Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 832145' = '<SYSTEM32>\WScript.exe C:\$Recycle.Bin\S-1-5-21-1960123792-2022915161-3775307078-1001\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 177749' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sdhelp\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 507198' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sdinvoker\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 237052' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sdloader\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 330389' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sdraw\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 889182' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SDTrayApp\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 633886' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SeaMonkey\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 324028' = '<SYSTEM32>\WScript.exe %ProgramFiles%\seccenter\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 918338' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SFAgent\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 828707' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sigtool\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 955204' = '<SYSTEM32>\WScript.exe %ProgramFiles%\simpress\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 190396' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SiteCli\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 78265' = '<SYSTEM32>\WScript.exe %ProgramFiles%\skype\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 321824' = '<SYSTEM32>\WScript.exe %ProgramFiles%\skypePM\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 807150' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SmartFTP\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 890662' = '<SYSTEM32>\WScript.exe %ProgramFiles%\smath\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 459159' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Smc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 984074' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SNDSrvc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 655606' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sniffer\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 89679' = '<SYSTEM32>\WScript.exe %ProgramFiles%\so3d\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 568754' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sched\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 878952' = '<SYSTEM32>\WScript.exe %ProgramFiles%\soffice\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 907190' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ScanningProcess\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 705822' = '<SYSTEM32>\WScript.exe %ProgramFiles%\scalc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 446108' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Realmon\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 746982' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Reference Assemblies\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 320619' = '<SYSTEM32>\WScript.exe %ProgramFiles%\register\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 858436' = '<SYSTEM32>\WScript.exe %ProgramFiles%\removeit\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 406300' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Remover\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 466259' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Rescue\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 613225' = '<SYSTEM32>\WScript.exe %ProgramFiles%\rfwmain\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 879298' = '<SYSTEM32>\WScript.exe %ProgramFiles%\RQ\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 897670' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Rtvscan\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 580286' = '<SYSTEM32>\WScript.exe %ProgramFiles%\RuLaunch\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 756742' = '<SYSTEM32>\WScript.exe %ProgramFiles%\RunSetup\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 241960' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Safari\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 680043' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sarcli\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 872081' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sargui\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 214609' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SAVAdminService\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 118604' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SAVMain\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 549381' = '<SYSTEM32>\WScript.exe %ProgramFiles%\savprogress\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 16266' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SAVScan\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 775461' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sbase\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 228399' = '<SYSTEM32>\WScript.exe %ProgramFiles%\scanner\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 924160' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SPAMCFG\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 486961' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SPBBCSvc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 890782' = '<SYSTEM32>\WScript.exe %ProgramFiles%\spider\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 823470' = '<SYSTEM32>\WScript.exe %ProgramFiles%\tgsvcstp\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 459685' = '<SYSTEM32>\WScript.exe %ProgramFiles%\thebat\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 710645' = '<SYSTEM32>\WScript.exe %ProgramFiles%\THGnard\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 916444' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Thunderbird\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 110510' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Tmas\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 31427' = '<SYSTEM32>\WScript.exe %ProgramFiles%\tmlisten\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 946837' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Tmntsrv\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 603620' = '<SYSTEM32>\WScript.exe %ProgramFiles%\TmPfw\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 768046' = '<SYSTEM32>\WScript.exe %ProgramFiles%\uiscan\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 111726' = '<SYSTEM32>\WScript.exe %ProgramFiles%\tmproxy\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 837177' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Totalcmd\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 988508' = '<SYSTEM32>\WScript.exe %ProgramFiles%\tracelog\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 39337' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Traymon\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 309885' = '<SYSTEM32>\WScript.exe %ProgramFiles%\trillian\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 416639' = '<SYSTEM32>\WScript.exe %ProgramFiles%\TrojanGuarder\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 778689' = '<SYSTEM32>\WScript.exe %ProgramFiles%\TrojanHunter\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 333103' = '<SYSTEM32>\WScript.exe %ProgramFiles%\trtddptr\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 685669' = '<SYSTEM32>\WScript.exe %ProgramFiles%\TwelveSky2\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 563355' = '<SYSTEM32>\WScript.exe %ProgramFiles%\tca\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 810220' = '<SYSTEM32>\WScript.exe %ProgramFiles%\TeaTimer\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 875237' = '<SYSTEM32>\WScript.exe %ProgramFiles%\TBMon\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 312801' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Sysinfo\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 743382' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SymWSC\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 197074' = '<SYSTEM32>\WScript.exe %ProgramFiles%\spidernt\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 448736' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Spiderui\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 913904' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sporder\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 295437' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SpybotSD\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 507223' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sro_client\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 740211' = '<SYSTEM32>\WScript.exe %ProgramFiles%\start_diag\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 623706' = '<SYSTEM32>\WScript.exe %ProgramFiles%\stopsignav\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 663346' = '<SYSTEM32>\WScript.exe %ProgramFiles%\StreetsOlkShim\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 328483' = '<SYSTEM32>\WScript.exe %ProgramFiles%\rcimlby\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 753050' = '<SYSTEM32>\WScript.exe %ProgramFiles%\svcntaux\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 161554' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SubmitFiles\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 93834' = '<SYSTEM32>\WScript.exe %ProgramFiles%\swdoctor\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 272675' = '<SYSTEM32>\WScript.exe %ProgramFiles%\swdsvc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 461922' = '<SYSTEM32>\WScript.exe %ProgramFiles%\sweb\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 904375' = '<SYSTEM32>\WScript.exe %ProgramFiles%\swriter\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 983937' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SymantecRootInstaller\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 211986' = '<SYSTEM32>\WScript.exe %ProgramFiles%\symlcsvc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 65131' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SymProxySvc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 81321' = '<SYSTEM32>\WScript.exe %ProgramFiles%\SymSPort\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 840145' = '<SYSTEM32>\WScript.exe %ProgramFiles%\spiderml\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 907700' = '<SYSTEM32>\WScript.exe %ProgramFiles%\swAgent\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 89546' = '<SYSTEM32>\WScript.exe %ProgramFiles%\tnbutil\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 975053' = '<SYSTEM32>\WScript.exe %ProgramFiles%\RavTimer\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 228884' = '<SYSTEM32>\WScript.exe %ProgramFiles%\qhwscsvc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 813004' = '<SYSTEM32>\WScript.exe %ProgramFiles%\oget\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 919854' = '<SYSTEM32>\WScript.exe %ProgramFiles%\olAddin\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 106323' = '<SYSTEM32>\WScript.exe %ProgramFiles%\OnAccessInstaller\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 213358' = '<SYSTEM32>\WScript.exe %ProgramFiles%\opera\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 330426' = '<SYSTEM32>\WScript.exe %ProgramFiles%\osCheck\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 352207' = '<SYSTEM32>\WScript.exe %ProgramFiles%\outlook\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 105406' = '<SYSTEM32>\WScript.exe %ProgramFiles%\outpost\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 577682' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PartIn\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 402738' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PartIn9x\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 889423' = '<SYSTEM32>\WScript.exe %ProgramFiles%\partinfo\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 481309' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PartInNT\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 737328' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PavFires\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 311738' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PavFnSvr\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 248602' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Pavkre\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 395224' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PavProt\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 271215' = '<SYSTEM32>\WScript.exe %ProgramFiles%\pavProxy\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 133172' = '<SYSTEM32>\WScript.exe %ProgramFiles%\pavprsrv\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 765012' = '<SYSTEM32>\WScript.exe %ProgramFiles%\pavsrv51\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 153855' = '<SYSTEM32>\WScript.exe %ProgramFiles%\pccguide\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 800789' = '<SYSTEM32>\WScript.exe %ProgramFiles%\OfcPfwSvc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 321738' = '<SYSTEM32>\WScript.exe %ProgramFiles%\pccntmon\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 77749' = '<SYSTEM32>\WScript.exe %ProgramFiles%\oaui\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 96993' = '<SYSTEM32>\WScript.exe %ProgramFiles%\NWService\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 571298' = '<SYSTEM32>\WScript.exe %ProgramFiles%\nisoptui\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 394667' = '<SYSTEM32>\WScript.exe %ProgramFiles%\nod\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 120299' = '<SYSTEM32>\WScript.exe %ProgramFiles%\nod32\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 793685' = '<SYSTEM32>\WScript.exe %ProgramFiles%\nod32krn\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 910183' = '<SYSTEM32>\WScript.exe %ProgramFiles%\nod32kui\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 88216' = '<SYSTEM32>\WScript.exe %ProgramFiles%\NotifyHA\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 159038' = '<SYSTEM32>\WScript.exe %ProgramFiles%\notstart\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 569313' = '<SYSTEM32>\WScript.exe %ProgramFiles%\npavtray\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 157764' = '<SYSTEM32>\WScript.exe %ProgramFiles%\npfmsg\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 872085' = '<SYSTEM32>\WScript.exe %ProgramFiles%\NSMdtr\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 477597' = '<SYSTEM32>\WScript.exe %ProgramFiles%\NssServ\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 853138' = '<SYSTEM32>\WScript.exe %ProgramFiles%\NssTray\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 837783' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ntoskrnl\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 487546' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ntrtscan\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 914660' = '<SYSTEM32>\WScript.exe %ProgramFiles%\NTXconfig\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 941608' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Nupgrade\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 623396' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Nvcod\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 227630' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Nvcte\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 653636' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Nvcut\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 290300' = '<SYSTEM32>\WScript.exe %ProgramFiles%\oasrv\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 252355' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PCCPFW\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 845208' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PcCtlCom\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 850036' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PCTAV\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 18566' = '<SYSTEM32>\WScript.exe %ProgramFiles%\pshost\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 657661' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PsImSvc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 829425' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PXAgent\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 234483' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PXConsole\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 695762' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PXL\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 970065' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PXL1\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 110231' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PXReset\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 988012' = '<SYSTEM32>\WScript.exe %ProgramFiles%\pxsupport\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 652775' = '<SYSTEM32>\WScript.exe %ProgramFiles%\RAT\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 897331' = '<SYSTEM32>\WScript.exe %ProgramFiles%\python\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 993198' = '<SYSTEM32>\WScript.exe %ProgramFiles%\qip\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 610839' = '<SYSTEM32>\WScript.exe %ProgramFiles%\qklez\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 463665' = '<SYSTEM32>\WScript.exe %ProgramFiles%\qrtfix\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 475439' = '<SYSTEM32>\WScript.exe %ProgramFiles%\quaranti\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 666864' = '<SYSTEM32>\WScript.exe %ProgramFiles%\quickstart\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 599850' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Ragexe\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 716603' = '<SYSTEM32>\WScript.exe %ProgramFiles%\RagFree\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 306714' = '<SYSTEM32>\WScript.exe %ProgramFiles%\rapget\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 904626' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ps\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 26214' = '<SYSTEM32>\WScript.exe %ProgramFiles%\psctrls\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 602890' = '<SYSTEM32>\WScript.exe %ProgramFiles%\protect\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 241168' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ProcessViewer\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 633898' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PrivateBrowser\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 129797' = '<SYSTEM32>\WScript.exe %ProgramFiles%\pidgin\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 670159' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PM\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 253358' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PM8Flash\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 78405' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PMagic\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 316828' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PMagic9x\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 148372' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PMagicBT\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 950798' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PMagicNT\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 839846' = '<SYSTEM32>\WScript.exe %ProgramFiles%\POLUTIL\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 452909' = '<SYSTEM32>\WScript.exe %ProgramFiles%\RavMon\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 119021' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ppfw\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 721224' = '<SYSTEM32>\WScript.exe %ProgramFiles%\postinstall\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 634769' = '<SYSTEM32>\WScript.exe %ProgramFiles%\pqbw\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 122832' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PqPe\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 805067' = '<SYSTEM32>\WScript.exe %ProgramFiles%\pqpe9x\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 256592' = '<SYSTEM32>\WScript.exe %ProgramFiles%\pqpent\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 594827' = '<SYSTEM32>\WScript.exe %ProgramFiles%\preconfig\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 939193' = '<SYSTEM32>\WScript.exe %ProgramFiles%\preupd\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 516385' = '<SYSTEM32>\WScript.exe %ProgramFiles%\prevsrv\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 891436' = '<SYSTEM32>\WScript.exe %ProgramFiles%\PrevxSetup\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 672894' = '<SYSTEM32>\WScript.exe %ProgramFiles%\pertsk\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 737337' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Pqboot32\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 538187' = '<SYSTEM32>\WScript.exe %ProgramFiles%\una\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 863444' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Uninstall Information\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 918131' = '<SYSTEM32>\WScript.exe %ProgramFiles%\UninstallCAVS\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 599922' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Oracle\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 792192' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Package Cache\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 477529' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Start Menu\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 72581' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Sun\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 21739' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Templates\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 908821' = '<SYSTEM32>\WScript.exe C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 749682' = '<SYSTEM32>\WScript.exe C:\totalcmd\LANGUAGE\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 424273' = '<SYSTEM32>\WScript.exe C:\Users\All Users\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 758484' = '<SYSTEM32>\WScript.exe %WINDIR%\Cursors\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 649706' = '<SYSTEM32>\WScript.exe C:\Users\Default\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 240401' = '<SYSTEM32>\WScript.exe C:\Users\Public\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 92985' = '<SYSTEM32>\WScript.exe %HOMEPATH%\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 470963' = '<SYSTEM32>\WScript.exe %WINDIR%\addins\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 717340' = '<SYSTEM32>\WScript.exe %WINDIR%\AppCompat\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 274779' = '<SYSTEM32>\WScript.exe %WINDIR%\AppPatch\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 400251' = '<SYSTEM32>\WScript.exe %WINDIR%\assembly\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 567965' = '<SYSTEM32>\WScript.exe %WINDIR%\BitLockerDiscoveryVolumeContents\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 619936' = '<SYSTEM32>\WScript.exe %WINDIR%\Branding\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 911617' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Microsoft Toolkit\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 116751' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Mozilla\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 413288' = '<SYSTEM32>\WScript.exe C:\Users\Default User\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 236179' = '<SYSTEM32>\WScript.exe %WINDIR%\CSC\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 661916' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Favorites\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 443048' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Pidgin\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 94479' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\QIP 2012\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 700672' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Reference Assemblies\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 138136' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Steam\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 245116' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Uninstall Information\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 103559' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Winamp\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 677585' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Windows Defender\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 444947' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Windows Mail\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 862038' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Windows Media Player\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 890733' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Windows NT\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 