' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashUpd\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 1134' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashWebSv\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 445002' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ash_UpdateMediator\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 26553' = '<SYSTEM32>\WScript.exe %ProgramFiles%\B2\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 363887' = '<SYSTEM32>\WScript.exe %ProgramFiles%\aswUpdSv\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 949763' = '<SYSTEM32>\WScript.exe %ProgramFiles%\aswRegSvr\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 274720' = '<SYSTEM32>\WScript.exe %ProgramFiles%\AutostartExplorer\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 17494' = '<SYSTEM32>\WScript.exe %ProgramFiles%\AutoTrace\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 740039' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avadmin\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 407303' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avcenter\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 838313' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avciman\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 434380' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avcmd\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 416382' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avconfig\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 847270' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Avconsol\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 499643' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashQuick\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 23796' = '<SYSTEM32>\WScript.exe %ProgramFiles%\AutoDown\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 538485' = '<SYSTEM32>\WScript.exe %ProgramFiles%\exit_av\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 574283' = '<SYSTEM32>\WScript.exe %ProgramFiles%\EzAntivirusRegistrationCheck\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 462922' = '<SYSTEM32>\WScript.exe %ProgramFiles%\F-Sched\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 999594' = '<SYSTEM32>\WScript.exe %ProgramFiles%\iTunes\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 354467' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Java\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 69329' = '<SYSTEM32>\WScript.exe %ProgramFiles%\k-meleon\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 773805' = '<SYSTEM32>\WScript.exe %ProgramFiles%\KAV\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 550696' = '<SYSTEM32>\WScript.exe %ProgramFiles%\kavmm\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 236562' = '<SYSTEM32>\WScript.exe %ProgramFiles%\KAVPF\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 66844' = '<SYSTEM32>\WScript.exe %ProgramFiles%\KavPFW\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 99863' = '<SYSTEM32>\WScript.exe %ProgramFiles%\KAVStart\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 443846' = '<SYSTEM32>\WScript.exe %ProgramFiles%\LuConfig\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 866710' = '<SYSTEM32>\WScript.exe %ProgramFiles%\KAVSvc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 956376' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Launcher\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 238151' = '<SYSTEM32>\WScript.exe %ProgramFiles%\licmgr\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 281192' = '<SYSTEM32>\WScript.exe %ProgramFiles%\livesrv\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 174469' = '<SYSTEM32>\WScript.exe %ProgramFiles%\LiveUpdate\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 364940' = '<SYSTEM32>\WScript.exe %ProgramFiles%\LogWatNT\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 370126' = '<SYSTEM32>\WScript.exe %ProgramFiles%\lotroclient\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 62271' = '<SYSTEM32>\WScript.exe %ProgramFiles%\lpfw\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 550227' = '<SYSTEM32>\WScript.exe %ProgramFiles%\LUCallbackProxy\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 107325' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ISSVC\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 766994' = '<SYSTEM32>\WScript.exe %ProgramFiles%\isUAC\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 655953' = '<SYSTEM32>\WScript.exe %ProgramFiles%\konnekt\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 330682' = '<SYSTEM32>\WScript.exe %ProgramFiles%\LUCheck\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 446803' = '<SYSTEM32>\WScript.exe %ProgramFiles%\isafe\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 569045' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ImApp\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 116941' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ImNotfy\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 494432' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ImpCnt\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 985922' = '<SYSTEM32>\WScript.exe %ProgramFiles%\IncMail\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 577066' = '<SYSTEM32>\WScript.exe %ProgramFiles%\InocIT\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 794295' = '<SYSTEM32>\WScript.exe %ProgramFiles%\InoRpc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 608122' = '<SYSTEM32>\WScript.exe %ProgramFiles%\InoRT\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 457597' = '<SYSTEM32>\WScript.exe %ProgramFiles%\InoTask\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 973808' = '<SYSTEM32>\WScript.exe %ProgramFiles%\InoUpTNG\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 418766' = '<SYSTEM32>\WScript.exe %ProgramFiles%\InphaseNXD\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 540617' = '<SYSTEM32>\WScript.exe %ProgramFiles%\InstallCAVS\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 492386' = '<SYSTEM32>\WScript.exe %ProgramFiles%\InstallLicense\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 622614' = '<SYSTEM32>\WScript.exe %ProgramFiles%\InstallLSP\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 462827' = '<SYSTEM32>\WScript.exe %ProgramFiles%\InstLsp\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 686999' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Internet Explorer\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 467548' = '<SYSTEM32>\WScript.exe %ProgramFiles%\iris\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 704208' = '<SYSTEM32>\WScript.exe %ProgramFiles%\iron\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 298792' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ISPNews\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 395288' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ih8run\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 191004' = '<SYSTEM32>\WScript.exe %ProgramFiles%\isPwdsvc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 63654' = '<SYSTEM32>\WScript.exe %ProgramFiles%\NeoWatchLog\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 178268' = '<SYSTEM32>\WScript.exe %ProgramFiles%\LUInit\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 202863' = '<SYSTEM32>\WScript.exe %ProgramFiles%\MP3ToysTray\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 466860' = '<SYSTEM32>\WScript.exe %ProgramFiles%\MpEng\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 41539' = '<SYSTEM32>\WScript.exe %ProgramFiles%\mpftray\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 741512' = '<SYSTEM32>\WScript.exe %ProgramFiles%\mpssvc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 557060' = '<SYSTEM32>\WScript.exe %ProgramFiles%\MSBuild\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 801516' = '<SYSTEM32>\WScript.exe %ProgramFiles%\msimn\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 682346' = '<SYSTEM32>\WScript.exe %ProgramFiles%\MSMPSVC\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 134763' = '<SYSTEM32>\WScript.exe %ProgramFiles%\msn6\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 680284' = '<SYSTEM32>\WScript.exe %ProgramFiles%\msnmsgr\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 440760' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Luna\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 772909' = '<SYSTEM32>\WScript.exe %ProgramFiles%\mva\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 766468' = '<SYSTEM32>\WScript.exe %ProgramFiles%\myAgtSvc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 326430' = '<SYSTEM32>\WScript.exe %ProgramFiles%\myagttry\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 460692' = '<SYSTEM32>\WScript.exe %ProgramFiles%\navapsvc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 302962' = '<SYSTEM32>\WScript.exe %ProgramFiles%\NavLu32\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 978483' = '<SYSTEM32>\WScript.exe %ProgramFiles%\NAVStub\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 532425' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Navw32\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 566584' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Navwnt\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 429666' = '<SYSTEM32>\WScript.exe %ProgramFiles%\MP3Toys\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 795736' = '<SYSTEM32>\WScript.exe %ProgramFiles%\MP3Theater\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 45810' = '<SYSTEM32>\WScript.exe %ProgramFiles%\MP3Tray\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 533433' = '<SYSTEM32>\WScript.exe %ProgramFiles%\MonSysNT\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 702350' = '<SYSTEM32>\WScript.exe %ProgramFiles%\monlite\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 193508' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Luupdate\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 313328' = '<SYSTEM32>\WScript.exe %ProgramFiles%\MalwareRemoval\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 356138' = '<SYSTEM32>\WScript.exe %ProgramFiles%\maplestory\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 735704' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Maxthon\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 260518' = '<SYSTEM32>\WScript.exe %ProgramFiles%\mcmnhdlr\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 133038' = '<SYSTEM32>\WScript.exe %ProgramFiles%\mcregwiz\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 862096' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Mcshield\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 572567' = '<SYSTEM32>\WScript.exe %ProgramFiles%\mcupdmgr\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 383957' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ih8\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 935720' = '<SYSTEM32>\WScript.exe %ProgramFiles%\mcvsshld\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 927641' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ILAUNCHR\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 33157' = '<SYSTEM32>\WScript.exe %ProgramFiles%\mfpmp\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 323421' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Microsoft Office\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 739739' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Microsoft SQL Server Compact Edition\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 155761' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Microsoft Sync Framework\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 850262' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Microsoft Synchronization Services\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 126560' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Mir3Game\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 655759' = '<SYSTEM32>\WScript.exe %ProgramFiles%\miranda32\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 681384' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Miro\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 800057' = '<SYSTEM32>\WScript.exe %ProgramFiles%\MemString\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 502097' = '<SYSTEM32>\WScript.exe %ProgramFiles%\magent\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 793024' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Microsoft Analysis Services\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 263161' = '<SYSTEM32>\WScript.exe %ProgramFiles%\iexplore\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 407451' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ieuser\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 81624' = '<SYSTEM32>\WScript.exe %ProgramFiles%\IERegFix\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 178391' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsavaui\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 394492' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsavgui\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 470006' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsavstrt\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 259518' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsavwsch\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 280324' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsavwscr\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 737376' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsbwsys\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 745311' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsdbuh\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 771738' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsdc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 979261' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsdfwd\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 183778' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FSDIAG\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 26464' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FsDiagUi\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 317195' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsfwwsch\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 426141' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsfwwscr\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 843381' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsgetwab\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 296924' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsgk32\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 8011' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsgk32st\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 97101' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsguidll\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 366737' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsauach\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 266187' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsample\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 560016' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsav32\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 82093' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsaua\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 543141' = '<SYSTEM32>\WScript.exe %ProgramFiles%\freshclam\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 228737' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FlashFXP\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 235244' = '<SYSTEM32>\WScript.exe %ProgramFiles%\far\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 188350' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FCH32\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 757682' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fdm\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 701236' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fdmwi\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 103425' = '<SYSTEM32>\WScript.exe %ProgramFiles%\filezilla\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 635811' = '<SYSTEM32>\WScript.exe %ProgramFiles%\firebird\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 509295' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FireFox\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 414415' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FireSvc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 850277' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsguiexe\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 711300' = '<SYSTEM32>\WScript.exe %ProgramFiles%\NeoWatchTray\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 309835' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FireTray\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 319599' = '<SYSTEM32>\WScript.exe %ProgramFiles%\flock\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 616012' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Foxit\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 495022' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FPAVServer\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 240743' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fpavupdm\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 792826' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FProtTray\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 956341' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fpscan\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 444005' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fptrayproc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 733884' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FPWin\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 746407' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FAMEH32\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 344042' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FlashGot\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 48352' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fssg\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 466909' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FSHDLL32\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 514019' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsihs\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 325571' = '<SYSTEM32>\WScript.exe %ProgramFiles%\GoogleDesktop\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 357311' = '<SYSTEM32>\WScript.exe %ProgramFiles%\googletalk\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 430975' = '<SYSTEM32>\WScript.exe %ProgramFiles%\GoogleUpdate\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 640831' = '<SYSTEM32>\WScript.exe %ProgramFiles%\guardgni\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 906223' = '<SYSTEM32>\WScript.exe %ProgramFiles%\GuardNT\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 862671' = '<SYSTEM32>\WScript.exe %ProgramFiles%\gw\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 422952' = '<SYSTEM32>\WScript.exe %ProgramFiles%\helpctr\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 253222' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsav\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 390730' = '<SYSTEM32>\WScript.exe %ProgramFiles%\helper\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 426705' = '<SYSTEM32>\WScript.exe %ProgramFiles%\HRegMon\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 883439' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Hrres\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 801506' = '<SYSTEM32>\WScript.exe %ProgramFiles%\HSockPE\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 369997' = '<SYSTEM32>\WScript.exe %ProgramFiles%\httplook\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 133946' = '<SYSTEM32>\WScript.exe %ProgramFiles%\iamapp\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 121334' = '<SYSTEM32>\WScript.exe %ProgramFiles%\iamserv\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 258963' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ICQ\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 734199' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ICQLite\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 73162' = '<SYSTEM32>\WScript.exe %ProgramFiles%\GIANTAntiSpywareMain\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 729035' = '<SYSTEM32>\WScript.exe %ProgramFiles%\hipsdiag\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 389638' = '<SYSTEM32>\WScript.exe %ProgramFiles%\gnotify\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 857398' = '<SYSTEM32>\WScript.exe %ProgramFiles%\GIANTAntiSpywareUpdater\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 662068' = '<SYSTEM32>\WScript.exe %ProgramFiles%\gg\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 57990' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ge\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 950964' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FSLAUNCH\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 985526' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FSM32\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 533148' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FSMA32\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 873861' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FSMB32\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 88478' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fspc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 171862' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fspex\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 427507' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsqh\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 176034' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fshelp\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 80677' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fssf\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 809096' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FSHOTFIX\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 801272' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fssm32\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 657965' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fssw\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 322592' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fstlui\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 210242' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsuninst\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 590199' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsus\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 259106' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ftpte\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 13553' = '<SYSTEM32>\WScript.exe %ProgramFiles%\gc\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 904205' = '<SYSTEM32>\WScript.exe %ProgramFiles%\gcasDtServ\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 316101' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsihcomp\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 457775' = '<SYSTEM32>\WScript.exe %ProgramFiles%\gcasServ\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 262178' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsstm\<File name>.vbs'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 656538' = '<SYSTEM32>\WScript.exe D:\$RECYCLE.BIN\S-1-5-21-1960123792-2022915161-3775307078-1001\<File name>.vbs'