652243' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Windows Photo Viewer\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 762427' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Windows Portable Devices\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 435232' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Windows Sidebar\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 844247' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Adobe\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 22413' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Application Data\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 209779' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Desktop\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 669593' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Documents\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 257150' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Microsoft\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 941903' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\MSBuild\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 692336' = '<SYSTEM32>\WScript.exe %PROGRAMDATA%\Microsoft Help\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 528970' = '<SYSTEM32>\WScript.exe %WINDIR%\Web\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 15969' = '<SYSTEM32>\WScript.exe %WINDIR%\debug\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 540971' = '<SYSTEM32>\WScript.exe %WINDIR%\RemotePackages\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 45720' = '<SYSTEM32>\WScript.exe %WINDIR%\SchCache\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 563626' = '<SYSTEM32>\WScript.exe %WINDIR%\schemas\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 274251' = '<SYSTEM32>\WScript.exe %WINDIR%\security\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 36845' = '<SYSTEM32>\WScript.exe %WINDIR%\ServiceProfiles\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 3154' = '<SYSTEM32>\WScript.exe %WINDIR%\Setup\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 529459' = '<SYSTEM32>\WScript.exe %WINDIR%\ShellNew\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 112348' = '<SYSTEM32>\WScript.exe %WINDIR%\SoftwareDistribution\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 565767' = '<SYSTEM32>\WScript.exe %WINDIR%\Speech\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 957809' = '<SYSTEM32>\WScript.exe %WINDIR%\DigitalLocker\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 536748' = '<SYSTEM32>\WScript.exe %WINDIR%\system\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 831201' = '<SYSTEM32>\WScript.exe %WINDIR%\SysWOW64\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 909451' = '<SYSTEM32>\WScript.exe %WINDIR%\TAPI\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 254962' = '<SYSTEM32>\WScript.exe %WINDIR%\Tasks\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 665146' = '<SYSTEM32>\WScript.exe %WINDIR%\Temp\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 531946' = '<SYSTEM32>\WScript.exe %WINDIR%\tracing\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 326992' = '<SYSTEM32>\WScript.exe %WINDIR%\twain_32\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 693014' = '<SYSTEM32>\WScript.exe %WINDIR%\Vss\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 574573' = '<SYSTEM32>\WScript.exe %WINDIR%\Registration\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 92120' = '<SYSTEM32>\WScript.exe %WINDIR%\Prefetch\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 88004' = '<SYSTEM32>\WScript.exe %WINDIR%\Resources\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 805855' = '<SYSTEM32>\WScript.exe %WINDIR%\PolicyDefinitions\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 696137' = '<SYSTEM32>\WScript.exe %WINDIR%\PLA\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 426906' = '<SYSTEM32>\WScript.exe %WINDIR%\Downloaded Program Files\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 160739' = '<SYSTEM32>\WScript.exe %WINDIR%\en-US\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 756165' = '<SYSTEM32>\WScript.exe %WINDIR%\Fonts\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 583839' = '<SYSTEM32>\WScript.exe %WINDIR%\Globalization\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 946460' = '<SYSTEM32>\WScript.exe %WINDIR%\Help\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 259172' = '<SYSTEM32>\WScript.exe %WINDIR%\IME\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 306814' = '<SYSTEM32>\WScript.exe %WINDIR%\inf\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 644051' = '<SYSTEM32>\WScript.exe %WINDIR%\Installer\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 269196' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Mozilla Thunderbird\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 879351' = '<SYSTEM32>\WScript.exe %WINDIR%\L2Schemas\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 868301' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Opera\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 496291' = '<SYSTEM32>\WScript.exe %WINDIR%\Logs\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 725759' = '<SYSTEM32>\WScript.exe %WINDIR%\Microsoft.NET\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 494028' = '<SYSTEM32>\WScript.exe %WINDIR%\Migration\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 383984' = '<SYSTEM32>\WScript.exe %WINDIR%\ModemLogs\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 567326' = '<SYSTEM32>\WScript.exe %WINDIR%\Offline Web Pages\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 145169' = '<SYSTEM32>\WScript.exe %WINDIR%\Panther\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 965534' = '<SYSTEM32>\WScript.exe %WINDIR%\PCHEALTH\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 30256' = '<SYSTEM32>\WScript.exe %WINDIR%\Performance\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 369922' = '<SYSTEM32>\WScript.exe %WINDIR%\LiveKernelReports\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 823265' = '<SYSTEM32>\WScript.exe %WINDIR%\ehome\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 760433' = '<SYSTEM32>\WScript.exe %WINDIR%\Media\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 49767' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Mozilla Firefox\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 416632' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\mIRC\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 36714' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Microsoft.NET\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 598646' = '<SYSTEM32>\WScript.exe %ProgramFiles%\VisthLic\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 586305' = '<SYSTEM32>\WScript.exe %ProgramFiles%\VisthUpd\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 974339' = '<SYSTEM32>\WScript.exe %ProgramFiles%\vrfwsvc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 194699' = '<SYSTEM32>\WScript.exe %ProgramFiles%\vrmonsvc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 67738' = '<SYSTEM32>\WScript.exe %ProgramFiles%\vrrw32\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 783764' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Vshwin32\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 817755' = '<SYSTEM32>\WScript.exe %ProgramFiles%\vsmon\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 607079' = '<SYSTEM32>\WScript.exe %ProgramFiles%\vsserv\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 252716' = '<SYSTEM32>\WScript.exe %ProgramFiles%\VsStat\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 212473' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Wclose\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 830699' = '<SYSTEM32>\WScript.exe %ProgramFiles%\webfiltr\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 921029' = '<SYSTEM32>\WScript.exe %ProgramFiles%\WebMoney\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 502517' = '<SYSTEM32>\WScript.exe %ProgramFiles%\WebProxy\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 138119' = '<SYSTEM32>\WScript.exe %ProgramFiles%\WebScanX\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 278614' = '<SYSTEM32>\WScript.exe %ProgramFiles%\wil\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 152723' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Winaw32\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 331118' = '<SYSTEM32>\WScript.exe %ProgramFiles%\winbaram\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 718670' = '<SYSTEM32>\WScript.exe %ProgramFiles%\VirusKeeper\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 385925' = '<SYSTEM32>\WScript.exe %ProgramFiles%\viritexp\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 946034' = '<SYSTEM32>\WScript.exe %ProgramFiles%\VistAux\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 708414' = '<SYSTEM32>\WScript.exe %ProgramFiles%\viritsvc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 942335' = '<SYSTEM32>\WScript.exe %ProgramFiles%\VetTray\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 303734' = '<SYSTEM32>\WScript.exe %ProgramFiles%\UPSObMaker\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 203101' = '<SYSTEM32>\WScript.exe %ProgramFiles%\UninstallLSP\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 384573' = '<SYSTEM32>\WScript.exe %ProgramFiles%\unoinfo\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 57137' = '<SYSTEM32>\WScript.exe %ProgramFiles%\unopkg\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 576005' = '<SYSTEM32>\WScript.exe %ProgramFiles%\unp_test\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 847220' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Up2Date\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 237615' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Updater\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 391810' = '<SYSTEM32>\WScript.exe %ProgramFiles%\UpdaterUI\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 140589' = '<SYSTEM32>\WScript.exe %ProgramFiles%\updclient\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 331271' = '<SYSTEM32>\WScript.exe %ProgramFiles%\wincmd32\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 180003' = '<SYSTEM32>\WScript.exe %ProgramFiles%\netxray\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 697658' = '<SYSTEM32>\WScript.exe %ProgramFiles%\upgrepl\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 599433' = '<SYSTEM32>\WScript.exe %ProgramFiles%\UUpd\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 400470' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Vba32ECM\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 207260' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Vba32ifs\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 94691' = '<SYSTEM32>\WScript.exe %ProgramFiles%\vba32ldr\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 696496' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Vba32PP3\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 536285' = '<SYSTEM32>\WScript.exe %ProgramFiles%\VBSNTW\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 768809' = '<SYSTEM32>\WScript.exe %ProgramFiles%\vchk\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 753061' = '<SYSTEM32>\WScript.exe %ProgramFiles%\vcrmon\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 850200' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Uninstaller\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 591157' = '<SYSTEM32>\WScript.exe %ProgramFiles%\USDownloader\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 196631' = '<SYSTEM32>\WScript.exe %ProgramFiles%\winss\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 912294' = '<SYSTEM32>\WScript.exe %ProgramFiles%\WindowList\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 796008' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Windows Media Player\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 206664' = '<SYSTEM32>\WScript.exe %ProgramFiles%\YahooSync\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 811871' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ybclient\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 961278' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Ymsgr_tray\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 805477' = '<SYSTEM32>\WScript.exe %ProgramFiles%\zapro\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 833122' = '<SYSTEM32>\WScript.exe %ProgramFiles%\zatutor\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 756962' = '<SYSTEM32>\WScript.exe %ProgramFiles%\zauninst\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 902618' = '<SYSTEM32>\WScript.exe %ProgramFiles%\zlclient\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 