Creates or modifies the following files
  • %WINDIR%\tasks\<File name>.vbs
Creates the following files on removable media
  • <Drive name for removable media>:\autorun.inf
  • <Drive name for removable media>:\<File name>.vbs
Modifies file system
Creates the following files
  • C:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\<File name>.vbs
  • %ProgramFiles%\sdhelp\<File name>.vbs
  • %ProgramFiles%\sdinvoker\<File name>.vbs
  • %ProgramFiles%\sdloader\<File name>.vbs
  • %ProgramFiles%\sdraw\<File name>.vbs
  • %ProgramFiles%\sdtrayapp\<File name>.vbs
  • %ProgramFiles%\seamonkey\<File name>.vbs
  • %ProgramFiles%\seccenter\<File name>.vbs
  • %ProgramFiles%\sfagent\<File name>.vbs
  • %ProgramFiles%\sigtool\<File name>.vbs
  • %ProgramFiles%\simpress\<File name>.vbs
  • %ProgramFiles%\sitecli\<File name>.vbs
  • %ProgramFiles%\skype\<File name>.vbs
  • %ProgramFiles%\skypepm\<File name>.vbs
  • %ProgramFiles%\smartftp\<File name>.vbs
  • %ProgramFiles%\smath\<File name>.vbs
  • %ProgramFiles%\smc\<File name>.vbs
  • %ProgramFiles%\sndsrvc\<File name>.vbs
  • %ProgramFiles%\sniffer\<File name>.vbs
  • %ProgramFiles%\so3d\<File name>.vbs
  • %ProgramFiles%\sched\<File name>.vbs
  • %ProgramFiles%\ravtimer\<File name>.vbs
  • %ProgramFiles%\scanningprocess\<File name>.vbs
  • %ProgramFiles%\scalc\<File name>.vbs
  • %ProgramFiles%\realmon\<File name>.vbs
  • %ProgramFiles%\reference assemblies\<File name>.vbs
  • %ProgramFiles%\register\<File name>.vbs
  • %ProgramFiles%\removeit\<File name>.vbs
  • %ProgramFiles%\remover\<File name>.vbs
  • %ProgramFiles%\rescue\<File name>.vbs
  • %ProgramFiles%\rfwmain\<File name>.vbs
  • %ProgramFiles%\rq\<File name>.vbs
  • %ProgramFiles%\rtvscan\<File name>.vbs
  • %ProgramFiles%\rulaunch\<File name>.vbs
  • %ProgramFiles%\runsetup\<File name>.vbs
  • %ProgramFiles%\safari\<File name>.vbs
  • %ProgramFiles%\sarcli\<File name>.vbs
  • %ProgramFiles%\sargui\<File name>.vbs
  • %ProgramFiles%\savadminservice\<File name>.vbs
  • %ProgramFiles%\savmain\<File name>.vbs
  • %ProgramFiles%\savprogress\<File name>.vbs
  • %ProgramFiles%\savscan\<File name>.vbs
  • %ProgramFiles%\sbase\<File name>.vbs
  • %ProgramFiles%\scanner\<File name>.vbs
  • %ProgramFiles%\rcimlby\<File name>.vbs
  • %ProgramFiles%\soffice\<File name>.vbs
  • %ProgramFiles%\spiderml\<File name>.vbs
  • %ProgramFiles%\tca\<File name>.vbs
  • %ProgramFiles%\teatimer\<File name>.vbs
  • %ProgramFiles%\tgsvcstp\<File name>.vbs
  • %ProgramFiles%\thebat\<File name>.vbs
  • %ProgramFiles%\thgnard\<File name>.vbs
  • %ProgramFiles%\thunderbird\<File name>.vbs
  • %ProgramFiles%\tmas\<File name>.vbs
  • %ProgramFiles%\tmlisten\<File name>.vbs
  • %ProgramFiles%\rat\<File name>.vbs
  • %ProgramFiles%\tmntsrv\<File name>.vbs
  • %ProgramFiles%\tmproxy\<File name>.vbs
  • %ProgramFiles%\tnbutil\<File name>.vbs
  • %ProgramFiles%\totalcmd\<File name>.vbs
  • %ProgramFiles%\tracelog\<File name>.vbs
  • %ProgramFiles%\traymon\<File name>.vbs
  • %ProgramFiles%\trillian\<File name>.vbs
  • %ProgramFiles%\trojanguarder\<File name>.vbs
  • %ProgramFiles%\trojanhunter\<File name>.vbs
  • %ProgramFiles%\sysinfo\<File name>.vbs
  • %ProgramFiles%\tbmon\<File name>.vbs
  • %ProgramFiles%\spbbcsvc\<File name>.vbs
  • %ProgramFiles%\spamcfg\<File name>.vbs
  • %ProgramFiles%\symproxysvc\<File name>.vbs
  • %ProgramFiles%\spidernt\<File name>.vbs
  • %ProgramFiles%\spiderui\<File name>.vbs
  • %ProgramFiles%\sporder\<File name>.vbs
  • %ProgramFiles%\spybotsd\<File name>.vbs
  • %ProgramFiles%\sro_client\<File name>.vbs
  • %ProgramFiles%\start_diag\<File name>.vbs
  • %ProgramFiles%\stopsignav\<File name>.vbs
  • %ProgramFiles%\streetsolkshim\<File name>.vbs
  • %ProgramFiles%\submitfiles\<File name>.vbs
  • %ProgramFiles%\svcntaux\<File name>.vbs
  • %ProgramFiles%\swagent\<File name>.vbs
  • %ProgramFiles%\swdoctor\<File name>.vbs
  • %ProgramFiles%\swdsvc\<File name>.vbs
  • %ProgramFiles%\sweb\<File name>.vbs
  • %ProgramFiles%\swriter\<File name>.vbs
  • %ProgramFiles%\symantecrootinstaller\<File name>.vbs
  • %ProgramFiles%\symlcsvc\<File name>.vbs
  • %ProgramFiles%\symsport\<File name>.vbs
  • %ProgramFiles%\spider\<File name>.vbs
  • %ProgramFiles%\symwsc\<File name>.vbs
  • %ProgramFiles%\ravmon\<File name>.vbs
  • %ProgramFiles%\rapget\<File name>.vbs
  • %ProgramFiles%\twelvesky2\<File name>.vbs
  • %ProgramFiles%\oladdin\<File name>.vbs
  • %ProgramFiles%\onaccessinstaller\<File name>.vbs
  • %ProgramFiles%\opera\<File name>.vbs
  • %ProgramFiles%\oscheck\<File name>.vbs
  • %ProgramFiles%\outlook\<File name>.vbs
  • %ProgramFiles%\outpost\<File name>.vbs
  • %ProgramFiles%\partin\<File name>.vbs
  • %ProgramFiles%\partin9x\<File name>.vbs
  • %ProgramFiles%\partinfo\<File name>.vbs
  • %ProgramFiles%\partinnt\<File name>.vbs
  • %ProgramFiles%\pavfires\<File name>.vbs
  • %ProgramFiles%\pavfnsvr\<File name>.vbs
  • %ProgramFiles%\pavkre\<File name>.vbs
  • %ProgramFiles%\pavprot\<File name>.vbs
  • %ProgramFiles%\pavproxy\<File name>.vbs
  • %ProgramFiles%\pavprsrv\<File name>.vbs
  • %ProgramFiles%\pavsrv51\<File name>.vbs
  • %ProgramFiles%\oaui\<File name>.vbs
  • %ProgramFiles%\oasrv\<File name>.vbs
  • %ProgramFiles%\oget\<File name>.vbs
  • %ProgramFiles%\pccpfw\<File name>.vbs
  • %ProgramFiles%\pccguide\<File name>.vbs
  • %ProgramFiles%\pccntmon\<File name>.vbs
  • %ProgramFiles%\nod\<File name>.vbs
  • %ProgramFiles%\nod32\<File name>.vbs
  • %ProgramFiles%\nod32krn\<File name>.vbs
  • %ProgramFiles%\nod32kui\<File name>.vbs
  • %ProgramFiles%\notifyha\<File name>.vbs
  • %ProgramFiles%\notstart\<File name>.vbs
  • %ProgramFiles%\npavtray\<File name>.vbs
  • %ProgramFiles%\npfmsg\<File name>.vbs
  • %ProgramFiles%\nsmdtr\<File name>.vbs
  • %ProgramFiles%\nssserv\<File name>.vbs
  • %ProgramFiles%\nsstray\<File name>.vbs
  • %ProgramFiles%\ntoskrnl\<File name>.vbs
  • %ProgramFiles%\ntrtscan\<File name>.vbs
  • %ProgramFiles%\ntxconfig\<File name>.vbs
  • %ProgramFiles%\nupgrade\<File name>.vbs
  • %ProgramFiles%\nvcod\<File name>.vbs
  • %ProgramFiles%\nvcte\<File name>.vbs
  • %ProgramFiles%\nwservice\<File name>.vbs
  • %ProgramFiles%\netxray\<File name>.vbs
  • %ProgramFiles%\nvcut\<File name>.vbs
  • %ProgramFiles%\pcctlcom\<File name>.vbs
  • %ProgramFiles%\ps\<File name>.vbs
  • %ProgramFiles%\pidgin\<File name>.vbs
  • %ProgramFiles%\psimsvc\<File name>.vbs
  • %ProgramFiles%\pxagent\<File name>.vbs
  • %ProgramFiles%\pxconsole\<File name>.vbs
  • %ProgramFiles%\pxl\<File name>.vbs
  • %ProgramFiles%\pxl1\<File name>.vbs
  • %ProgramFiles%\pxreset\<File name>.vbs
  • %ProgramFiles%\pxsupport\<File name>.vbs
  • %ProgramFiles%\ofcpfwsvc\<File name>.vbs
  • %ProgramFiles%\python\<File name>.vbs
  • %ProgramFiles%\qip\<File name>.vbs
  • %ProgramFiles%\qklez\<File name>.vbs
  • %ProgramFiles%\qrtfix\<File name>.vbs
  • %ProgramFiles%\quaranti\<File name>.vbs
  • %ProgramFiles%\quickstart\<File name>.vbs
  • %ProgramFiles%\ragexe\<File name>.vbs
  • %ProgramFiles%\ragfree\<File name>.vbs
  • %ProgramFiles%\protect\<File name>.vbs
  • %ProgramFiles%\processviewer\<File name>.vbs
  • %ProgramFiles%\qhwscsvc\<File name>.vbs
  • %ProgramFiles%\pshost\<File name>.vbs
  • %ProgramFiles%\psctrls\<File name>.vbs
  • %ProgramFiles%\privatebrowser\<File name>.vbs
  • %ProgramFiles%\prevxsetup\<File name>.vbs
  • %ProgramFiles%\pm\<File name>.vbs
  • %ProgramFiles%\pm8flash\<File name>.vbs
  • %ProgramFiles%\pmagic\<File name>.vbs
  • %ProgramFiles%\pmagic9x\<File name>.vbs
  • %ProgramFiles%\pmagicbt\<File name>.vbs
  • %ProgramFiles%\pmagicnt\<File name>.vbs
  • %ProgramFiles%\trtddptr\<File name>.vbs
  • %ProgramFiles%\polutil\<File name>.vbs
  • %ProgramFiles%\ppfw\<File name>.vbs
  • %ProgramFiles%\tmpfw\<File name>.vbs
  • %ProgramFiles%\pqboot32\<File name>.vbs
  • %ProgramFiles%\pqpe\<File name>.vbs
  • %ProgramFiles%\pqpe9x\<File name>.vbs
  • %ProgramFiles%\pqpent\<File name>.vbs
  • %ProgramFiles%\preconfig\<File name>.vbs
  • %ProgramFiles%\preupd\<File name>.vbs
  • %ProgramFiles%\prevsrv\<File name>.vbs
  • %ProgramFiles%\postinstall\<File name>.vbs
  • %ProgramFiles%\pertsk\<File name>.vbs
  • %ProgramFiles%\pctav\<File name>.vbs
  • %ProgramFiles%\pqbw\<File name>.vbs
  • %ProgramFiles%\fssf\<File name>.vbs
  • %ProgramFiles%\uiscan\<File name>.vbs
  • %PROGRAMDATA%\microsoft\<File name>.vbs
  • %PROGRAMDATA%\microsoft help\<File name>.vbs
  • %PROGRAMDATA%\microsoft toolkit\<File name>.vbs
  • %PROGRAMDATA%\mozilla\<File name>.vbs
  • %PROGRAMDATA%\oracle\<File name>.vbs
  • %PROGRAMDATA%\package cache\<File name>.vbs
  • %PROGRAMDATA%\start menu\<File name>.vbs
  • %PROGRAMDATA%\sun\<File name>.vbs
  • %PROGRAMDATA%\templates\<File name>.vbs
  • C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\<File name>.vbs
  • C:\totalcmd\language\<File name>.vbs
  • C:\users\default\<File name>.vbs
  • C:\users\public\<File name>.vbs
  • %HOMEPATH%\<File name>.vbs
  • %WINDIR%\addins\<File name>.vbs
  • %WINDIR%\appcompat\<File name>.vbs
  • %WINDIR%\apppatch\<File name>.vbs
  • %WINDIR%\assembly\<File name>.vbs
  • %WINDIR%\bitlockerdiscoveryvolumecontents\<File name>.vbs
  • %PROGRAMDATA%\favorites\<File name>.vbs
  • %WINDIR%\branding\<File name>.vbs
  • %PROGRAMDATA%\documents\<File name>.vbs
  • %PROGRAMDATA%\application data\<File name>.vbs
  • %ProgramFiles(x86)%\mirc\<File name>.vbs
  • %ProgramFiles(x86)%\mozilla firefox\<File name>.vbs
  • %ProgramFiles(x86)%\mozilla thunderbird\<File name>.vbs
  • %ProgramFiles(x86)%\msbuild\<File name>.vbs
  • %ProgramFiles(x86)%\opera\<File name>.vbs
  • %ProgramFiles(x86)%\pidgin\<File name>.vbs
  • %ProgramFiles(x86)%\qip 2012\<File name>.vbs
  • %ProgramFiles(x86)%\reference assemblies\<File name>.vbs
  • %ProgramFiles(x86)%\steam\<File name>.vbs
  • %ProgramFiles(x86)%\uninstall information\<File name>.vbs
  • %ProgramFiles(x86)%\winamp\<File name>.vbs
  • %ProgramFiles(x86)%\windows defender\<File name>.vbs