942237' = '<SYSTEM32>\WScript.exe %ProgramFiles%\VirusNews\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 901624' = '<SYSTEM32>\WScript.exe %ProgramFiles%\zonealarm\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 935271' = '<SYSTEM32>\WScript.exe %CommonProgramFiles(x86)%\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 273206' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Google\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 323305' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Internet Explorer\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 418797' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\K-Lite Codec Pack\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 82457' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Microsoft Analysis Services\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 178573' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Microsoft Office\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 816432' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Microsoft Visual Studio .NET 2003\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 561730' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Microsoft Visual Studio 8\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 513757' = '<SYSTEM32>\WScript.exe %ProgramFiles%\wsm\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 34183' = '<SYSTEM32>\WScript.exe %ProgramFiles(x86)%\Adobe\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 633681' = '<SYSTEM32>\WScript.exe %ProgramFiles%\YahooMessenger\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 895415' = '<SYSTEM32>\WScript.exe %ProgramFiles%\xcommsvr\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 496058' = '<SYSTEM32>\WScript.exe %ProgramFiles%\wsftpgui\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 1653' = '<SYSTEM32>\WScript.exe %ProgramFiles%\wsctool\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 669389' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Windows NT\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 74574' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Windows Photo Viewer\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 720531' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Windows Portable Devices\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 385628' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Windows Sidebar\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 18938' = '<SYSTEM32>\WScript.exe %ProgramFiles%\windump\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 920704' = '<SYSTEM32>\WScript.exe %ProgramFiles%\WinMail\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 747816' = '<SYSTEM32>\WScript.exe %ProgramFiles%\WinRAR\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 862279' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Windows Defender\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 856752' = '<SYSTEM32>\WScript.exe %ProgramFiles%\winroute\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 620660' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Windows Journal\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 864433' = '<SYSTEM32>\WScript.exe %ProgramFiles%\winssnotify\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 682829' = '<SYSTEM32>\WScript.exe %ProgramFiles%\WLLoginProxy\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 594618' = '<SYSTEM32>\WScript.exe %ProgramFiles%\wlmail\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 291808' = '<SYSTEM32>\WScript.exe %ProgramFiles%\wltuser\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 840071' = '<SYSTEM32>\WScript.exe %ProgramFiles%\woool\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 463287' = '<SYSTEM32>\WScript.exe %ProgramFiles%\wow\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 227122' = '<SYSTEM32>\WScript.exe %ProgramFiles%\WrAdmin\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 722666' = '<SYSTEM32>\WScript.exe %ProgramFiles%\WrCtrl\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 458005' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Windows Mail\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 812390' = '<SYSTEM32>\WScript.exe %ProgramFiles%\writespid\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 736210' = '<SYSTEM32>\WScript.exe %ProgramFiles%\wish\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 817591' = '<SYSTEM32>\WScript.exe <SYSTEM32>\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 539296' = '<SYSTEM32>\WScript.exe %ProgramFiles%\NetstatViewer\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 994972' = '<SYSTEM32>\WScript.exe %ProgramFiles%\MVC\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 942073' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CavQ\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 394464' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CAVSCons\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 597045' = '<SYSTEM32>\WScript.exe %ProgramFiles%\cavse\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 497542' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CavSn\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 708831' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CavSub\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 24121' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CAVSubmit\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 168279' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CavUMAS\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 653225' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CavUserUpd\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 883628' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Cavvl\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 824192' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ccapp\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 44677' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ccEvtMgr\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 444196' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CCleaner\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 500217' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ccProxy\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 255919' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ccSetMgr\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 155012' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CEmRep\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 146639' = '<SYSTEM32>\WScript.exe %ProgramFiles%\chrome\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 542545' = '<SYSTEM32>\WScript.exe %ProgramFiles%\clamscan\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 929960' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ClamTray\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 979812' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ClamWin\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 717565' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Cavoar\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 381465' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Claw95\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 63336' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CavMUD\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 734172' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CavEmSrv\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 504297' = '<SYSTEM32>\WScript.exe %ProgramFiles%\bdmcon\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 150846' = '<SYSTEM32>\WScript.exe %ProgramFiles%\bdnews\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 686236' = '<SYSTEM32>\WScript.exe %ProgramFiles%\bdoesrv\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 92455' = '<SYSTEM32>\WScript.exe %ProgramFiles%\bdss\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 524129' = '<SYSTEM32>\WScript.exe %ProgramFiles%\bdsubmit\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 215618' = '<SYSTEM32>\WScript.exe %ProgramFiles%\bdsubmitwiz\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 369118' = '<SYSTEM32>\WScript.exe %ProgramFiles%\BDSurvey\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 662218' = '<SYSTEM32>\WScript.exe %ProgramFiles%\bdswitch\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 209614' = '<SYSTEM32>\WScript.exe %ProgramFiles%\bdwizreg\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 224836' = '<SYSTEM32>\WScript.exe %ProgramFiles%\blackd\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 394441' = '<SYSTEM32>\WScript.exe %ProgramFiles%\blackice\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 677313' = '<SYSTEM32>\WScript.exe %ProgramFiles%\blindman\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 141136' = '<SYSTEM32>\WScript.exe %ProgramFiles%\BTIni\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 749851' = '<SYSTEM32>\WScript.exe %ProgramFiles%\BTIniNT\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 110655' = '<SYSTEM32>\WScript.exe %ProgramFiles%\cabalmain\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 904891' = '<SYSTEM32>\WScript.exe %ProgramFiles%\cafix\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 579741' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CavApp\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 320021' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CaVasm\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 992187' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CavAUD\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 920267' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Cavmr\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 960381' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Claw95cf\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 559511' = '<SYSTEM32>\WScript.exe %ProgramFiles%\cleaner\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 691992' = '<SYSTEM32>\WScript.exe %ProgramFiles%\cleaner3\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 220968' = '<SYSTEM32>\WScript.exe %ProgramFiles%\DrVirus\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 506020' = '<SYSTEM32>\WScript.exe %ProgramFiles%\DrvMap\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 417650' = '<SYSTEM32>\WScript.exe %ProgramFiles%\drwadins\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 569906' = '<SYSTEM32>\WScript.exe %ProgramFiles%\drweb\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 889200' = '<SYSTEM32>\WScript.exe %ProgramFiles%\drweb32w\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 290630' = '<SYSTEM32>\WScript.exe %ProgramFiles%\drweb386\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 945900' = '<SYSTEM32>\WScript.exe %ProgramFiles%\drwebscd\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 588915' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Drwebupw\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 918032' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ewidoctrl\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 270892' = '<SYSTEM32>\WScript.exe %ProgramFiles%\drwebwcl\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 28093' = '<SYSTEM32>\WScript.exe %ProgramFiles%\DVD Maker\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 246876' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ecmd\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 833388' = '<SYSTEM32>\WScript.exe %ProgramFiles%\egni\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 32774' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ehsniffer\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 495346' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ekrn\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 112939' = '<SYSTEM32>\WScript.exe %ProgramFiles%\elementclient\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 681731' = '<SYSTEM32>\WScript.exe %ProgramFiles%\etherd\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 398145' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Eudora\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 460861' = '<SYSTEM32>\WScript.exe %ProgramFiles%\dpatrolq\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 74795' = '<SYSTEM32>\WScript.exe %ProgramFiles%\drvctl\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 948892' = '<SYSTEM32>\WScript.exe %ProgramFiles%\dnf\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 670919' = '<SYSTEM32>\WScript.exe %ProgramFiles%\dislite\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 364508' = '<SYSTEM32>\WScript.exe %ProgramFiles%\DirectFTP\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 934937' = '<SYSTEM32>\WScript.exe %ProgramFiles%\clrcche\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 163430' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CMain\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 547470' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CMGrdian\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 374292' = '<SYSTEM32>\WScript.exe %CommonProgramFiles%\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 394498' = '<SYSTEM32>\WScript.exe %ProgramFiles%\copyx64\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 519367' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Courier\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 525801' = '<SYSTEM32>\WScript.exe %ProgramFiles%\cpd\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 550872' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CSendTo\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 307317' = '<SYSTEM32>\WScript.exe %ProgramFiles%\bdagent\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 866885' = '<SYSTEM32>\WScript.exe %ProgramFiles%\custinstall\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 780042' = '<SYSTEM32>\WScript.exe %ProgramFiles%\cssexc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 503243' = '<SYSTEM32>\WScript.exe %ProgramFiles%\cuteftp\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 60868' = '<SYSTEM32>\WScript.exe %ProgramFiles%\DBConvert\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 860587' = '<SYSTEM32>\WScript.exe %ProgramFiles%\DBTool\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 981147' = '<SYSTEM32>\WScript.exe %ProgramFiles%\defensewall\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 247823' = '<SYSTEM32>\WScript.exe %ProgramFiles%\DefWatch\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 223' = '<SYSTEM32>\WScript.exe %ProgramFiles%\dekaron\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 773237' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Digsby\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 301057' = '<SYSTEM32>\WScript.exe %ProgramFiles%\digsby-app\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 692437' = '<SYSTEM32>\WScript.exe %ProgramFiles%\CliSvc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 220795' = '<SYSTEM32>\WScript.exe %ProgramFiles%\custsetup\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 79394' = '<SYSTEM32>\WScript.exe %ProgramFiles%\drwreg\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 295198' = '<SYSTEM32>\WScript.exe %ProgramFiles%\BackWeb-4476822\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 821160' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgwizfw\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 95185' = '<SYSTEM32>\WScript.exe %ProgramFiles%\AhnSD\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 308480' = '<SYSTEM32>\WScript.exe %ProgramFiles%\aim6\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 47438' = '<SYSTEM32>\WScript.exe %ProgramFiles%\aimpro\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 631530' = '<SYSTEM32>\WScript.exe %ProgramFiles%\airdefense\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 663862' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ALMon\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 650545' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ALsvc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 126959' = '<SYSTEM32>\WScript.exe %ProgramFiles%\amon\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 325830' = '<SYSTEM32>\WScript.exe %ProgramFiles%\amsn\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 32378' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Anti-Trojan\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 440748' = '<SYSTEM32>\WScript.exe %ProgramFiles%\AntiVirus\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 319093' = '<SYSTEM32>\WScript.exe %ProgramFiles%\AolTbServer\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 311195' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Armor2net\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 640980' = '<SYSTEM32>\WScript.exe %ProgramFiles%\armorsurf\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 170851' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ash\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 711060' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashAvast\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 638467' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashAvSrv\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 399640' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashchest\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 923434' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashDisp\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 617618' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashDug\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 354210' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ageofconan\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 675873' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashEnhcd\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 267726' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Agb5\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 27701' = '<SYSTEM32>\WScript.exe %ProgramFiles%\AckWin32\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 134304' = '<SYSTEM32>\WScript.exe C:\Far2\Addons\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 33347' = '<SYSTEM32>\WScript.exe C:\Far2\Documentation\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 783666' = '<SYSTEM32>\WScript.exe C:\Far2\Encyclopedia\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 377863' = '<SYSTEM32>\WScript.exe C:\Far2\FExcept\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 497311' = '<SYSTEM32>\WScript.exe C:\Far2\Plugins\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 120352' = '<SYSTEM32>\WScript.exe C:\Far2\PluginSDK\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 244575' = '<SYSTEM32>\WScript.exe C:\MSOCache\All Users\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 79364' = '<SYSTEM32>\WScript.exe C:\PerfLogs\Admin\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 390122' = '<SYSTEM32>\WScript.exe %ProgramFiles%\360tray\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 699975' = '<SYSTEM32>\WScript.exe %ProgramFiles%\a2cmd\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 981535' = '<SYSTEM32>\WScript.exe %ProgramFiles%\a2guard\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 690995' = '<SYSTEM32>\WScript.exe %ProgramFiles%\a2HiJackFree\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 337700' = '<SYSTEM32>\WScript.exe %ProgramFiles%\a2scan\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 759827' = '<SYSTEM32>\WScript.exe %ProgramFiles%\a2service\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 344215' = '<SYSTEM32>\WScript.exe %ProgramFiles%\a2start\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 226244' = '<SYSTEM32>\WScript.exe %ProgramFiles%\a2upd\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 112080' = '<SYSTEM32>\WScript.exe %ProgramFiles%\a2wizard\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 546307' = '<SYSTEM32>\WScript.exe %ProgramFiles%\aavshield\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 905920' = '<SYSTEM32>\WScript.exe %ProgramFiles%\About\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 497991' = '<SYSTEM32>\WScript.exe %ProgramFiles%\AdMunch\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 266184' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashLogV\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 637522' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashMaiSv\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 784190' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashPopWz\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 952583' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avginet\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 8747' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgnpdln\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 129255' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgnpsvc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 838228' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgrssvc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 687321' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgscan\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 649502' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgupden\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 922078' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgupsvc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 564495' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgvv\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 47274' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avsynmgr\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 444311' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgw\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 329224' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avinitnt\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 826701' = '<SYSTEM32>\WScript.exe %ProgramFiles%\AvkServ\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 456767' = '<SYSTEM32>\WScript.exe %ProgramFiles%\AVKService\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 636575' = '<SYSTEM32>\WScript.exe %ProgramFiles%\AVKWCtl\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 574630' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avnotify\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 265530' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avpcc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 865132' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avpm\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 486921' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avscan\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 938730' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgemc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 371471' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgfwsrv\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 48737' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgdiag\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 585981' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgcc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 361429' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avgamsvr\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 74413' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashServ\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 624213' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashsimp2\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 839987' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashSimpl\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 534645' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashSkPcc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 612229' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashSkPck\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 332297' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashUpd\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 1134' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashWebSv\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 445002' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ash_UpdateMediator\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 26553' = '<SYSTEM32>\WScript.exe %ProgramFiles%\B2\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 363887' = '<SYSTEM32>\WScript.exe %ProgramFiles%\aswUpdSv\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 949763' = '<SYSTEM32>\WScript.exe %ProgramFiles%\aswRegSvr\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 274720' = '<SYSTEM32>\WScript.exe %ProgramFiles%\AutostartExplorer\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 17494' = '<SYSTEM32>\WScript.exe %ProgramFiles%\AutoTrace\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 740039' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avadmin\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 407303' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avcenter\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 838313' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avciman\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 434380' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avcmd\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 416382' = '<SYSTEM32>\WScript.exe %ProgramFiles%\avconfig\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 