  • %ProgramFiles(x86)%\windows mail\<File name>.vbs
  • %ProgramFiles(x86)%\windows media player\<File name>.vbs
  • %ProgramFiles(x86)%\windows nt\<File name>.vbs
  • %ProgramFiles(x86)%\windows photo viewer\<File name>.vbs
  • %ProgramFiles(x86)%\windows portable devices\<File name>.vbs
  • %ProgramFiles(x86)%\windows sidebar\<File name>.vbs
  • %PROGRAMDATA%\adobe\<File name>.vbs
  • %PROGRAMDATA%\desktop\<File name>.vbs
  • %WINDIR%\csc\<File name>.vbs
  • %WINDIR%\cursors\<File name>.vbs
  • %WINDIR%\debug\<File name>.vbs
  • %WINDIR%\registration\<File name>.vbs
  • %WINDIR%\resources\<File name>.vbs
  • %WINDIR%\schcache\<File name>.vbs
  • %WINDIR%\schemas\<File name>.vbs
  • %WINDIR%\security\<File name>.vbs
  • %WINDIR%\serviceprofiles\<File name>.vbs
  • %WINDIR%\setup\<File name>.vbs
  • %WINDIR%\shellnew\<File name>.vbs
  • %WINDIR%\softwaredistribution\<File name>.vbs
  • %ProgramFiles(x86)%\microsoft visual studio 8\<File name>.vbs
  • %WINDIR%\speech\<File name>.vbs
  • <SYSTEM32>\<File name>.vbs
  • %WINDIR%\syswow64\<File name>.vbs
  • %WINDIR%\tapi\<File name>.vbs
  • %WINDIR%\temp\<File name>.vbs
  • %WINDIR%\tracing\<File name>.vbs
  • %WINDIR%\twain_32\<File name>.vbs
  • %WINDIR%\vss\<File name>.vbs
  • %WINDIR%\prefetch\<File name>.vbs
  • %WINDIR%\policydefinitions\<File name>.vbs
  • %WINDIR%\remotepackages\<File name>.vbs
  • %WINDIR%\pla\<File name>.vbs
  • %WINDIR%\performance\<File name>.vbs
  • %WINDIR%\digitallocker\<File name>.vbs
  • %WINDIR%\ehome\<File name>.vbs
  • %WINDIR%\en-us\<File name>.vbs
  • %WINDIR%\fonts\<File name>.vbs
  • %WINDIR%\globalization\<File name>.vbs
  • %WINDIR%\help\<File name>.vbs
  • %WINDIR%\ime\<File name>.vbs
  • %WINDIR%\inf\<File name>.vbs
  • %ProgramFiles(x86)%\microsoft.net\<File name>.vbs
  • %WINDIR%\installer\<File name>.vbs
  • %ProgramFiles%\netstatviewer\<File name>.vbs
  • %WINDIR%\livekernelreports\<File name>.vbs
  • %WINDIR%\media\<File name>.vbs
  • %WINDIR%\microsoft.net\<File name>.vbs
  • %WINDIR%\migration\<File name>.vbs
  • %WINDIR%\modemlogs\<File name>.vbs
  • %WINDIR%\offline web pages\<File name>.vbs
  • %WINDIR%\panther\<File name>.vbs
  • %WINDIR%\pchealth\<File name>.vbs
  • %WINDIR%\l2schemas\<File name>.vbs
  • %WINDIR%\downloaded program files\<File name>.vbs
  • %WINDIR%\logs\<File name>.vbs
  • %ProgramFiles%\nisoptui\<File name>.vbs
  • %ProgramFiles(x86)%\microsoft office\<File name>.vbs
  • %ProgramFiles%\zlclient\<File name>.vbs
  • %ProgramFiles%\viritsvc\<File name>.vbs
  • %ProgramFiles%\viruskeeper\<File name>.vbs
  • %ProgramFiles%\virusnews\<File name>.vbs
  • %ProgramFiles%\vistaux\<File name>.vbs
  • %ProgramFiles%\visthlic\<File name>.vbs
  • %ProgramFiles%\visthupd\<File name>.vbs
  • %ProgramFiles%\vrfwsvc\<File name>.vbs
  • %ProgramFiles%\vrmonsvc\<File name>.vbs
  • %ProgramFiles%\vrrw32\<File name>.vbs
  • %ProgramFiles%\vshwin32\<File name>.vbs
  • %ProgramFiles%\vsmon\<File name>.vbs
  • %ProgramFiles%\vsserv\<File name>.vbs
  • %ProgramFiles%\vsstat\<File name>.vbs
  • %ProgramFiles%\wclose\<File name>.vbs
  • %ProgramFiles%\webfiltr\<File name>.vbs
  • %ProgramFiles%\webmoney\<File name>.vbs
  • %ProgramFiles%\webproxy\<File name>.vbs
  • %ProgramFiles%\webscanx\<File name>.vbs
  • %ProgramFiles%\vettray\<File name>.vbs
  • %ProgramFiles%\wil\<File name>.vbs
  • %ProgramFiles%\vcrmon\<File name>.vbs
  • %ProgramFiles%\vbsntw\<File name>.vbs
  • %ProgramFiles%\uninstall information\<File name>.vbs
  • %ProgramFiles%\uninstallcavs\<File name>.vbs
  • %ProgramFiles%\uninstaller\<File name>.vbs
  • %ProgramFiles%\uninstalllsp\<File name>.vbs
  • %ProgramFiles%\unoinfo\<File name>.vbs
  • %ProgramFiles%\unopkg\<File name>.vbs
  • %ProgramFiles%\unp_test\<File name>.vbs
  • %ProgramFiles%\up2date\<File name>.vbs
  • %ProgramFiles%\updater\<File name>.vbs
  • %ProgramFiles%\updaterui\<File name>.vbs
  • %ProgramFiles%\updclient\<File name>.vbs
  • %ProgramFiles%\upgrepl\<File name>.vbs
  • %ProgramFiles%\upsobmaker\<File name>.vbs
  • %ProgramFiles%\usdownloader\<File name>.vbs
  • %ProgramFiles%\uupd\<File name>.vbs
  • %ProgramFiles%\vba32ecm\<File name>.vbs
  • %ProgramFiles%\vba32ifs\<File name>.vbs
  • %ProgramFiles%\vba32ldr\<File name>.vbs
  • %ProgramFiles%\vba32pp3\<File name>.vbs
  • %ProgramFiles%\vchk\<File name>.vbs
  • %ProgramFiles%\winaw32\<File name>.vbs
  • %ProgramFiles%\winbaram\<File name>.vbs
  • %ProgramFiles%\wincmd32\<File name>.vbs
  • %ProgramFiles%\wsctool\<File name>.vbs
  • %ProgramFiles%\wsm\<File name>.vbs
  • %ProgramFiles%\xcommsvr\<File name>.vbs
  • %ProgramFiles%\yahoomessenger\<File name>.vbs
  • %ProgramFiles%\yahoosync\<File name>.vbs
  • %ProgramFiles%\ybclient\<File name>.vbs
  • %ProgramFiles%\ymsgr_tray\<File name>.vbs
  • %ProgramFiles%\zapro\<File name>.vbs
  • %ProgramFiles%\zatutor\<File name>.vbs
  • %ProgramFiles%\viritexp\<File name>.vbs
  • %ProgramFiles%\zauninst\<File name>.vbs
  • %ProgramFiles%\zonealarm\<File name>.vbs
  • %ProgramFiles(x86)%\adobe\<File name>.vbs
  • %CommonProgramFiles(x86)%\<File name>.vbs
  • %ProgramFiles(x86)%\google\<File name>.vbs
  • %ProgramFiles(x86)%\internet explorer\<File name>.vbs
  • %ProgramFiles(x86)%\k-lite codec pack\<File name>.vbs
  • %ProgramFiles(x86)%\microsoft analysis services\<File name>.vbs
  • %ProgramFiles%\writespid\<File name>.vbs
  • %ProgramFiles%\wrctrl\<File name>.vbs
  • %ProgramFiles%\wsftpgui\<File name>.vbs
  • %ProgramFiles%\wradmin\<File name>.vbs
  • %ProgramFiles%\wow\<File name>.vbs
  • %ProgramFiles%\windowlist\<File name>.vbs
  • %ProgramFiles%\windows journal\<File name>.vbs
  • %ProgramFiles%\windows mail\<File name>.vbs
  • %ProgramFiles%\windows media player\<File name>.vbs
  • %ProgramFiles%\windows nt\<File name>.vbs
  • %ProgramFiles%\windows photo viewer\<File name>.vbs
  • %ProgramFiles%\windows portable devices\<File name>.vbs
  • %ProgramFiles%\windows sidebar\<File name>.vbs
  • %ProgramFiles(x86)%\microsoft visual studio .net 2003\<File name>.vbs
  • %ProgramFiles%\windump\<File name>.vbs
  • %ProgramFiles%\una\<File name>.vbs
  • %ProgramFiles%\winrar\<File name>.vbs
  • %ProgramFiles%\winss\<File name>.vbs
  • %ProgramFiles%\winssnotify\<File name>.vbs
  • %ProgramFiles%\wish\<File name>.vbs
  • %ProgramFiles%\wlloginproxy\<File name>.vbs
  • %ProgramFiles%\wlmail\<File name>.vbs
  • %ProgramFiles%\wltuser\<File name>.vbs
  • %ProgramFiles%\woool\<File name>.vbs
  • %ProgramFiles%\winmail\<File name>.vbs
  • %ProgramFiles%\windows defender\<File name>.vbs
  • %ProgramFiles%\winroute\<File name>.vbs
  • %ProgramFiles%\neowatchtray\<File name>.vbs
  • %ProgramFiles%\neowatchlog\<File name>.vbs
  • %ProgramFiles%\navwnt\<File name>.vbs
  • %ProgramFiles%\cavse\<File name>.vbs
  • %ProgramFiles%\cavsn\<File name>.vbs
  • %ProgramFiles%\cavsub\<File name>.vbs
  • %ProgramFiles%\cavsubmit\<File name>.vbs
  • %ProgramFiles%\cavumas\<File name>.vbs
  • %ProgramFiles%\cavuserupd\<File name>.vbs
  • %ProgramFiles%\cavvl\<File name>.vbs
  • %ProgramFiles%\ccapp\<File name>.vbs
  • %ProgramFiles%\ccevtmgr\<File name>.vbs
  • %ProgramFiles%\ccleaner\<File name>.vbs
  • %ProgramFiles%\ccproxy\<File name>.vbs
  • %ProgramFiles%\ccsetmgr\<File name>.vbs
  • %ProgramFiles%\cemrep\<File name>.vbs
  • %ProgramFiles%\chrome\<File name>.vbs
  • %ProgramFiles%\clamscan\<File name>.vbs
  • %ProgramFiles%\clamtray\<File name>.vbs
  • %ProgramFiles%\clamwin\<File name>.vbs
  • %ProgramFiles%\cavoar\<File name>.vbs
  • %ProgramFiles%\cavmud\<File name>.vbs
  • %ProgramFiles%\cavscons\<File name>.vbs
  • %ProgramFiles%\cleaner\<File name>.vbs
  • %ProgramFiles%\claw95\<File name>.vbs
  • %ProgramFiles%\claw95cf\<File name>.vbs
  • %ProgramFiles%\bdoesrv\<File name>.vbs
  • %ProgramFiles%\bdss\<File name>.vbs
  • %ProgramFiles%\bdsubmit\<File name>.vbs
  • %ProgramFiles%\bdsubmitwiz\<File name>.vbs
  • %ProgramFiles%\bdsurvey\<File name>.vbs
  • %ProgramFiles%\bdswitch\<File name>.vbs
  • %ProgramFiles%\bdwizreg\<File name>.vbs
  • %ProgramFiles%\blackd\<File name>.vbs
  • %ProgramFiles%\blackice\<File name>.vbs
  • %ProgramFiles%\blindman\<File name>.vbs
  • %ProgramFiles%\btini\<File name>.vbs
  • %ProgramFiles%\btinint\<File name>.vbs
  • %ProgramFiles%\cabalmain\<File name>.vbs
  • %ProgramFiles%\cafix\<File name>.vbs
  • %ProgramFiles%\cavapp\<File name>.vbs
  • %ProgramFiles%\cavasm\<File name>.vbs
  • %ProgramFiles%\cavaud\<File name>.vbs
  • %ProgramFiles%\cavmr\<File name>.vbs
  • %ProgramFiles%\bdmcon\<File name>.vbs
  • %ProgramFiles%\cavemsrv\<File name>.vbs
  • %ProgramFiles%\cleaner3\<File name>.vbs
  • %ProgramFiles%\drvctl\<File name>.vbs
  • %ProgramFiles%\cmain\<File name>.vbs
  • %ProgramFiles%\drwadins\<File name>.vbs
  • %ProgramFiles%\drweb\<File name>.vbs
  • %ProgramFiles%\drweb32w\<File name>.vbs
  • %ProgramFiles%\drweb386\<File name>.vbs
  • %ProgramFiles%\drwebscd\<File name>.vbs
  • %ProgramFiles%\drwebupw\<File name>.vbs
  • %ProgramFiles%\drwebwcl\<File name>.vbs
  • %ProgramFiles%\aswupdsv\<File name>.vbs
  • %ProgramFiles%\drwreg\<File name>.vbs
  • %ProgramFiles%\ecmd\<File name>.vbs
  • %ProgramFiles%\egni\<File name>.vbs
  • %ProgramFiles%\ehsniffer\<File name>.vbs
  • %ProgramFiles%\ekrn\<File name>.vbs
  • %ProgramFiles%\elementclient\<File name>.vbs
  • %ProgramFiles%\etherd\<File name>.vbs
  • %ProgramFiles%\eudora\<File name>.vbs
  • %ProgramFiles%\dpatrolq\<File name>.vbs
  • %ProgramFiles%\dnf\<File name>.vbs
  • %ProgramFiles%\dvd maker\<File name>.vbs
  • %ProgramFiles%\drvmap\<File name>.vbs
  • %ProgramFiles%\drvirus\<File name>.vbs
  • %ProgramFiles%\dislite\<File name>.vbs
  • %ProgramFiles%\directftp\<File name>.vbs
  • %ProgramFiles%\cmgrdian\<File name>.vbs
  • %CommonProgramFiles%\<File name>.vbs
  • %ProgramFiles%\copyx64\<File name>.vbs
  • %ProgramFiles%\courier\<File name>.vbs
  • %ProgramFiles%\cpd\<File name>.vbs
  • %ProgramFiles%\csendto\<File name>.vbs
  • %ProgramFiles%\bdagent\<File name>.vbs
  • %ProgramFiles%\cssexc\<File name>.vbs
  • %ProgramFiles%\custsetup\<File name>.vbs
  • %ProgramFiles%\bdnews\<File name>.vbs
  • %ProgramFiles%\cuteftp\<File name>.vbs
  • %ProgramFiles%\dbtool\<File name>.vbs
  • %ProgramFiles%\defensewall\<File name>.vbs
  • %ProgramFiles%\defwatch\<File name>.vbs
  • %ProgramFiles%\dekaron\<File name>.vbs
  • %ProgramFiles%\digsby\<File name>.vbs
  • %ProgramFiles%\digsby-app\<File name>.vbs
  • %ProgramFiles%\custinstall\<File name>.vbs
  • %ProgramFiles%\clrcche\<File name>.vbs
  • %ProgramFiles%\clisvc\<File name>.vbs
  • %ProgramFiles%\dbconvert\<File name>.vbs
  • %WINDIR%\web\<File name>.vbs
  • %ProgramFiles%\ewidoctrl\<File name>.vbs
  • %ProgramFiles%\avsynmgr\<File name>.vbs
  • %ProgramFiles%\aim6\<File name>.vbs
  • %ProgramFiles%\aimpro\<File name>.vbs
  • %ProgramFiles%\airdefense\<File name>.vbs
  • %ProgramFiles%\almon\<File name>.vbs
  • %ProgramFiles%\alsvc\<File name>.vbs
  • %ProgramFiles%\amon\<File name>.vbs
  • %ProgramFiles%\amsn\<File name>.vbs
  • %ProgramFiles%\anti-trojan\<File name>.vbs
  • %ProgramFiles%\antivirus\<File name>.vbs
  • %ProgramFiles%\aoltbserver\<File name>.vbs
  • %ProgramFiles%\armor2net\<File name>.vbs
  • %ProgramFiles%\armorsurf\<File name>.vbs
  • %ProgramFiles%\ash\<File name>.vbs
  • %ProgramFiles%\ashavast\<File name>.vbs
  • %ProgramFiles%\ashavsrv\<File name>.vbs
  • %ProgramFiles%\ashchest\<File name>.vbs
  • %ProgramFiles%\ashdisp\<File name>.vbs
  • %ProgramFiles%\ashdug\<File name>.vbs
  • %ProgramFiles%\ageofconan\<File name>.vbs
  • %ProgramFiles%\ashenhcd\<File name>.vbs
  • %ProgramFiles%\agb5\<File name>.vbs
  • %ProgramFiles%\ackwin32\<File name>.vbs
  • C:\far2\addons\<File name>.vbs
  • C:\far2\documentation\<File name>.vbs
  • C:\far2\encyclopedia\<File name>.vbs
  • C:\far2\fexcept\<File name>.vbs
  • C:\far2\plugins\<File name>.vbs
  • C:\far2\pluginsdk\<File name>.vbs
  • C:\msocache\all users\<File name>.vbs
  • C:\perflogs\admin\<File name>.vbs
  • %ProgramFiles%\360tray\<File name>.vbs
  • %ProgramFiles%\a2cmd\<File name>.vbs
  • %ProgramFiles%\a2guard\<File name>.vbs
  • %ProgramFiles%\a2hijackfree\<File name>.vbs
  • %ProgramFiles%\a2scan\<File name>.vbs
  • %ProgramFiles%\a2service\<File name>.vbs
  • %ProgramFiles%\a2start\<File name>.vbs
  • %ProgramFiles%\a2upd\<File name>.vbs
  • %ProgramFiles%\a2wizard\<File name>.vbs
  • %ProgramFiles%\aavshield\<File name>.vbs
  • %ProgramFiles%\about\<File name>.vbs
  • %ProgramFiles%\admunch\<File name>.vbs
  • %ProgramFiles%\ashlogv\<File name>.vbs
  • %ProgramFiles%\ahnsd\<File name>.vbs
  • %ProgramFiles%\ashmaisv\<File name>.vbs
  • %ProgramFiles%\avgfwsrv\<File name>.vbs
  • %ProgramFiles%\avgnpdln\<File name>.vbs
  • %ProgramFiles%\avgnpsvc\<File name>.vbs
  • %ProgramFiles%\avgrssvc\<File name>.vbs
  • %ProgramFiles%\avgscan\<File name>.vbs
  • %ProgramFiles%\avgupden\<File name>.vbs
  • %ProgramFiles%\avgupsvc\<File name>.vbs
  • %ProgramFiles%\avgvv\<File name>.vbs
  • %ProgramFiles%\avgw\<File name>.vbs
  • %ProgramFiles%\avgwizfw\<File name>.vbs
  • %ProgramFiles%\avinitnt\<File name>.vbs
  • %ProgramFiles%\avkserv\<File name>.vbs
  • %ProgramFiles%\avkservice\<File name>.vbs
  • %ProgramFiles%\avkwctl\<File name>.vbs
  • %ProgramFiles%\avnotify\<File name>.vbs
  • %ProgramFiles%\avpcc\<File name>.vbs
  • %ProgramFiles%\avpm\<File name>.vbs
  • %ProgramFiles%\avscan\<File name>.vbs
  • %ProgramFiles%\avgemc\<File name>.vbs
  • %ProgramFiles%\avgcc\<File name>.vbs
  • %ProgramFiles%\avginet\<File name>.vbs
  • %ProgramFiles%\avgdiag\<File name>.vbs
  • %ProgramFiles%\avgamsvr\<File name>.vbs
  • %ProgramFiles%\ashpopwz\<File name>.vbs
  • %ProgramFiles%\ashserv\<File name>.vbs
  • %ProgramFiles%\ashsimp2\<File name>.vbs
  • %ProgramFiles%\ashsimpl\<File name>.vbs
  • %ProgramFiles%\ashskpcc\<File name>.vbs
  • %ProgramFiles%\ashskpck\<File name>.vbs
  • %ProgramFiles%\ashupd\<File name>.vbs
  • %ProgramFiles%\ashwebsv\<File name>.vbs
  • %ProgramFiles%\ash_updatemediator\<File name>.vbs
  • %ProgramFiles%\b2\<File name>.vbs
  • %ProgramFiles%\backweb-4476822\<File name>.vbs
  • %ProgramFiles%\aswregsvr\<File name>.vbs
  • %ProgramFiles%\autostartexplorer\<File name>.vbs
  • %ProgramFiles%\autotrace\<File name>.vbs
  • %ProgramFiles%\avadmin\<File name>.vbs
  • %ProgramFiles%\avcenter\<File name>.vbs
  • %ProgramFiles%\avciman\<File name>.vbs
  • %ProgramFiles%\avcmd\<File name>.vbs
  • %ProgramFiles%\avconfig\<File name>.vbs
  • %ProgramFiles%\avconsol\<File name>.vbs
  • %ProgramFiles%\ashquick\<File name>.vbs
  • %ProgramFiles%\autodown\<File name>.vbs
  • %WINDIR%\system\<File name>.vbs
  • %ProgramFiles%\exit_av\<File name>.vbs
  • %ProgramFiles%\fameh32\<File name>.vbs
  • %ProgramFiles%\isuac\<File name>.vbs
  • %ProgramFiles%\itunes\<File name>.vbs
  • %ProgramFiles%\java\<File name>.vbs
  • %ProgramFiles%\k-meleon\<File name>.vbs
  • %ProgramFiles%\kav\<File name>.vbs
  • %ProgramFiles%\kavmm\<File name>.vbs
  • %ProgramFiles%\kavpf\<File name>.vbs
  • %ProgramFiles%\kavpfw\<File name>.vbs
  • %ProgramFiles%\kavstart\<File name>.vbs
  • %ProgramFiles%\kavsvc\<File name>.vbs
  • %ProgramFiles%\konnekt\<File name>.vbs
  • %ProgramFiles%\launcher\<File name>.vbs
  • %ProgramFiles%\licmgr\<File name>.vbs
  • %ProgramFiles%\livesrv\<File name>.vbs
  • %ProgramFiles%\liveupdate\<File name>.vbs
  • %ProgramFiles%\logwatnt\<File name>.vbs
  • %ProgramFiles%\lotroclient\<File name>.vbs
  • %ProgramFiles%\lpfw\<File name>.vbs
  • %ProgramFiles%\lucallbackproxy\<File name>.vbs
  • %ProgramFiles%\issvc\<File name>.vbs
  • %ProgramFiles%\lucheck\<File name>.vbs
  • %ProgramFiles%\ispwdsvc\<File name>.vbs
  • %ProgramFiles%\isafe\<File name>.vbs
  • %ProgramFiles%\ih8run\<File name>.vbs
  • %ProgramFiles%\ilaunchr\<File name>.vbs
  • %ProgramFiles%\imapp\<File name>.vbs
  • %ProgramFiles%\imnotfy\<File name>.vbs
  • %ProgramFiles%\impcnt\<File name>.vbs
  • %ProgramFiles%\incmail\<File name>.vbs
  • %ProgramFiles%\inocit\<File name>.vbs
  • %ProgramFiles%\inorpc\<File name>.vbs
  • %ProgramFiles%\inort\<File name>.vbs
  • %ProgramFiles%\inotask\<File name>.vbs
  • %ProgramFiles%\inouptng\<File name>.vbs
  • %ProgramFiles%\inphasenxd\<File name>.vbs
  • %ProgramFiles%\installcavs\<File name>.vbs
  • %ProgramFiles%\installlicense\<File name>.vbs
  • %ProgramFiles%\installlsp\<File name>.vbs
  • %ProgramFiles%\instlsp\<File name>.vbs
  • %ProgramFiles%\internet explorer\<File name>.vbs
  • %ProgramFiles%\iris\<File name>.vbs
  • %ProgramFiles%\iron\<File name>.vbs
  • %ProgramFiles%\ispnews\<File name>.vbs
  • %ProgramFiles%\luconfig\<File name>.vbs
  • %ProgramFiles%\luinit\<File name>.vbs
  • %ProgramFiles%\luupdate\<File name>.vbs
  • %ProgramFiles%\mp3tray\<File name>.vbs
  • %ProgramFiles%\mpeng\<File name>.vbs
  • %ProgramFiles%\mpftray\<File name>.vbs
  • %ProgramFiles%\mpssvc\<File name>.vbs
  • %ProgramFiles%\msbuild\<File name>.vbs
  • %ProgramFiles%\msimn\<File name>.vbs
  • %ProgramFiles%\msmpsvc\<File name>.vbs
  • %ProgramFiles%\ezantivirusregistrationcheck\<File name>.vbs
  • %ProgramFiles%\msn6\<File name>.vbs
  • %ProgramFiles%\mva\<File name>.vbs
  • %ProgramFiles%\mvc\<File name>.vbs
  • %ProgramFiles%\myagtsvc\<File name>.vbs
  • %ProgramFiles%\myagttry\<File name>.vbs
  • %ProgramFiles%\navapsvc\<File name>.vbs
  • %ProgramFiles%\navlu32\<File name>.vbs
  • %ProgramFiles%\navstub\<File name>.vbs
  • %ProgramFiles%\navw32\<File name>.vbs
  • %ProgramFiles%\mp3theater\<File name>.vbs
  • %ProgramFiles%\msnmsgr\<File name>.vbs
  • %ProgramFiles%\mp3toystray\<File name>.vbs
  • %ProgramFiles%\mp3toys\<File name>.vbs
  • %ProgramFiles%\monsysnt\<File name>.vbs
  • %ProgramFiles%\monlite\<File name>.vbs
  • %ProgramFiles%\magent\<File name>.vbs
  • %ProgramFiles%\malwareremoval\<File name>.vbs
  • %ProgramFiles%\maplestory\<File name>.vbs
  • %ProgramFiles%\maxthon\<File name>.vbs
  • %ProgramFiles%\mcmnhdlr\<File name>.vbs
  • %ProgramFiles%\mcregwiz\<File name>.vbs
  • %ProgramFiles%\mcshield\<File name>.vbs
  • %ProgramFiles%\iexplore\<File name>.vbs
  • %ProgramFiles%\mcupdmgr\<File name>.vbs
  • %ProgramFiles%\ih8\<File name>.vbs
  • %ProgramFiles%\memstring\<File name>.vbs
  • %ProgramFiles%\microsoft analysis services\<File name>.vbs
  • %ProgramFiles%\microsoft office\<File name>.vbs
  • %ProgramFiles%\microsoft sql server compact edition\<File name>.vbs
  • %ProgramFiles%\microsoft sync framework\<File name>.vbs
  • %ProgramFiles%\microsoft synchronization services\<File name>.vbs
  • %ProgramFiles%\mir3game\<File name>.vbs
  • %ProgramFiles%\miranda32\<File name>.vbs
  • %ProgramFiles%\luna\<File name>.vbs
  • %ProgramFiles%\miro\<File name>.vbs
  • %ProgramFiles%\mfpmp\<File name>.vbs
  • %ProgramFiles%\f-sched\<File name>.vbs
  • %ProgramFiles%\mcvsshld\<File name>.vbs
  • %ProgramFiles%\cavq\<File name>.vbs
  • %ProgramFiles%\fsav\<File name>.vbs
  • %ProgramFiles%\fsav32\<File name>.vbs
  • %ProgramFiles%\fsavaui\<File name>.vbs
  • %ProgramFiles%\fsavgui\<File name>.vbs
  • %ProgramFiles%\fsavstrt\<File name>.vbs
  • %ProgramFiles%\fsavwsch\<File name>.vbs
  • %ProgramFiles%\fsavwscr\<File name>.vbs
  • %ProgramFiles%\fsbwsys\<File name>.vbs
  • %ProgramFiles%\fsdbuh\<File name>.vbs
  • %ProgramFiles%\fsdc\<File name>.vbs
  • %ProgramFiles%\fsdfwd\<File name>.vbs
  • %ProgramFiles%\fsdiag\<File name>.vbs
  • %ProgramFiles%\fsdiagui\<File name>.vbs
  • %ProgramFiles%\fsfwwsch\<File name>.vbs
  • %ProgramFiles%\fsfwwscr\<File name>.vbs
  • %ProgramFiles%\fsgetwab\<File name>.vbs
  • %ProgramFiles%\fsgk32\<File name>.vbs
  • %ProgramFiles%\fsgk32st\<File name>.vbs
  • %ProgramFiles%\fsguidll\<File name>.vbs
  • %ProgramFiles%\fsauach\<File name>.vbs
  • %ProgramFiles%\fsguiexe\<File name>.vbs
  • %ProgramFiles%\fsaua\<File name>.vbs
  • %ProgramFiles%\freshclam\<File name>.vbs
  • %ProgramFiles%\far\<File name>.vbs
  • %ProgramFiles%\fch32\<File name>.vbs
  • %ProgramFiles%\fdm\<File name>.vbs
  • %ProgramFiles%\fdmwi\<File name>.vbs
  • %ProgramFiles%\filezilla\<File name>.vbs
  • %ProgramFiles%\firebird\<File name>.vbs
  • %ProgramFiles%\firefox\<File name>.vbs
  • %ProgramFiles%\firesvc\<File name>.vbs
  • %ProgramFiles%\firetray\<File name>.vbs
  • %ProgramFiles%\flashfxp\<File name>.vbs
  • %ProgramFiles%\flashgot\<File name>.vbs
  • %ProgramFiles%\flock\<File name>.vbs
  • %ProgramFiles%\foxit\<File name>.vbs
  • %ProgramFiles%\fpavserver\<File name>.vbs
  • %ProgramFiles%\fpavupdm\<File name>.vbs
  • %ProgramFiles%\fprottray\<File name>.vbs
  • %ProgramFiles%\fpscan\<File name>.vbs
  • %ProgramFiles%\fptrayproc\<File name>.vbs
  • %ProgramFiles%\fpwin\<File name>.vbs
  • %ProgramFiles%\fsample\<File name>.vbs
  • %ProgramFiles%\fshdll32\<File name>.vbs
  • %ProgramFiles%\fshelp\<File name>.vbs
  • %ProgramFiles%\fsihcomp\<File name>.vbs
  • %ProgramFiles%\gnotify\<File name>.vbs
  • %ProgramFiles%\googledesktop\<File name>.vbs
  • %ProgramFiles%\googletalk\<File name>.vbs
  • %ProgramFiles%\googleupdate\<File name>.vbs
  • %ProgramFiles%\guardgni\<File name>.vbs
  • %ProgramFiles%\guardnt\<File name>.vbs
  • %ProgramFiles%\gw\<File name>.vbs
  • %ProgramFiles%\icqlite\<File name>.vbs
  • %ProgramFiles%\helpctr\<File name>.vbs
  • %ProgramFiles%\hipsdiag\<File name>.vbs
  • %ProgramFiles%\hregmon\<File name>.vbs
  • %ProgramFiles%\hrres\<File name>.vbs
  • %ProgramFiles%\hsockpe\<File name>.vbs
  • %ProgramFiles%\httplook\<File name>.vbs
  • %ProgramFiles%\iamapp\<File name>.vbs
  • %ProgramFiles%\iamserv\<File name>.vbs
  • %ProgramFiles%\icq\<File name>.vbs
  • %ProgramFiles%\gg\<File name>.vbs
  • %ProgramFiles%\helper\<File name>.vbs
  • %ProgramFiles%\giantantispywareupdater\<File name>.vbs
  • %ProgramFiles%\giantantispywaremain\<File name>.vbs
  • %ProgramFiles%\ge\<File name>.vbs
  • %ProgramFiles%\gcasserv\<File name>.vbs
  • %ProgramFiles%\fsihs\<File name>.vbs
  • %ProgramFiles%\fslaunch\<File name>.vbs
  • %ProgramFiles%\fsm32\<File name>.vbs
  • %ProgramFiles%\fsma32\<File name>.vbs
  • %ProgramFiles%\fsmb32\<File name>.vbs
  • %ProgramFiles%\fspc\<File name>.vbs
  • %ProgramFiles%\fspex\<File name>.vbs
  • %ProgramFiles%\ieregfix\<File name>.vbs
  • %ProgramFiles%\fsqh\<File name>.vbs
  • %ProgramFiles%\ieuser\<File name>.vbs
  • %ProgramFiles%\fssg\<File name>.vbs
  • %ProgramFiles%\fsstm\<File name>.vbs
  • %ProgramFiles%\fssw\<File name>.vbs
  • %ProgramFiles%\fstlui\<File name>.vbs
  • %ProgramFiles%\fsuninst\<File name>.vbs
  • %ProgramFiles%\fsus\<File name>.vbs
  • %ProgramFiles%\ftpte\<File name>.vbs
  • %ProgramFiles%\gc\<File name>.vbs