847270' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Avconsol\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 499643' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ashQuick\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 23796' = '<SYSTEM32>\WScript.exe %ProgramFiles%\AutoDown\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 538485' = '<SYSTEM32>\WScript.exe %ProgramFiles%\exit_av\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 574283' = '<SYSTEM32>\WScript.exe %ProgramFiles%\EzAntivirusRegistrationCheck\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 462922' = '<SYSTEM32>\WScript.exe %ProgramFiles%\F-Sched\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 999594' = '<SYSTEM32>\WScript.exe %ProgramFiles%\iTunes\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 354467' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Java\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 69329' = '<SYSTEM32>\WScript.exe %ProgramFiles%\k-meleon\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 773805' = '<SYSTEM32>\WScript.exe %ProgramFiles%\KAV\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 550696' = '<SYSTEM32>\WScript.exe %ProgramFiles%\kavmm\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 236562' = '<SYSTEM32>\WScript.exe %ProgramFiles%\KAVPF\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 66844' = '<SYSTEM32>\WScript.exe %ProgramFiles%\KavPFW\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 99863' = '<SYSTEM32>\WScript.exe %ProgramFiles%\KAVStart\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 443846' = '<SYSTEM32>\WScript.exe %ProgramFiles%\LuConfig\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 866710' = '<SYSTEM32>\WScript.exe %ProgramFiles%\KAVSvc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 956376' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Launcher\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 238151' = '<SYSTEM32>\WScript.exe %ProgramFiles%\licmgr\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 281192' = '<SYSTEM32>\WScript.exe %ProgramFiles%\livesrv\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 174469' = '<SYSTEM32>\WScript.exe %ProgramFiles%\LiveUpdate\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 364940' = '<SYSTEM32>\WScript.exe %ProgramFiles%\LogWatNT\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 370126' = '<SYSTEM32>\WScript.exe %ProgramFiles%\lotroclient\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 62271' = '<SYSTEM32>\WScript.exe %ProgramFiles%\lpfw\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 550227' = '<SYSTEM32>\WScript.exe %ProgramFiles%\LUCallbackProxy\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 107325' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ISSVC\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 766994' = '<SYSTEM32>\WScript.exe %ProgramFiles%\isUAC\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 655953' = '<SYSTEM32>\WScript.exe %ProgramFiles%\konnekt\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 330682' = '<SYSTEM32>\WScript.exe %ProgramFiles%\LUCheck\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 446803' = '<SYSTEM32>\WScript.exe %ProgramFiles%\isafe\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 569045' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ImApp\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 116941' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ImNotfy\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 494432' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ImpCnt\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 985922' = '<SYSTEM32>\WScript.exe %ProgramFiles%\IncMail\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 577066' = '<SYSTEM32>\WScript.exe %ProgramFiles%\InocIT\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 794295' = '<SYSTEM32>\WScript.exe %ProgramFiles%\InoRpc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 608122' = '<SYSTEM32>\WScript.exe %ProgramFiles%\InoRT\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 457597' = '<SYSTEM32>\WScript.exe %ProgramFiles%\InoTask\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 973808' = '<SYSTEM32>\WScript.exe %ProgramFiles%\InoUpTNG\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 418766' = '<SYSTEM32>\WScript.exe %ProgramFiles%\InphaseNXD\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 540617' = '<SYSTEM32>\WScript.exe %ProgramFiles%\InstallCAVS\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 492386' = '<SYSTEM32>\WScript.exe %ProgramFiles%\InstallLicense\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 622614' = '<SYSTEM32>\WScript.exe %ProgramFiles%\InstallLSP\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 462827' = '<SYSTEM32>\WScript.exe %ProgramFiles%\InstLsp\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 686999' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Internet Explorer\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 467548' = '<SYSTEM32>\WScript.exe %ProgramFiles%\iris\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 704208' = '<SYSTEM32>\WScript.exe %ProgramFiles%\iron\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 298792' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ISPNews\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 395288' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ih8run\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 191004' = '<SYSTEM32>\WScript.exe %ProgramFiles%\isPwdsvc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 63654' = '<SYSTEM32>\WScript.exe %ProgramFiles%\NeoWatchLog\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 178268' = '<SYSTEM32>\WScript.exe %ProgramFiles%\LUInit\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 202863' = '<SYSTEM32>\WScript.exe %ProgramFiles%\MP3ToysTray\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 466860' = '<SYSTEM32>\WScript.exe %ProgramFiles%\MpEng\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 41539' = '<SYSTEM32>\WScript.exe %ProgramFiles%\mpftray\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 741512' = '<SYSTEM32>\WScript.exe %ProgramFiles%\mpssvc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 557060' = '<SYSTEM32>\WScript.exe %ProgramFiles%\MSBuild\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 801516' = '<SYSTEM32>\WScript.exe %ProgramFiles%\msimn\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 682346' = '<SYSTEM32>\WScript.exe %ProgramFiles%\MSMPSVC\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 134763' = '<SYSTEM32>\WScript.exe %ProgramFiles%\msn6\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 680284' = '<SYSTEM32>\WScript.exe %ProgramFiles%\msnmsgr\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 440760' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Luna\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 772909' = '<SYSTEM32>\WScript.exe %ProgramFiles%\mva\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 766468' = '<SYSTEM32>\WScript.exe %ProgramFiles%\myAgtSvc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 326430' = '<SYSTEM32>\WScript.exe %ProgramFiles%\myagttry\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 460692' = '<SYSTEM32>\WScript.exe %ProgramFiles%\navapsvc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 302962' = '<SYSTEM32>\WScript.exe %ProgramFiles%\NavLu32\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 978483' = '<SYSTEM32>\WScript.exe %ProgramFiles%\NAVStub\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 532425' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Navw32\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 566584' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Navwnt\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 429666' = '<SYSTEM32>\WScript.exe %ProgramFiles%\MP3Toys\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 795736' = '<SYSTEM32>\WScript.exe %ProgramFiles%\MP3Theater\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 45810' = '<SYSTEM32>\WScript.exe %ProgramFiles%\MP3Tray\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 533433' = '<SYSTEM32>\WScript.exe %ProgramFiles%\MonSysNT\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 702350' = '<SYSTEM32>\WScript.exe %ProgramFiles%\monlite\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 193508' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Luupdate\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 313328' = '<SYSTEM32>\WScript.exe %ProgramFiles%\MalwareRemoval\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 356138' = '<SYSTEM32>\WScript.exe %ProgramFiles%\maplestory\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 735704' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Maxthon\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 260518' = '<SYSTEM32>\WScript.exe %ProgramFiles%\mcmnhdlr\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 133038' = '<SYSTEM32>\WScript.exe %ProgramFiles%\mcregwiz\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 862096' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Mcshield\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 572567' = '<SYSTEM32>\WScript.exe %ProgramFiles%\mcupdmgr\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 383957' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ih8\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 935720' = '<SYSTEM32>\WScript.exe %ProgramFiles%\mcvsshld\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 927641' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ILAUNCHR\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 33157' = '<SYSTEM32>\WScript.exe %ProgramFiles%\mfpmp\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 323421' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Microsoft Office\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 739739' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Microsoft SQL Server Compact Edition\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 155761' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Microsoft Sync Framework\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 850262' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Microsoft Synchronization Services\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 126560' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Mir3Game\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 655759' = '<SYSTEM32>\WScript.exe %ProgramFiles%\miranda32\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 681384' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Miro\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 800057' = '<SYSTEM32>\WScript.exe %ProgramFiles%\MemString\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 502097' = '<SYSTEM32>\WScript.exe %ProgramFiles%\magent\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 793024' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Microsoft Analysis Services\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 263161' = '<SYSTEM32>\WScript.exe %ProgramFiles%\iexplore\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 407451' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ieuser\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 81624' = '<SYSTEM32>\WScript.exe %ProgramFiles%\IERegFix\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 178391' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsavaui\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 394492' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsavgui\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 470006' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsavstrt\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 259518' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsavwsch\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 280324' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsavwscr\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 737376' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsbwsys\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 745311' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsdbuh\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 771738' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsdc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 979261' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsdfwd\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 183778' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FSDIAG\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 26464' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FsDiagUi\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 317195' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsfwwsch\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 