  • %ProgramFiles%\fshotfix\<File name>.vbs
  • %ProgramFiles%\gcasdtserv\<File name>.vbs
  • %ProgramFiles%\fssm32\<File name>.vbs
  • D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\<File name>.vbs
Sets the 'hidden' attribute to the following files
  • <Drive name for removable media>:\<File name>.vbs
  • %ProgramFiles%\scanningprocess\<File name>.vbs
  • %ProgramFiles%\sched\<File name>.vbs
  • %ProgramFiles%\sdhelp\<File name>.vbs
  • %ProgramFiles%\sdinvoker\<File name>.vbs
  • %ProgramFiles%\sdloader\<File name>.vbs
  • %ProgramFiles%\sdraw\<File name>.vbs
  • %ProgramFiles%\sdtrayapp\<File name>.vbs
  • %ProgramFiles%\seamonkey\<File name>.vbs
  • %ProgramFiles%\seccenter\<File name>.vbs
  • %ProgramFiles%\sfagent\<File name>.vbs
  • %ProgramFiles%\sigtool\<File name>.vbs
  • %ProgramFiles%\simpress\<File name>.vbs
  • %ProgramFiles%\sitecli\<File name>.vbs
  • %ProgramFiles%\skype\<File name>.vbs
  • %ProgramFiles%\skypepm\<File name>.vbs
  • %ProgramFiles%\smartftp\<File name>.vbs
  • %ProgramFiles%\smath\<File name>.vbs
  • %ProgramFiles%\smc\<File name>.vbs
  • %ProgramFiles%\sndsrvc\<File name>.vbs
  • %ProgramFiles%\scanner\<File name>.vbs
  • %ProgramFiles%\sniffer\<File name>.vbs
  • %ProgramFiles%\scalc\<File name>.vbs
  • %ProgramFiles%\savscan\<File name>.vbs
  • %ProgramFiles%\ravtimer\<File name>.vbs
  • %ProgramFiles%\rcimlby\<File name>.vbs
  • %ProgramFiles%\realmon\<File name>.vbs
  • %ProgramFiles%\reference assemblies\<File name>.vbs
  • %ProgramFiles%\register\<File name>.vbs
  • %ProgramFiles%\removeit\<File name>.vbs
  • %ProgramFiles%\remover\<File name>.vbs
  • %ProgramFiles%\rescue\<File name>.vbs
  • %ProgramFiles%\rfwmain\<File name>.vbs
  • %ProgramFiles%\rq\<File name>.vbs
  • %ProgramFiles%\rtvscan\<File name>.vbs
  • %ProgramFiles%\rulaunch\<File name>.vbs
  • %ProgramFiles%\runsetup\<File name>.vbs
  • %ProgramFiles%\safari\<File name>.vbs
  • %ProgramFiles%\sarcli\<File name>.vbs
  • %ProgramFiles%\sargui\<File name>.vbs
  • %ProgramFiles%\savadminservice\<File name>.vbs
  • %ProgramFiles%\savmain\<File name>.vbs
  • %ProgramFiles%\savprogress\<File name>.vbs
  • %ProgramFiles%\sbase\<File name>.vbs
  • %ProgramFiles%\so3d\<File name>.vbs
  • %ProgramFiles%\soffice\<File name>.vbs
  • %ProgramFiles%\spamcfg\<File name>.vbs
  • %ProgramFiles%\tca\<File name>.vbs
  • %ProgramFiles%\teatimer\<File name>.vbs
  • %ProgramFiles%\tgsvcstp\<File name>.vbs
  • %ProgramFiles%\thebat\<File name>.vbs
  • %ProgramFiles%\thgnard\<File name>.vbs
  • %ProgramFiles%\thunderbird\<File name>.vbs
  • %ProgramFiles%\tmas\<File name>.vbs
  • %ProgramFiles%\tmlisten\<File name>.vbs
  • %ProgramFiles%\trtddptr\<File name>.vbs
  • %ProgramFiles%\tmntsrv\<File name>.vbs
  • %ProgramFiles%\tmproxy\<File name>.vbs
  • %ProgramFiles%\tnbutil\<File name>.vbs
  • %ProgramFiles%\totalcmd\<File name>.vbs
  • %ProgramFiles%\tracelog\<File name>.vbs
  • %ProgramFiles%\traymon\<File name>.vbs
  • %ProgramFiles%\trillian\<File name>.vbs
  • %ProgramFiles%\trojanguarder\<File name>.vbs
  • %ProgramFiles%\trojanhunter\<File name>.vbs
  • %ProgramFiles%\sysinfo\<File name>.vbs
  • %ProgramFiles%\tbmon\<File name>.vbs
  • %ProgramFiles%\symwsc\<File name>.vbs
  • %ProgramFiles%\symsport\<File name>.vbs
  • %ProgramFiles%\symproxysvc\<File name>.vbs
  • %ProgramFiles%\spider\<File name>.vbs
  • %ProgramFiles%\spiderml\<File name>.vbs
  • %ProgramFiles%\spidernt\<File name>.vbs
  • %ProgramFiles%\spiderui\<File name>.vbs
  • %ProgramFiles%\sporder\<File name>.vbs
  • %ProgramFiles%\spybotsd\<File name>.vbs
  • %ProgramFiles%\sro_client\<File name>.vbs
  • %ProgramFiles%\start_diag\<File name>.vbs
  • %ProgramFiles%\ravmon\<File name>.vbs
  • %ProgramFiles%\streetsolkshim\<File name>.vbs
  • %ProgramFiles%\stopsignav\<File name>.vbs
  • %ProgramFiles%\svcntaux\<File name>.vbs
  • %ProgramFiles%\swagent\<File name>.vbs
  • %ProgramFiles%\swdoctor\<File name>.vbs
  • %ProgramFiles%\swdsvc\<File name>.vbs
  • %ProgramFiles%\sweb\<File name>.vbs
  • %ProgramFiles%\swriter\<File name>.vbs
  • %ProgramFiles%\symantecrootinstaller\<File name>.vbs
  • %ProgramFiles%\symlcsvc\<File name>.vbs
  • %ProgramFiles%\spbbcsvc\<File name>.vbs
  • %ProgramFiles%\submitfiles\<File name>.vbs
  • %ProgramFiles%\tmpfw\<File name>.vbs
  • %ProgramFiles%\rat\<File name>.vbs
  • %ProgramFiles%\pxsupport\<File name>.vbs
  • %ProgramFiles%\oaui\<File name>.vbs
  • %ProgramFiles%\ofcpfwsvc\<File name>.vbs
  • %ProgramFiles%\oget\<File name>.vbs
  • %ProgramFiles%\oladdin\<File name>.vbs
  • %ProgramFiles%\onaccessinstaller\<File name>.vbs
  • %ProgramFiles%\opera\<File name>.vbs
  • %ProgramFiles%\oscheck\<File name>.vbs
  • %ProgramFiles%\outlook\<File name>.vbs
  • %ProgramFiles%\outpost\<File name>.vbs
  • %ProgramFiles%\partin\<File name>.vbs
  • %ProgramFiles%\partin9x\<File name>.vbs
  • %ProgramFiles%\partinfo\<File name>.vbs
  • %ProgramFiles%\partinnt\<File name>.vbs
  • %ProgramFiles%\pavfires\<File name>.vbs
  • %ProgramFiles%\pavfnsvr\<File name>.vbs
  • %ProgramFiles%\pavkre\<File name>.vbs
  • %ProgramFiles%\pavprot\<File name>.vbs
  • %ProgramFiles%\pavproxy\<File name>.vbs
  • %ProgramFiles%\pavprsrv\<File name>.vbs
  • %ProgramFiles%\oasrv\<File name>.vbs
  • %ProgramFiles%\pavsrv51\<File name>.vbs
  • %ProgramFiles%\nwservice\<File name>.vbs
  • %ProgramFiles%\nvcte\<File name>.vbs
  • %ProgramFiles%\netstatviewer\<File name>.vbs
  • %ProgramFiles%\netxray\<File name>.vbs
  • %ProgramFiles%\nisoptui\<File name>.vbs
  • %ProgramFiles%\nod\<File name>.vbs
  • %ProgramFiles%\nod32\<File name>.vbs
  • %ProgramFiles%\nod32krn\<File name>.vbs
  • %ProgramFiles%\nod32kui\<File name>.vbs
  • %ProgramFiles%\notifyha\<File name>.vbs
  • %ProgramFiles%\notstart\<File name>.vbs
  • %ProgramFiles%\npavtray\<File name>.vbs
  • %ProgramFiles%\npfmsg\<File name>.vbs
  • %ProgramFiles%\nsmdtr\<File name>.vbs
  • %ProgramFiles%\nssserv\<File name>.vbs
  • %ProgramFiles%\nsstray\<File name>.vbs
  • %ProgramFiles%\ntoskrnl\<File name>.vbs
  • %ProgramFiles%\ntrtscan\<File name>.vbs
  • %ProgramFiles%\ntxconfig\<File name>.vbs
  • %ProgramFiles%\nupgrade\<File name>.vbs
  • %ProgramFiles%\nvcod\<File name>.vbs
  • %ProgramFiles%\nvcut\<File name>.vbs
  • %ProgramFiles%\pccguide\<File name>.vbs
  • %ProgramFiles%\pccntmon\<File name>.vbs
  • %ProgramFiles%\pccpfw\<File name>.vbs
  • %ProgramFiles%\ps\<File name>.vbs
  • %ProgramFiles%\psctrls\<File name>.vbs
  • %ProgramFiles%\pshost\<File name>.vbs
  • %ProgramFiles%\psimsvc\<File name>.vbs
  • %ProgramFiles%\pxagent\<File name>.vbs
  • %ProgramFiles%\pxconsole\<File name>.vbs
  • %ProgramFiles%\pxl\<File name>.vbs
  • %ProgramFiles%\pxl1\<File name>.vbs
  • %ProgramFiles%\ragfree\<File name>.vbs
  • %ProgramFiles%\pxreset\<File name>.vbs
  • %ProgramFiles%\python\<File name>.vbs
  • %ProgramFiles%\qhwscsvc\<File name>.vbs
  • %ProgramFiles%\qip\<File name>.vbs
  • %ProgramFiles%\qklez\<File name>.vbs
  • %ProgramFiles%\qrtfix\<File name>.vbs
  • %ProgramFiles%\quaranti\<File name>.vbs
  • %ProgramFiles%\quickstart\<File name>.vbs
  • %ProgramFiles%\ragexe\<File name>.vbs
  • %ProgramFiles%\processviewer\<File name>.vbs
  • %ProgramFiles%\protect\<File name>.vbs
  • %ProgramFiles%\privatebrowser\<File name>.vbs
  • %ProgramFiles%\prevxsetup\<File name>.vbs
  • %ProgramFiles%\prevsrv\<File name>.vbs
  • %ProgramFiles%\pctav\<File name>.vbs
  • %ProgramFiles%\pertsk\<File name>.vbs
  • %ProgramFiles%\pidgin\<File name>.vbs
  • %ProgramFiles%\pm\<File name>.vbs
  • %ProgramFiles%\pm8flash\<File name>.vbs
  • %ProgramFiles%\pmagic\<File name>.vbs
  • %ProgramFiles%\pmagic9x\<File name>.vbs
  • %ProgramFiles%\pmagicbt\<File name>.vbs
  • %ProgramFiles%\rapget\<File name>.vbs
  • %ProgramFiles%\polutil\<File name>.vbs
  • %ProgramFiles%\pmagicnt\<File name>.vbs
  • %ProgramFiles%\ppfw\<File name>.vbs
  • %ProgramFiles%\pqboot32\<File name>.vbs
  • %ProgramFiles%\pqbw\<File name>.vbs
  • %ProgramFiles%\pqpe\<File name>.vbs
  • %ProgramFiles%\pqpe9x\<File name>.vbs
  • %ProgramFiles%\pqpent\<File name>.vbs
  • %ProgramFiles%\preconfig\<File name>.vbs
  • %ProgramFiles%\preupd\<File name>.vbs
  • %ProgramFiles%\pcctlcom\<File name>.vbs
  • %ProgramFiles%\postinstall\<File name>.vbs
  • %ProgramFiles%\twelvesky2\<File name>.vbs
  • %ProgramFiles%\uiscan\<File name>.vbs
  • %ProgramFiles%\una\<File name>.vbs
  • %PROGRAMDATA%\microsoft toolkit\<File name>.vbs
  • %PROGRAMDATA%\mozilla\<File name>.vbs
  • %PROGRAMDATA%\oracle\<File name>.vbs
  • %PROGRAMDATA%\package cache\<File name>.vbs
  • %PROGRAMDATA%\start menu\<File name>.vbs
  • %PROGRAMDATA%\sun\<File name>.vbs
  • %PROGRAMDATA%\templates\<File name>.vbs
  • C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\<File name>.vbs
  • %WINDIR%\cursors\<File name>.vbs
  • C:\totalcmd\language\<File name>.vbs
  • C:\users\public\<File name>.vbs
  • %HOMEPATH%\<File name>.vbs
  • %WINDIR%\addins\<File name>.vbs
  • %WINDIR%\appcompat\<File name>.vbs
  • %WINDIR%\apppatch\<File name>.vbs
  • %WINDIR%\assembly\<File name>.vbs
  • %WINDIR%\bitlockerdiscoveryvolumecontents\<File name>.vbs
  • %WINDIR%\branding\<File name>.vbs
  • %PROGRAMDATA%\microsoft\<File name>.vbs
  • %PROGRAMDATA%\microsoft help\<File name>.vbs
  • C:\users\default\<File name>.vbs
  • %WINDIR%\csc\<File name>.vbs
  • %PROGRAMDATA%\desktop\<File name>.vbs
  • %ProgramFiles(x86)%\msbuild\<File name>.vbs
  • %ProgramFiles(x86)%\opera\<File name>.vbs
  • %ProgramFiles(x86)%\pidgin\<File name>.vbs
  • %ProgramFiles(x86)%\qip 2012\<File name>.vbs
  • %ProgramFiles(x86)%\reference assemblies\<File name>.vbs
  • %ProgramFiles(x86)%\steam\<File name>.vbs
  • %ProgramFiles(x86)%\uninstall information\<File name>.vbs
  • %ProgramFiles(x86)%\winamp\<File name>.vbs
  • %ProgramFiles(x86)%\windows defender\<File name>.vbs
  • %ProgramFiles(x86)%\windows mail\<File name>.vbs
  • %ProgramFiles(x86)%\windows media player\<File name>.vbs
  • %ProgramFiles(x86)%\windows nt\<File name>.vbs
  • %ProgramFiles(x86)%\windows photo viewer\<File name>.vbs
  • %ProgramFiles(x86)%\windows portable devices\<File name>.vbs
  • %ProgramFiles(x86)%\windows sidebar\<File name>.vbs
  • %PROGRAMDATA%\adobe\<File name>.vbs
  • %PROGRAMDATA%\application data\<File name>.vbs
  • %PROGRAMDATA%\documents\<File name>.vbs
  • %ProgramFiles(x86)%\mozilla firefox\<File name>.vbs
  • %PROGRAMDATA%\favorites\<File name>.vbs
  • %WINDIR%\web\<File name>.vbs
  • %WINDIR%\debug\<File name>.vbs
  • %WINDIR%\remotepackages\<File name>.vbs
  • %WINDIR%\schcache\<File name>.vbs
  • %WINDIR%\schemas\<File name>.vbs
  • %WINDIR%\security\<File name>.vbs
  • %WINDIR%\serviceprofiles\<File name>.vbs
  • %WINDIR%\setup\<File name>.vbs
  • %WINDIR%\shellnew\<File name>.vbs
  • %WINDIR%\softwaredistribution\<File name>.vbs
  • %WINDIR%\speech\<File name>.vbs
  • %WINDIR%\digitallocker\<File name>.vbs
  • %WINDIR%\system\<File name>.vbs
  • %WINDIR%\syswow64\<File name>.vbs
  • %WINDIR%\tapi\<File name>.vbs
  • %WINDIR%\tasks\<File name>.vbs
  • %WINDIR%\temp\<File name>.vbs
  • %WINDIR%\tracing\<File name>.vbs
  • %WINDIR%\twain_32\<File name>.vbs
  • %WINDIR%\vss\<File name>.vbs
  • %WINDIR%\registration\<File name>.vbs
  • %WINDIR%\prefetch\<File name>.vbs
  • %WINDIR%\resources\<File name>.vbs