426141' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsfwwscr\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 843381' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsgetwab\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 296924' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsgk32\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 8011' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsgk32st\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 97101' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsguidll\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 366737' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsauach\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 266187' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsample\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 560016' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsav32\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 82093' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsaua\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 543141' = '<SYSTEM32>\WScript.exe %ProgramFiles%\freshclam\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 228737' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FlashFXP\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 235244' = '<SYSTEM32>\WScript.exe %ProgramFiles%\far\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 188350' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FCH32\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 757682' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fdm\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 701236' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fdmwi\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 103425' = '<SYSTEM32>\WScript.exe %ProgramFiles%\filezilla\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 635811' = '<SYSTEM32>\WScript.exe %ProgramFiles%\firebird\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 509295' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FireFox\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 414415' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FireSvc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 850277' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsguiexe\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 711300' = '<SYSTEM32>\WScript.exe %ProgramFiles%\NeoWatchTray\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 309835' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FireTray\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 319599' = '<SYSTEM32>\WScript.exe %ProgramFiles%\flock\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 616012' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Foxit\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 495022' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FPAVServer\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 240743' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fpavupdm\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 792826' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FProtTray\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 956341' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fpscan\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 444005' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fptrayproc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 733884' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FPWin\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 746407' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FAMEH32\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 344042' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FlashGot\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 48352' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fssg\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 466909' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FSHDLL32\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 514019' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsihs\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 325571' = '<SYSTEM32>\WScript.exe %ProgramFiles%\GoogleDesktop\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 357311' = '<SYSTEM32>\WScript.exe %ProgramFiles%\googletalk\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 430975' = '<SYSTEM32>\WScript.exe %ProgramFiles%\GoogleUpdate\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 640831' = '<SYSTEM32>\WScript.exe %ProgramFiles%\guardgni\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 906223' = '<SYSTEM32>\WScript.exe %ProgramFiles%\GuardNT\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 862671' = '<SYSTEM32>\WScript.exe %ProgramFiles%\gw\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 422952' = '<SYSTEM32>\WScript.exe %ProgramFiles%\helpctr\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 253222' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsav\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 390730' = '<SYSTEM32>\WScript.exe %ProgramFiles%\helper\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 426705' = '<SYSTEM32>\WScript.exe %ProgramFiles%\HRegMon\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 883439' = '<SYSTEM32>\WScript.exe %ProgramFiles%\Hrres\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 801506' = '<SYSTEM32>\WScript.exe %ProgramFiles%\HSockPE\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 369997' = '<SYSTEM32>\WScript.exe %ProgramFiles%\httplook\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 133946' = '<SYSTEM32>\WScript.exe %ProgramFiles%\iamapp\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 121334' = '<SYSTEM32>\WScript.exe %ProgramFiles%\iamserv\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 258963' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ICQ\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 734199' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ICQLite\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 73162' = '<SYSTEM32>\WScript.exe %ProgramFiles%\GIANTAntiSpywareMain\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 729035' = '<SYSTEM32>\WScript.exe %ProgramFiles%\hipsdiag\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 389638' = '<SYSTEM32>\WScript.exe %ProgramFiles%\gnotify\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 857398' = '<SYSTEM32>\WScript.exe %ProgramFiles%\GIANTAntiSpywareUpdater\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 662068' = '<SYSTEM32>\WScript.exe %ProgramFiles%\gg\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 57990' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ge\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 950964' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FSLAUNCH\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 985526' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FSM32\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 533148' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FSMA32\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 873861' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FSMB32\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 88478' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fspc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 171862' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fspex\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 427507' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsqh\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 176034' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fshelp\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 80677' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fssf\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 809096' = '<SYSTEM32>\WScript.exe %ProgramFiles%\FSHOTFIX\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 801272' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fssm32\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 657965' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fssw\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 322592' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fstlui\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 210242' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsuninst\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 590199' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsus\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 259106' = '<SYSTEM32>\WScript.exe %ProgramFiles%\ftpte\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 13553' = '<SYSTEM32>\WScript.exe %ProgramFiles%\gc\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 904205' = '<SYSTEM32>\WScript.exe %ProgramFiles%\gcasDtServ\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 316101' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsihcomp\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 457775' = '<SYSTEM32>\WScript.exe %ProgramFiles%\gcasServ\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 262178' = '<SYSTEM32>\WScript.exe %ProgramFiles%\fsstm\<File name>.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 656538' = '<SYSTEM32>\WScript.exe D:\$RECYCLE.BIN\S-1-5-21-1960123792-2022915161-3775307078-1001\<File name>.vbs'
- %WINDIR%\tasks\<File name>.vbs
- <Drive name for removable media>:\autorun.inf
- <Drive name for removable media>:\<File name>.vbs
- C:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\<File name>.vbs
- %ProgramFiles%\sdhelp\<File name>.vbs
- %ProgramFiles%\sdinvoker\<File name>.vbs
- %ProgramFiles%\sdloader\<File name>.vbs
- %ProgramFiles%\sdraw\<File name>.vbs
- %ProgramFiles%\sdtrayapp\<File name>.vbs
- %ProgramFiles%\seamonkey\<File name>.vbs
- %ProgramFiles%\seccenter\<File name>.vbs
- %ProgramFiles%\sfagent\<File name>.vbs
- %ProgramFiles%\sigtool\<File name>.vbs
- %ProgramFiles%\simpress\<File name>.vbs
- %ProgramFiles%\sitecli\<File name>.vbs
- %ProgramFiles%\skype\<File name>.vbs
- %ProgramFiles%\skypepm\<File name>.vbs
- %ProgramFiles%\smartftp\<File name>.vbs
- %ProgramFiles%\smath\<File name>.vbs
- %ProgramFiles%\smc\<File name>.vbs
- %ProgramFiles%\sndsrvc\<File name>.vbs
- %ProgramFiles%\sniffer\<File name>.vbs
- %ProgramFiles%\so3d\<File name>.vbs
- %ProgramFiles%\sched\<File name>.vbs
- %ProgramFiles%\ravtimer\<File name>.vbs
- %ProgramFiles%\scanningprocess\<File name>.vbs
- %ProgramFiles%\scalc\<File name>.vbs
- %ProgramFiles%\realmon\<File name>.vbs
- %ProgramFiles%\reference assemblies\<File name>.vbs
- %ProgramFiles%\register\<File name>.vbs
- %ProgramFiles%\removeit\<File name>.vbs
- %ProgramFiles%\remover\<File name>.vbs
- %ProgramFiles%\rescue\<File name>.vbs
- %ProgramFiles%\rfwmain\<File name>.vbs
- %ProgramFiles%\rq\<File name>.vbs
- %ProgramFiles%\rtvscan\<File name>.vbs
- %ProgramFiles%\rulaunch\<File name>.vbs
- %ProgramFiles%\runsetup\<File name>.vbs
- %ProgramFiles%\safari\<File name>.vbs
- %ProgramFiles%\sarcli\<File name>.vbs
- %ProgramFiles%\sargui\<File name>.vbs
- %ProgramFiles%\savadminservice\<File name>.vbs
- %ProgramFiles%\savmain\<File name>.vbs
- %ProgramFiles%\savprogress\<File name>.vbs
- %ProgramFiles%\savscan\<File name>.vbs
- %ProgramFiles%\sbase\<File name>.vbs
- %ProgramFiles%\scanner\<File name>.vbs
- %ProgramFiles%\rcimlby\<File name>.vbs
- %ProgramFiles%\soffice\<File name>.vbs
- %ProgramFiles%\spiderml\<File name>.vbs
- %ProgramFiles%\tca\<File name>.vbs
- %ProgramFiles%\teatimer\<File name>.vbs
- %ProgramFiles%\tgsvcstp\<File name>.vbs
- %ProgramFiles%\thebat\<File name>.vbs
- %ProgramFiles%\thgnard\<File name>.vbs
- %ProgramFiles%\thunderbird\<File name>.vbs
- %ProgramFiles%\tmas\<File name>.vbs
- %ProgramFiles%\tmlisten\<File name>.vbs
- %ProgramFiles%\rat\<File name>.vbs
- %ProgramFiles%\tmntsrv\<File name>.vbs
- %ProgramFiles%\tmproxy\<File name>.vbs
- %ProgramFiles%\tnbutil\<File name>.vbs
- %ProgramFiles%\totalcmd\<File name>.vbs
- %ProgramFiles%\tracelog\<File name>.vbs
- %ProgramFiles%\traymon\<File name>.vbs
- %ProgramFiles%\trillian\<File name>.vbs
- %ProgramFiles%\trojanguarder\<File name>.vbs
- %ProgramFiles%\trojanhunter\<File name>.vbs
- %ProgramFiles%\sysinfo\<File name>.vbs
- %ProgramFiles%\tbmon\<File name>.vbs
- %ProgramFiles%\spbbcsvc\<File name>.vbs
- %ProgramFiles%\spamcfg\<File name>.vbs
- %ProgramFiles%\symproxysvc\<File name>.vbs
- %ProgramFiles%\spidernt\<File name>.vbs
- %ProgramFiles%\spiderui\<File name>.vbs
- %ProgramFiles%\sporder\<File name>.vbs
- %ProgramFiles%\spybotsd\<File name>.vbs
- %ProgramFiles%\sro_client\<File name>.vbs
- %ProgramFiles%\start_diag\<File name>.vbs
- %ProgramFiles%\stopsignav\<File name>.vbs
- %ProgramFiles%\streetsolkshim\<File name>.vbs
- %ProgramFiles%\submitfiles\<File name>.vbs