  • %WINDIR%\policydefinitions\<File name>.vbs
  • %WINDIR%\pla\<File name>.vbs
  • %WINDIR%\downloaded program files\<File name>.vbs
  • %WINDIR%\en-us\<File name>.vbs
  • %WINDIR%\fonts\<File name>.vbs
  • %WINDIR%\globalization\<File name>.vbs
  • %WINDIR%\help\<File name>.vbs
  • %WINDIR%\ime\<File name>.vbs
  • %WINDIR%\inf\<File name>.vbs
  • %WINDIR%\installer\<File name>.vbs
  • %ProgramFiles(x86)%\mirc\<File name>.vbs
  • %WINDIR%\l2schemas\<File name>.vbs
  • %ProgramFiles(x86)%\mozilla thunderbird\<File name>.vbs
  • %WINDIR%\logs\<File name>.vbs
  • %WINDIR%\microsoft.net\<File name>.vbs
  • %WINDIR%\migration\<File name>.vbs
  • %WINDIR%\modemlogs\<File name>.vbs
  • %WINDIR%\offline web pages\<File name>.vbs
  • %WINDIR%\panther\<File name>.vbs
  • %WINDIR%\pchealth\<File name>.vbs
  • %WINDIR%\performance\<File name>.vbs
  • %WINDIR%\livekernelreports\<File name>.vbs
  • %WINDIR%\ehome\<File name>.vbs
  • %WINDIR%\media\<File name>.vbs
  • %ProgramFiles(x86)%\microsoft.net\<File name>.vbs
  • %ProgramFiles(x86)%\microsoft visual studio 8\<File name>.vbs
  • %ProgramFiles(x86)%\microsoft visual studio .net 2003\<File name>.vbs
  • %ProgramFiles%\virusnews\<File name>.vbs
  • %ProgramFiles%\vistaux\<File name>.vbs
  • %ProgramFiles%\visthlic\<File name>.vbs
  • %ProgramFiles%\visthupd\<File name>.vbs
  • %ProgramFiles%\vrfwsvc\<File name>.vbs
  • %ProgramFiles%\vrmonsvc\<File name>.vbs
  • %ProgramFiles%\vrrw32\<File name>.vbs
  • %ProgramFiles%\vshwin32\<File name>.vbs
  • %ProgramFiles%\vsmon\<File name>.vbs
  • %ProgramFiles%\vsserv\<File name>.vbs
  • %ProgramFiles%\vsstat\<File name>.vbs
  • %ProgramFiles%\wclose\<File name>.vbs
  • %ProgramFiles%\webfiltr\<File name>.vbs
  • %ProgramFiles%\webmoney\<File name>.vbs
  • %ProgramFiles%\webproxy\<File name>.vbs
  • %ProgramFiles%\webscanx\<File name>.vbs
  • %ProgramFiles%\wil\<File name>.vbs
  • %ProgramFiles%\viritexp\<File name>.vbs
  • %ProgramFiles%\vcrmon\<File name>.vbs
  • %ProgramFiles%\viruskeeper\<File name>.vbs
  • %ProgramFiles%\vettray\<File name>.vbs
  • %ProgramFiles%\vchk\<File name>.vbs
  • %ProgramFiles%\updclient\<File name>.vbs
  • %ProgramFiles%\uninstallcavs\<File name>.vbs
  • %ProgramFiles%\uninstaller\<File name>.vbs
  • %ProgramFiles%\uninstalllsp\<File name>.vbs
  • %ProgramFiles%\unoinfo\<File name>.vbs
  • %ProgramFiles%\unopkg\<File name>.vbs
  • %ProgramFiles%\unp_test\<File name>.vbs
  • %ProgramFiles%\up2date\<File name>.vbs
  • %ProgramFiles%\updater\<File name>.vbs
  • %ProgramFiles%\winaw32\<File name>.vbs
  • %ProgramFiles%\neowatchtray\<File name>.vbs
  • %ProgramFiles%\updaterui\<File name>.vbs
  • %ProgramFiles%\upsobmaker\<File name>.vbs
  • %ProgramFiles%\usdownloader\<File name>.vbs
  • %ProgramFiles%\uupd\<File name>.vbs
  • %ProgramFiles%\vba32ecm\<File name>.vbs
  • %ProgramFiles%\vba32ifs\<File name>.vbs
  • %ProgramFiles%\vba32ldr\<File name>.vbs
  • %ProgramFiles%\vba32pp3\<File name>.vbs
  • %ProgramFiles%\vbsntw\<File name>.vbs
  • %ProgramFiles%\uninstall information\<File name>.vbs
  • %ProgramFiles%\upgrepl\<File name>.vbs
  • %ProgramFiles%\winrar\<File name>.vbs
  • %ProgramFiles%\winbaram\<File name>.vbs
  • %ProgramFiles%\windows journal\<File name>.vbs
  • %ProgramFiles%\xcommsvr\<File name>.vbs
  • %ProgramFiles%\yahoomessenger\<File name>.vbs
  • %ProgramFiles%\yahoosync\<File name>.vbs
  • %ProgramFiles%\ybclient\<File name>.vbs
  • %ProgramFiles%\ymsgr_tray\<File name>.vbs
  • %ProgramFiles%\zapro\<File name>.vbs
  • %ProgramFiles%\zatutor\<File name>.vbs
  • %ProgramFiles%\viritsvc\<File name>.vbs
  • %ProgramFiles%\zauninst\<File name>.vbs
  • %ProgramFiles%\zonealarm\<File name>.vbs
  • %ProgramFiles(x86)%\adobe\<File name>.vbs
  • %CommonProgramFiles(x86)%\<File name>.vbs
  • %ProgramFiles(x86)%\google\<File name>.vbs
  • %ProgramFiles(x86)%\internet explorer\<File name>.vbs
  • %ProgramFiles(x86)%\k-lite codec pack\<File name>.vbs
  • %ProgramFiles(x86)%\microsoft analysis services\<File name>.vbs
  • %ProgramFiles(x86)%\microsoft office\<File name>.vbs
  • %ProgramFiles%\wsctool\<File name>.vbs
  • %ProgramFiles%\zlclient\<File name>.vbs
  • %ProgramFiles%\wsm\<File name>.vbs
  • %ProgramFiles%\wsftpgui\<File name>.vbs
  • %ProgramFiles%\writespid\<File name>.vbs
  • %ProgramFiles%\wrctrl\<File name>.vbs
  • %ProgramFiles%\windows mail\<File name>.vbs
  • %ProgramFiles%\windows media player\<File name>.vbs
  • %ProgramFiles%\windows nt\<File name>.vbs
  • %ProgramFiles%\windows photo viewer\<File name>.vbs
  • %ProgramFiles%\windows portable devices\<File name>.vbs
  • %ProgramFiles%\windows sidebar\<File name>.vbs
  • %ProgramFiles%\windump\<File name>.vbs
  • %ProgramFiles%\wincmd32\<File name>.vbs
  • %ProgramFiles%\winmail\<File name>.vbs
  • %ProgramFiles%\windowlist\<File name>.vbs
  • %ProgramFiles%\winroute\<File name>.vbs
  • %ProgramFiles%\winssnotify\<File name>.vbs
  • %ProgramFiles%\wish\<File name>.vbs
  • %ProgramFiles%\wlloginproxy\<File name>.vbs
  • %ProgramFiles%\wlmail\<File name>.vbs
  • %ProgramFiles%\wltuser\<File name>.vbs
  • %ProgramFiles%\woool\<File name>.vbs
  • %ProgramFiles%\wow\<File name>.vbs
  • %ProgramFiles%\windows defender\<File name>.vbs
  • %ProgramFiles%\wradmin\<File name>.vbs
  • %ProgramFiles%\winss\<File name>.vbs
  • <SYSTEM32>\<File name>.vbs
  • %ProgramFiles%\neowatchlog\<File name>.vbs
  • %ProgramFiles%\msnmsgr\<File name>.vbs
  • %ProgramFiles%\cavmud\<File name>.vbs
  • %ProgramFiles%\cavoar\<File name>.vbs
  • %ProgramFiles%\cavq\<File name>.vbs
  • %ProgramFiles%\cavscons\<File name>.vbs
  • %ProgramFiles%\cavse\<File name>.vbs
  • %ProgramFiles%\cavsn\<File name>.vbs
  • %ProgramFiles%\cavsub\<File name>.vbs
  • %ProgramFiles%\cavsubmit\<File name>.vbs
  • %ProgramFiles%\cavumas\<File name>.vbs
  • %ProgramFiles%\cavuserupd\<File name>.vbs
  • %ProgramFiles%\cavvl\<File name>.vbs
  • %ProgramFiles%\ccapp\<File name>.vbs
  • %ProgramFiles%\ccevtmgr\<File name>.vbs
  • %ProgramFiles%\ccleaner\<File name>.vbs
  • %ProgramFiles%\ccproxy\<File name>.vbs
  • %ProgramFiles%\ccsetmgr\<File name>.vbs
  • %ProgramFiles%\cemrep\<File name>.vbs
  • %ProgramFiles%\chrome\<File name>.vbs
  • %ProgramFiles%\clamscan\<File name>.vbs
  • %ProgramFiles%\cavmr\<File name>.vbs
  • %ProgramFiles%\clamtray\<File name>.vbs
  • %ProgramFiles%\cavemsrv\<File name>.vbs
  • %ProgramFiles%\cavasm\<File name>.vbs
  • %ProgramFiles%\backweb-4476822\<File name>.vbs
  • %ProgramFiles%\bdagent\<File name>.vbs
  • %ProgramFiles%\bdmcon\<File name>.vbs
  • %ProgramFiles%\bdnews\<File name>.vbs
  • %ProgramFiles%\bdoesrv\<File name>.vbs
  • %ProgramFiles%\bdss\<File name>.vbs
  • %ProgramFiles%\bdsubmit\<File name>.vbs
  • %ProgramFiles%\bdsubmitwiz\<File name>.vbs
  • %ProgramFiles%\bdsurvey\<File name>.vbs
  • %ProgramFiles%\bdswitch\<File name>.vbs
  • %ProgramFiles%\bdwizreg\<File name>.vbs
  • %ProgramFiles%\blackd\<File name>.vbs
  • %ProgramFiles%\blackice\<File name>.vbs
  • %ProgramFiles%\blindman\<File name>.vbs
  • %ProgramFiles%\btini\<File name>.vbs
  • %ProgramFiles%\btinint\<File name>.vbs
  • %ProgramFiles%\cabalmain\<File name>.vbs
  • %ProgramFiles%\cafix\<File name>.vbs
  • %ProgramFiles%\cavapp\<File name>.vbs
  • %ProgramFiles%\cavaud\<File name>.vbs
  • %ProgramFiles%\clamwin\<File name>.vbs
  • %ProgramFiles%\claw95\<File name>.vbs
  • %ProgramFiles%\claw95cf\<File name>.vbs
  • %ProgramFiles%\dpatrolq\<File name>.vbs
  • %ProgramFiles%\drvctl\<File name>.vbs
  • %ProgramFiles%\drvirus\<File name>.vbs
  • %ProgramFiles%\drvmap\<File name>.vbs
  • %ProgramFiles%\drwadins\<File name>.vbs
  • %ProgramFiles%\drweb\<File name>.vbs
  • %ProgramFiles%\drweb32w\<File name>.vbs
  • %ProgramFiles%\drweb386\<File name>.vbs
  • %ProgramFiles%\etherd\<File name>.vbs
  • %ProgramFiles%\drwebscd\<File name>.vbs
  • %ProgramFiles%\drwebwcl\<File name>.vbs
  • %ProgramFiles%\drwreg\<File name>.vbs
  • %ProgramFiles%\dvd maker\<File name>.vbs
  • %ProgramFiles%\ecmd\<File name>.vbs
  • %ProgramFiles%\egni\<File name>.vbs
  • %ProgramFiles%\ehsniffer\<File name>.vbs
  • %ProgramFiles%\ekrn\<File name>.vbs
  • %ProgramFiles%\elementclient\<File name>.vbs
  • %ProgramFiles%\dislite\<File name>.vbs
  • %ProgramFiles%\dnf\<File name>.vbs
  • %ProgramFiles%\directftp\<File name>.vbs
  • %ProgramFiles%\digsby-app\<File name>.vbs
  • %ProgramFiles%\digsby\<File name>.vbs
  • %ProgramFiles%\cleaner3\<File name>.vbs
  • %ProgramFiles%\clisvc\<File name>.vbs
  • %ProgramFiles%\clrcche\<File name>.vbs
  • %ProgramFiles%\cmain\<File name>.vbs
  • %ProgramFiles%\cmgrdian\<File name>.vbs
  • %CommonProgramFiles%\<File name>.vbs
  • %ProgramFiles%\copyx64\<File name>.vbs
  • %ProgramFiles%\courier\<File name>.vbs
  • %ProgramFiles%\b2\<File name>.vbs
  • %ProgramFiles%\csendto\<File name>.vbs
  • %ProgramFiles%\cpd\<File name>.vbs
  • %ProgramFiles%\custinstall\<File name>.vbs
  • %ProgramFiles%\custsetup\<File name>.vbs
  • %ProgramFiles%\cuteftp\<File name>.vbs
  • %ProgramFiles%\dbconvert\<File name>.vbs
  • %ProgramFiles%\dbtool\<File name>.vbs
  • %ProgramFiles%\defensewall\<File name>.vbs
  • %ProgramFiles%\defwatch\<File name>.vbs
  • %ProgramFiles%\dekaron\<File name>.vbs
  • %ProgramFiles%\cleaner\<File name>.vbs
  • %ProgramFiles%\cssexc\<File name>.vbs
  • %ProgramFiles%\drwebupw\<File name>.vbs
  • %ProgramFiles%\avsynmgr\<File name>.vbs
  • %ProgramFiles%\avgvv\<File name>.vbs
  • %ProgramFiles%\agb5\<File name>.vbs
  • %ProgramFiles%\ageofconan\<File name>.vbs
  • %ProgramFiles%\ahnsd\<File name>.vbs
  • %ProgramFiles%\aim6\<File name>.vbs
  • %ProgramFiles%\aimpro\<File name>.vbs
  • %ProgramFiles%\airdefense\<File name>.vbs
  • %ProgramFiles%\almon\<File name>.vbs
  • %ProgramFiles%\alsvc\<File name>.vbs
  • %ProgramFiles%\amon\<File name>.vbs
  • %ProgramFiles%\amsn\<File name>.vbs
  • %ProgramFiles%\anti-trojan\<File name>.vbs
  • %ProgramFiles%\antivirus\<File name>.vbs
  • %ProgramFiles%\aoltbserver\<File name>.vbs
  • %ProgramFiles%\armor2net\<File name>.vbs
  • %ProgramFiles%\armorsurf\<File name>.vbs
  • %ProgramFiles%\ash\<File name>.vbs
  • %ProgramFiles%\ashavast\<File name>.vbs
  • %ProgramFiles%\ashavsrv\<File name>.vbs
  • %ProgramFiles%\ashchest\<File name>.vbs
  • %ProgramFiles%\admunch\<File name>.vbs
  • %ProgramFiles%\ashdisp\<File name>.vbs
  • %ProgramFiles%\ackwin32\<File name>.vbs
  • %ProgramFiles%\aavshield\<File name>.vbs
  • <Drive name for removable media>:\autorun.inf
  • C:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\<File name>.vbs
  • C:\far2\addons\<File name>.vbs
  • C:\far2\documentation\<File name>.vbs
  • C:\far2\encyclopedia\<File name>.vbs
  • C:\far2\fexcept\<File name>.vbs
  • C:\far2\plugins\<File name>.vbs
  • C:\far2\pluginsdk\<File name>.vbs
  • C:\msocache\all users\<File name>.vbs
  • C:\perflogs\admin\<File name>.vbs
  • %ProgramFiles%\360tray\<File name>.vbs
  • %ProgramFiles%\a2cmd\<File name>.vbs
  • %ProgramFiles%\a2guard\<File name>.vbs
  • %ProgramFiles%\a2hijackfree\<File name>.vbs
  • %ProgramFiles%\a2scan\<File name>.vbs
  • %ProgramFiles%\a2service\<File name>.vbs
  • %ProgramFiles%\a2start\<File name>.vbs
  • %ProgramFiles%\a2upd\<File name>.vbs
  • %ProgramFiles%\a2wizard\<File name>.vbs
  • %ProgramFiles%\about\<File name>.vbs
  • %ProgramFiles%\ashdug\<File name>.vbs
  • %ProgramFiles%\ashenhcd\<File name>.vbs
  • %ProgramFiles%\ashlogv\<File name>.vbs
  • %ProgramFiles%\avgemc\<File name>.vbs
  • %ProgramFiles%\avgfwsrv\<File name>.vbs
  • %ProgramFiles%\avginet\<File name>.vbs
  • %ProgramFiles%\avgnpdln\<File name>.vbs
  • %ProgramFiles%\avgnpsvc\<File name>.vbs
  • %ProgramFiles%\avgrssvc\<File name>.vbs
  • %ProgramFiles%\avgscan\<File name>.vbs
  • %ProgramFiles%\avgupden\<File name>.vbs
  • %ProgramFiles%\avpm\<File name>.vbs
  • %ProgramFiles%\avgupsvc\<File name>.vbs
  • %ProgramFiles%\avgw\<File name>.vbs
  • %ProgramFiles%\avgwizfw\<File name>.vbs
  • %ProgramFiles%\avinitnt\<File name>.vbs
  • %ProgramFiles%\avkserv\<File name>.vbs
  • %ProgramFiles%\avkservice\<File name>.vbs
  • %ProgramFiles%\avkwctl\<File name>.vbs
  • %ProgramFiles%\avnotify\<File name>.vbs
  • %ProgramFiles%\avpcc\<File name>.vbs
  • %ProgramFiles%\avgcc\<File name>.vbs
  • %ProgramFiles%\avgdiag\<File name>.vbs
  • %ProgramFiles%\avgamsvr\<File name>.vbs
  • %ProgramFiles%\avconsol\<File name>.vbs
  • %ProgramFiles%\avconfig\<File name>.vbs
  • %ProgramFiles%\ashpopwz\<File name>.vbs
  • %ProgramFiles%\ashquick\<File name>.vbs
  • %ProgramFiles%\ashserv\<File name>.vbs
  • %ProgramFiles%\ashsimp2\<File name>.vbs
  • %ProgramFiles%\ashsimpl\<File name>.vbs
  • %ProgramFiles%\ashskpcc\<File name>.vbs
  • %ProgramFiles%\ashskpck\<File name>.vbs
  • %ProgramFiles%\ashupd\<File name>.vbs
  • %ProgramFiles%\avscan\<File name>.vbs
  • %ProgramFiles%\ash_updatemediator\<File name>.vbs
  • %ProgramFiles%\ashwebsv\<File name>.vbs
  • %ProgramFiles%\aswupdsv\<File name>.vbs
  • %ProgramFiles%\autodown\<File name>.vbs
  • %ProgramFiles%\autostartexplorer\<File name>.vbs
  • %ProgramFiles%\autotrace\<File name>.vbs
  • %ProgramFiles%\avadmin\<File name>.vbs
  • %ProgramFiles%\avcenter\<File name>.vbs
  • %ProgramFiles%\avciman\<File name>.vbs
  • %ProgramFiles%\avcmd\<File name>.vbs
  • %ProgramFiles%\ashmaisv\<File name>.vbs
  • %ProgramFiles%\aswregsvr\<File name>.vbs
  • %ProgramFiles%\eudora\<File name>.vbs
  • %ProgramFiles%\ewidoctrl\<File name>.vbs
  • %ProgramFiles%\exit_av\<File name>.vbs
  • %ProgramFiles%\issvc\<File name>.vbs
  • %ProgramFiles%\isuac\<File name>.vbs
  • %ProgramFiles%\itunes\<File name>.vbs
  • %ProgramFiles%\java\<File name>.vbs
  • %ProgramFiles%\k-meleon\<File name>.vbs
  • %ProgramFiles%\kav\<File name>.vbs
  • %ProgramFiles%\kavmm\<File name>.vbs
  • %ProgramFiles%\kavpf\<File name>.vbs
  • %ProgramFiles%\lucallbackproxy\<File name>.vbs
  • %ProgramFiles%\kavpfw\<File name>.vbs
  • %ProgramFiles%\kavsvc\<File name>.vbs
  • %ProgramFiles%\konnekt\<File name>.vbs
  • %ProgramFiles%\launcher\<File name>.vbs
  • %ProgramFiles%\licmgr\<File name>.vbs
  • %ProgramFiles%\livesrv\<File name>.vbs
  • %ProgramFiles%\liveupdate\<File name>.vbs
  • %ProgramFiles%\logwatnt\<File name>.vbs
  • %ProgramFiles%\lotroclient\<File name>.vbs
  • %ProgramFiles%\ispnews\<File name>.vbs
  • %ProgramFiles%\ispwdsvc\<File name>.vbs
  • %ProgramFiles%\kavstart\<File name>.vbs
  • %ProgramFiles%\lpfw\<File name>.vbs
  • %ProgramFiles%\iris\<File name>.vbs
  • %ProgramFiles%\ih8run\<File name>.vbs
  • %ProgramFiles%\ilaunchr\<File name>.vbs
  • %ProgramFiles%\imapp\<File name>.vbs
  • %ProgramFiles%\imnotfy\<File name>.vbs
  • %ProgramFiles%\impcnt\<File name>.vbs
  • %ProgramFiles%\incmail\<File name>.vbs
  • %ProgramFiles%\inocit\<File name>.vbs
  • %ProgramFiles%\inorpc\<File name>.vbs
  • %ProgramFiles%\inort\<File name>.vbs
  • %ProgramFiles%\inotask\<File name>.vbs
  • %ProgramFiles%\inouptng\<File name>.vbs
  • %ProgramFiles%\inphasenxd\<File name>.vbs
  • %ProgramFiles%\installcavs\<File name>.vbs
  • %ProgramFiles%\installlicense\<File name>.vbs
  • %ProgramFiles%\installlsp\<File name>.vbs
  • %ProgramFiles%\instlsp\<File name>.vbs
  • %ProgramFiles%\internet explorer\<File name>.vbs
  • %ProgramFiles%\iron\<File name>.vbs
  • %ProgramFiles%\iexplore\<File name>.vbs
  • %ProgramFiles%\isafe\<File name>.vbs
  • %ProgramFiles%\navw32\<File name>.vbs
  • %ProgramFiles%\lucheck\<File name>.vbs
  • %ProgramFiles%\mp3theater\<File name>.vbs
  • %ProgramFiles%\mp3toystray\<File name>.vbs
  • %ProgramFiles%\mp3tray\<File name>.vbs
  • %ProgramFiles%\mpeng\<File name>.vbs
  • %ProgramFiles%\mpftray\<File name>.vbs
  • %ProgramFiles%\mpssvc\<File name>.vbs
  • %ProgramFiles%\msbuild\<File name>.vbs
  • %ProgramFiles%\msimn\<File name>.vbs
  • %ProgramFiles%\msmpsvc\<File name>.vbs
  • %ProgramFiles%\luconfig\<File name>.vbs
  • %ProgramFiles%\msn6\<File name>.vbs
  • %ProgramFiles%\mva\<File name>.vbs
  • %ProgramFiles%\mvc\<File name>.vbs
  • %ProgramFiles%\myagtsvc\<File name>.vbs
  • %ProgramFiles%\myagttry\<File name>.vbs
  • %ProgramFiles%\navapsvc\<File name>.vbs
  • %ProgramFiles%\navlu32\<File name>.vbs
  • %ProgramFiles%\navstub\<File name>.vbs
  • %ProgramFiles%\monsysnt\<File name>.vbs
  • %ProgramFiles%\monlite\<File name>.vbs
  • %ProgramFiles%\mp3toys\<File name>.vbs
  • %ProgramFiles%\miro\<File name>.vbs
  • %ProgramFiles%\miranda32\<File name>.vbs
  • %ProgramFiles%\luinit\<File name>.vbs
  • %ProgramFiles%\luupdate\<File name>.vbs
  • %ProgramFiles%\magent\<File name>.vbs
  • %ProgramFiles%\malwareremoval\<File name>.vbs
  • %ProgramFiles%\maplestory\<File name>.vbs
  • %ProgramFiles%\maxthon\<File name>.vbs
  • %ProgramFiles%\mcmnhdlr\<File name>.vbs
  • %ProgramFiles%\mcregwiz\<File name>.vbs
  • %ProgramFiles%\ieuser\<File name>.vbs
  • %ProgramFiles%\mcshield\<File name>.vbs
  • %ProgramFiles%\ih8\<File name>.vbs
  • %ProgramFiles%\mcvsshld\<File name>.vbs
  • %ProgramFiles%\mfpmp\<File name>.vbs
  • %ProgramFiles%\microsoft analysis services\<File name>.vbs
  • %ProgramFiles%\microsoft office\<File name>.vbs
  • %ProgramFiles%\microsoft sql server compact edition\<File name>.vbs
  • %ProgramFiles%\microsoft sync framework\<File name>.vbs
  • %ProgramFiles%\microsoft synchronization services\<File name>.vbs
  • %ProgramFiles%\mir3game\<File name>.vbs
  • %ProgramFiles%\mcupdmgr\<File name>.vbs
  • %ProgramFiles%\luna\<File name>.vbs
  • %ProgramFiles%\memstring\<File name>.vbs
  • %ProgramFiles%\ieregfix\<File name>.vbs
  • %ProgramFiles%\icqlite\<File name>.vbs
  • %ProgramFiles%\icq\<File name>.vbs
  • %ProgramFiles%\fsav\<File name>.vbs
  • %ProgramFiles%\fsav32\<File name>.vbs
  • %ProgramFiles%\fsavaui\<File name>.vbs
  • %ProgramFiles%\fsavgui\<File name>.vbs
  • %ProgramFiles%\fsavstrt\<File name>.vbs
  • %ProgramFiles%\fsavwsch\<File name>.vbs
  • %ProgramFiles%\fsavwscr\<File name>.vbs
  • %ProgramFiles%\fsbwsys\<File name>.vbs
  • %ProgramFiles%\fsdbuh\<File name>.vbs
  • %ProgramFiles%\fsdc\<File name>.vbs
  • %ProgramFiles%\fsdfwd\<File name>.vbs
  • %ProgramFiles%\fsdiag\<File name>.vbs
  • %ProgramFiles%\fsdiagui\<File name>.vbs
  • %ProgramFiles%\fsfwwsch\<File name>.vbs
  • %ProgramFiles%\fsfwwscr\<File name>.vbs
  • %ProgramFiles%\fsgetwab\<File name>.vbs
  • %ProgramFiles%\fsgk32\<File name>.vbs
  • %ProgramFiles%\fsample\<File name>.vbs
  • %ProgramFiles%\fpwin\<File name>.vbs
  • %ProgramFiles%\fsauach\<File name>.vbs
  • %ProgramFiles%\freshclam\<File name>.vbs
  • %ProgramFiles%\fptrayproc\<File name>.vbs
  • %ProgramFiles%\firesvc\<File name>.vbs
  • %ProgramFiles%\f-sched\<File name>.vbs
  • %ProgramFiles%\fameh32\<File name>.vbs
  • %ProgramFiles%\far\<File name>.vbs
  • %ProgramFiles%\fch32\<File name>.vbs
  • %ProgramFiles%\fdm\<File name>.vbs
  • %ProgramFiles%\fdmwi\<File name>.vbs
  • %ProgramFiles%\filezilla\<File name>.vbs
  • %ProgramFiles%\firebird\<File name>.vbs
  • %ProgramFiles%\fsgk32st\<File name>.vbs
  • %ProgramFiles%\navwnt\<File name>.vbs
  • %ProgramFiles%\firefox\<File name>.vbs
  • %ProgramFiles%\flashfxp\<File name>.vbs
  • %ProgramFiles%\flashgot\<File name>.vbs
  • %ProgramFiles%\flock\<File name>.vbs
  • %ProgramFiles%\foxit\<File name>.vbs
  • %ProgramFiles%\fpavserver\<File name>.vbs
  • %ProgramFiles%\fpavupdm\<File name>.vbs
  • %ProgramFiles%\fprottray\<File name>.vbs
  • %ProgramFiles%\fpscan\<File name>.vbs
  • %ProgramFiles%\ezantivirusregistrationcheck\<File name>.vbs
  • %ProgramFiles%\firetray\<File name>.vbs
  • %ProgramFiles%\fsqh\<File name>.vbs
  • %ProgramFiles%\fsguidll\<File name>.vbs
  • %ProgramFiles%\fshotfix\<File name>.vbs
  • %ProgramFiles%\giantantispywareupdater\<File name>.vbs
  • %ProgramFiles%\gnotify\<File name>.vbs
  • %ProgramFiles%\googledesktop\<File name>.vbs
  • %ProgramFiles%\googletalk\<File name>.vbs
  • %ProgramFiles%\googleupdate\<File name>.vbs
  • %ProgramFiles%\guardgni\<File name>.vbs
  • %ProgramFiles%\guardnt\<File name>.vbs
  • %ProgramFiles%\fsaua\<File name>.vbs
  • %ProgramFiles%\gw\<File name>.vbs
  • %ProgramFiles%\helper\<File name>.vbs
  • %ProgramFiles%\hipsdiag\<File name>.vbs
  • %ProgramFiles%\hregmon\<File name>.vbs
  • %ProgramFiles%\hrres\<File name>.vbs
  • %ProgramFiles%\hsockpe\<File name>.vbs
  • %ProgramFiles%\httplook\<File name>.vbs
  • %ProgramFiles%\iamapp\<File name>.vbs
  • %ProgramFiles%\iamserv\<File name>.vbs
  • %ProgramFiles%\ge\<File name>.vbs
  • %ProgramFiles%\helpctr\<File name>.vbs
  • %ProgramFiles%\giantantispywaremain\<File name>.vbs
  • %ProgramFiles%\gg\<File name>.vbs
  • %ProgramFiles%\gcasserv\<File name>.vbs
  • %ProgramFiles%\gcasdtserv\<File name>.vbs
  • %ProgramFiles%\fsihcomp\<File name>.vbs
  • %ProgramFiles%\fsihs\<File name>.vbs
  • %ProgramFiles%\fslaunch\<File name>.vbs
  • %ProgramFiles%\fsm32\<File name>.vbs
  • %ProgramFiles%\fsma32\<File name>.vbs
  • %ProgramFiles%\fsmb32\<File name>.vbs
  • %ProgramFiles%\fspc\<File name>.vbs
  • %ProgramFiles%\fsguiexe\<File name>.vbs
  • %ProgramFiles%\fspex\<File name>.vbs
  • %ProgramFiles%\fshdll32\<File name>.vbs
  • %ProgramFiles%\fssf\<File name>.vbs
  • %ProgramFiles%\fssm32\<File name>.vbs
  • %ProgramFiles%\fsstm\<File name>.vbs
  • %ProgramFiles%\fssw\<File name>.vbs
  • %ProgramFiles%\fstlui\<File name>.vbs
  • %ProgramFiles%\fsuninst\<File name>.vbs
  • %ProgramFiles%\fsus\<File name>.vbs
  • %ProgramFiles%\ftpte\<File name>.vbs
  • %ProgramFiles%\fshelp\<File name>.vbs
  • %ProgramFiles%\gc\<File name>.vbs
  • %ProgramFiles%\fssg\<File name>.vbs
  • D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\<File name>.vbs

Curing recommendations

  1. If the operating system (OS) can be loaded (either normally or in safe mode), download Dr.Web Security Space and run a full scan of your computer and removable media you use. More about Dr.Web Security Space.
  2. If you cannot boot the OS, change the BIOS settings to boot your system from a CD or USB drive. Download the image of the emergency system repair disk Dr.Web® LiveDisk , mount it on a USB drive or burn it to a CD/DVD. After booting up with this media, run a full scan and cure all the detected threats.
Download Dr.Web

Download by serial number

Use Dr.Web Anti-virus for macOS to run a full scan of your Mac.

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Download Dr.Web

Download by serial number

  1. If the mobile device is operating normally, download and install Dr.Web for Android. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web for Android onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android