- %ProgramFiles%\svcntaux\<File name>.vbs
- %ProgramFiles%\swagent\<File name>.vbs
- %ProgramFiles%\swdoctor\<File name>.vbs
- %ProgramFiles%\swdsvc\<File name>.vbs
- %ProgramFiles%\sweb\<File name>.vbs
- %ProgramFiles%\swriter\<File name>.vbs
- %ProgramFiles%\symantecrootinstaller\<File name>.vbs
- %ProgramFiles%\symlcsvc\<File name>.vbs
- %ProgramFiles%\symsport\<File name>.vbs
- %ProgramFiles%\spider\<File name>.vbs
- %ProgramFiles%\symwsc\<File name>.vbs
- %ProgramFiles%\ravmon\<File name>.vbs
- %ProgramFiles%\rapget\<File name>.vbs
- %ProgramFiles%\twelvesky2\<File name>.vbs
- %ProgramFiles%\oladdin\<File name>.vbs
- %ProgramFiles%\onaccessinstaller\<File name>.vbs
- %ProgramFiles%\opera\<File name>.vbs
- %ProgramFiles%\oscheck\<File name>.vbs
- %ProgramFiles%\outlook\<File name>.vbs
- %ProgramFiles%\outpost\<File name>.vbs
- %ProgramFiles%\partin\<File name>.vbs
- %ProgramFiles%\partin9x\<File name>.vbs
- %ProgramFiles%\partinfo\<File name>.vbs
- %ProgramFiles%\partinnt\<File name>.vbs
- %ProgramFiles%\pavfires\<File name>.vbs
- %ProgramFiles%\pavfnsvr\<File name>.vbs
- %ProgramFiles%\pavkre\<File name>.vbs
- %ProgramFiles%\pavprot\<File name>.vbs
- %ProgramFiles%\pavproxy\<File name>.vbs
- %ProgramFiles%\pavprsrv\<File name>.vbs
- %ProgramFiles%\pavsrv51\<File name>.vbs
- %ProgramFiles%\oaui\<File name>.vbs
- %ProgramFiles%\oasrv\<File name>.vbs
- %ProgramFiles%\oget\<File name>.vbs
- %ProgramFiles%\pccpfw\<File name>.vbs
- %ProgramFiles%\pccguide\<File name>.vbs
- %ProgramFiles%\pccntmon\<File name>.vbs
- %ProgramFiles%\nod\<File name>.vbs
- %ProgramFiles%\nod32\<File name>.vbs
- %ProgramFiles%\nod32krn\<File name>.vbs
- %ProgramFiles%\nod32kui\<File name>.vbs
- %ProgramFiles%\notifyha\<File name>.vbs
- %ProgramFiles%\notstart\<File name>.vbs
- %ProgramFiles%\npavtray\<File name>.vbs
- %ProgramFiles%\npfmsg\<File name>.vbs
- %ProgramFiles%\nsmdtr\<File name>.vbs
- %ProgramFiles%\nssserv\<File name>.vbs
- %ProgramFiles%\nsstray\<File name>.vbs
- %ProgramFiles%\ntoskrnl\<File name>.vbs
- %ProgramFiles%\ntrtscan\<File name>.vbs
- %ProgramFiles%\ntxconfig\<File name>.vbs
- %ProgramFiles%\nupgrade\<File name>.vbs
- %ProgramFiles%\nvcod\<File name>.vbs
- %ProgramFiles%\nvcte\<File name>.vbs
- %ProgramFiles%\nwservice\<File name>.vbs
- %ProgramFiles%\netxray\<File name>.vbs
- %ProgramFiles%\nvcut\<File name>.vbs
- %ProgramFiles%\pcctlcom\<File name>.vbs
- %ProgramFiles%\ps\<File name>.vbs
- %ProgramFiles%\pidgin\<File name>.vbs
- %ProgramFiles%\psimsvc\<File name>.vbs
- %ProgramFiles%\pxagent\<File name>.vbs
- %ProgramFiles%\pxconsole\<File name>.vbs
- %ProgramFiles%\pxl\<File name>.vbs
- %ProgramFiles%\pxl1\<File name>.vbs
- %ProgramFiles%\pxreset\<File name>.vbs
- %ProgramFiles%\pxsupport\<File name>.vbs
- %ProgramFiles%\ofcpfwsvc\<File name>.vbs
- %ProgramFiles%\python\<File name>.vbs
- %ProgramFiles%\qip\<File name>.vbs
- %ProgramFiles%\qklez\<File name>.vbs
- %ProgramFiles%\qrtfix\<File name>.vbs
- %ProgramFiles%\quaranti\<File name>.vbs
- %ProgramFiles%\quickstart\<File name>.vbs
- %ProgramFiles%\ragexe\<File name>.vbs
- %ProgramFiles%\ragfree\<File name>.vbs
- %ProgramFiles%\protect\<File name>.vbs
- %ProgramFiles%\processviewer\<File name>.vbs
- %ProgramFiles%\qhwscsvc\<File name>.vbs
- %ProgramFiles%\pshost\<File name>.vbs
- %ProgramFiles%\psctrls\<File name>.vbs
- %ProgramFiles%\privatebrowser\<File name>.vbs
- %ProgramFiles%\prevxsetup\<File name>.vbs
- %ProgramFiles%\pm\<File name>.vbs
- %ProgramFiles%\pm8flash\<File name>.vbs
- %ProgramFiles%\pmagic\<File name>.vbs
- %ProgramFiles%\pmagic9x\<File name>.vbs
- %ProgramFiles%\pmagicbt\<File name>.vbs
- %ProgramFiles%\pmagicnt\<File name>.vbs
- %ProgramFiles%\trtddptr\<File name>.vbs
- %ProgramFiles%\polutil\<File name>.vbs
- %ProgramFiles%\ppfw\<File name>.vbs
- %ProgramFiles%\tmpfw\<File name>.vbs
- %ProgramFiles%\pqboot32\<File name>.vbs
- %ProgramFiles%\pqpe\<File name>.vbs
- %ProgramFiles%\pqpe9x\<File name>.vbs
- %ProgramFiles%\pqpent\<File name>.vbs
- %ProgramFiles%\preconfig\<File name>.vbs
- %ProgramFiles%\preupd\<File name>.vbs
- %ProgramFiles%\prevsrv\<File name>.vbs
- %ProgramFiles%\postinstall\<File name>.vbs
- %ProgramFiles%\pertsk\<File name>.vbs
- %ProgramFiles%\pctav\<File name>.vbs
- %ProgramFiles%\pqbw\<File name>.vbs
- %ProgramFiles%\fssf\<File name>.vbs
- %ProgramFiles%\uiscan\<File name>.vbs
- %PROGRAMDATA%\microsoft\<File name>.vbs
- %PROGRAMDATA%\microsoft help\<File name>.vbs
- %PROGRAMDATA%\microsoft toolkit\<File name>.vbs
- %PROGRAMDATA%\mozilla\<File name>.vbs
- %PROGRAMDATA%\oracle\<File name>.vbs
- %PROGRAMDATA%\package cache\<File name>.vbs
- %PROGRAMDATA%\start menu\<File name>.vbs
- %PROGRAMDATA%\sun\<File name>.vbs
- %PROGRAMDATA%\templates\<File name>.vbs
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\<File name>.vbs
- C:\totalcmd\language\<File name>.vbs
- C:\users\default\<File name>.vbs
- C:\users\public\<File name>.vbs
- %HOMEPATH%\<File name>.vbs
- %WINDIR%\addins\<File name>.vbs
- %WINDIR%\appcompat\<File name>.vbs
- %WINDIR%\apppatch\<File name>.vbs
- %WINDIR%\assembly\<File name>.vbs
- %WINDIR%\bitlockerdiscoveryvolumecontents\<File name>.vbs
- %PROGRAMDATA%\favorites\<File name>.vbs
- %WINDIR%\branding\<File name>.vbs
- %PROGRAMDATA%\documents\<File name>.vbs
- %PROGRAMDATA%\application data\<File name>.vbs
- %ProgramFiles(x86)%\mirc\<File name>.vbs
- %ProgramFiles(x86)%\mozilla firefox\<File name>.vbs
- %ProgramFiles(x86)%\mozilla thunderbird\<File name>.vbs
- %ProgramFiles(x86)%\msbuild\<File name>.vbs
- %ProgramFiles(x86)%\opera\<File name>.vbs
- %ProgramFiles(x86)%\pidgin\<File name>.vbs
- %ProgramFiles(x86)%\qip 2012\<File name>.vbs
- %ProgramFiles(x86)%\reference assemblies\<File name>.vbs
- %ProgramFiles(x86)%\steam\<File name>.vbs
- %ProgramFiles(x86)%\uninstall information\<File name>.vbs
- %ProgramFiles(x86)%\winamp\<File name>.vbs
- %ProgramFiles(x86)%\windows defender\<File name>.vbs
- %ProgramFiles(x86)%\windows mail\<File name>.vbs
- %ProgramFiles(x86)%\windows media player\<File name>.vbs
- %ProgramFiles(x86)%\windows nt\<File name>.vbs
- %ProgramFiles(x86)%\windows photo viewer\<File name>.vbs
- %ProgramFiles(x86)%\windows portable devices\<File name>.vbs
- %ProgramFiles(x86)%\windows sidebar\<File name>.vbs
- %PROGRAMDATA%\adobe\<File name>.vbs
- %PROGRAMDATA%\desktop\<File name>.vbs
- %WINDIR%\csc\<File name>.vbs
- %WINDIR%\cursors\<File name>.vbs
- %WINDIR%\debug\<File name>.vbs
- %WINDIR%\registration\<File name>.vbs
- %WINDIR%\resources\<File name>.vbs
- %WINDIR%\schcache\<File name>.vbs
- %WINDIR%\schemas\<File name>.vbs
- %WINDIR%\security\<File name>.vbs
- %WINDIR%\serviceprofiles\<File name>.vbs
- %WINDIR%\setup\<File name>.vbs
- %WINDIR%\shellnew\<File name>.vbs
- %WINDIR%\softwaredistribution\<File name>.vbs
- %ProgramFiles(x86)%\microsoft visual studio 8\<File name>.vbs
- %WINDIR%\speech\<File name>.vbs
- <SYSTEM32>\<File name>.vbs
- %WINDIR%\syswow64\<File name>.vbs
- %WINDIR%\tapi\<File name>.vbs
- %WINDIR%\temp\<File name>.vbs
- %WINDIR%\tracing\<File name>.vbs
- %WINDIR%\twain_32\<File name>.vbs
- %WINDIR%\vss\<File name>.vbs
- %WINDIR%\prefetch\<File name>.vbs
- %WINDIR%\policydefinitions\<File name>.vbs
- %WINDIR%\remotepackages\<File name>.vbs
- %WINDIR%\pla\<File name>.vbs
- %WINDIR%\performance\<File name>.vbs
- %WINDIR%\digitallocker\<File name>.vbs
- %WINDIR%\ehome\<File name>.vbs
- %WINDIR%\en-us\<File name>.vbs
- %WINDIR%\fonts\<File name>.vbs
- %WINDIR%\globalization\<File name>.vbs
- %WINDIR%\help\<File name>.vbs
- %WINDIR%\ime\<File name>.vbs
- %WINDIR%\inf\<File name>.vbs
- %ProgramFiles(x86)%\microsoft.net\<File name>.vbs
- %WINDIR%\installer\<File name>.vbs
- %ProgramFiles%\netstatviewer\<File name>.vbs
- %WINDIR%\livekernelreports\<File name>.vbs
- %WINDIR%\media\<File name>.vbs
- %WINDIR%\microsoft.net\<File name>.vbs
- %WINDIR%\migration\<File name>.vbs
- %WINDIR%\modemlogs\<File name>.vbs
- %WINDIR%\offline web pages\<File name>.vbs
- %WINDIR%\panther\<File name>.vbs
- %WINDIR%\pchealth\<File name>.vbs
- %WINDIR%\l2schemas\<File name>.vbs
- %WINDIR%\downloaded program files\<File name>.vbs
- %WINDIR%\logs\<File name>.vbs
- %ProgramFiles%\nisoptui\<File name>.vbs
- %ProgramFiles(x86)%\microsoft office\<File name>.vbs
- %ProgramFiles%\zlclient\<File name>.vbs
- %ProgramFiles%\viritsvc\<File name>.vbs
- %ProgramFiles%\viruskeeper\<File name>.vbs
- %ProgramFiles%\virusnews\<File name>.vbs
- %ProgramFiles%\vistaux\<File name>.vbs
- %ProgramFiles%\visthlic\<File name>.vbs
- %ProgramFiles%\visthupd\<File name>.vbs
- %ProgramFiles%\vrfwsvc\<File name>.vbs
- %ProgramFiles%\vrmonsvc\<File name>.vbs
- %ProgramFiles%\vrrw32\<File name>.vbs
- %ProgramFiles%\vshwin32\<File name>.vbs
- %ProgramFiles%\vsmon\<File name>.vbs
- %ProgramFiles%\vsserv\<File name>.vbs
- %ProgramFiles%\vsstat\<File name>.vbs
- %ProgramFiles%\wclose\<File name>.vbs
- %ProgramFiles%\webfiltr\<File name>.vbs
- %ProgramFiles%\webmoney\<File name>.vbs
- %ProgramFiles%\webproxy\<File name>.vbs
- %ProgramFiles%\webscanx\<File name>.vbs
- %ProgramFiles%\vettray\<File name>.vbs
- %ProgramFiles%\wil\<File name>.vbs
- %ProgramFiles%\vcrmon\<File name>.vbs
- %ProgramFiles%\vbsntw\<File name>.vbs
- %ProgramFiles%\uninstall information\<File name>.vbs
- %ProgramFiles%\uninstallcavs\<File name>.vbs
- %ProgramFiles%\uninstaller\<File name>.vbs
- %ProgramFiles%\uninstalllsp\<File name>.vbs
- %ProgramFiles%\unoinfo\<File name>.vbs
- %ProgramFiles%\unopkg\<File name>.vbs
- %ProgramFiles%\unp_test\<File name>.vbs
- %ProgramFiles%\up2date\<File name>.vbs
- %ProgramFiles%\updater\<File name>.vbs
- %ProgramFiles%\updaterui\<File name>.vbs
- %ProgramFiles%\updclient\<File name>.vbs
- %ProgramFiles%\upgrepl\<File name>.vbs
- %ProgramFiles%\upsobmaker\<File name>.vbs
- %ProgramFiles%\usdownloader\<File name>.vbs
- %ProgramFiles%\uupd\<File name>.vbs
- %ProgramFiles%\vba32ecm\<File name>.vbs
- %ProgramFiles%\vba32ifs\<File name>.vbs
- %ProgramFiles%\vba32ldr\<File name>.vbs
- %ProgramFiles%\vba32pp3\<File name>.vbs
- %ProgramFiles%\vchk\<File name>.vbs
- %ProgramFiles%\winaw32\<File name>.vbs
- %ProgramFiles%\winbaram\<File name>.vbs
- %ProgramFiles%\wincmd32\<File name>.vbs
- %ProgramFiles%\wsctool\<File name>.vbs
- %ProgramFiles%\wsm\<File name>.vbs
- %ProgramFiles%\xcommsvr\<File name>.vbs
- %ProgramFiles%\yahoomessenger\<File name>.vbs
- %ProgramFiles%\yahoosync\<File name>.vbs
- %ProgramFiles%\ybclient\<File name>.vbs
- %ProgramFiles%\ymsgr_tray\<File name>.vbs
- %ProgramFiles%\zapro\<File name>.vbs
- %ProgramFiles%\zatutor\<File name>.vbs
- %ProgramFiles%\viritexp\<File name>.vbs
- %ProgramFiles%\zauninst\<File name>.vbs
- %ProgramFiles%\zonealarm\<File name>.vbs
- %ProgramFiles(x86)%\adobe\<File name>.vbs
- %CommonProgramFiles(x86)%\<File name>.vbs
- %ProgramFiles(x86)%\google\<File name>.vbs
- %ProgramFiles(x86)%\internet explorer\<File name>.vbs
- %ProgramFiles(x86)%\k-lite codec pack\<File name>.vbs
- %ProgramFiles(x86)%\microsoft analysis services\<File name>.vbs
- %ProgramFiles%\writespid\<File name>.vbs
- %ProgramFiles%\wrctrl\<File name>.vbs
- %ProgramFiles%\wsftpgui\<File name>.vbs
- %ProgramFiles%\wradmin\<File name>.vbs
- %ProgramFiles%\wow\<File name>.vbs
- %ProgramFiles%\windowlist\<File name>.vbs
- %ProgramFiles%\windows journal\<File name>.vbs
- %ProgramFiles%\windows mail\<File name>.vbs
- %ProgramFiles%\windows media player\<File name>.vbs
- %ProgramFiles%\windows nt\<File name>.vbs
- %ProgramFiles%\windows photo viewer\<File name>.vbs
- %ProgramFiles%\windows portable devices\<File name>.vbs
- %ProgramFiles%\windows sidebar\<File name>.vbs
- %ProgramFiles(x86)%\microsoft visual studio .net 2003\<File name>.vbs
- %ProgramFiles%\windump\<File name>.vbs
- %ProgramFiles%\una\<File name>.vbs
- %ProgramFiles%\winrar\<File name>.vbs
- %ProgramFiles%\winss\<File name>.vbs
- %ProgramFiles%\winssnotify\<File name>.vbs
- %ProgramFiles%\wish\<File name>.vbs
- %ProgramFiles%\wlloginproxy\<File name>.vbs
- %ProgramFiles%\wlmail\<File name>.vbs
- %ProgramFiles%\wltuser\<File name>.vbs
- %ProgramFiles%\woool\<File name>.vbs
- %ProgramFiles%\winmail\<File name>.vbs
- %ProgramFiles%\windows defender\<File name>.vbs
- %ProgramFiles%\winroute\<File name>.vbs
- %ProgramFiles%\neowatchtray\<File name>.vbs
- %ProgramFiles%\neowatchlog\<File name>.vbs
- %ProgramFiles%\navwnt\<File name>.vbs
- %ProgramFiles%\cavse\<File name>.vbs
- %ProgramFiles%\cavsn\<File name>.vbs
- %ProgramFiles%\cavsub\<File name>.vbs
- %ProgramFiles%\cavsubmit\<File name>.vbs
- %ProgramFiles%\cavumas\<File name>.vbs
- %ProgramFiles%\cavuserupd\<File name>.vbs
- %ProgramFiles%\cavvl\<File name>.vbs
- %ProgramFiles%\ccapp\<File name>.vbs
- %ProgramFiles%\ccevtmgr\<File name>.vbs
- %ProgramFiles%\ccleaner\<File name>.vbs
- %ProgramFiles%\ccproxy\<File name>.vbs
- %ProgramFiles%\ccsetmgr\<File name>.vbs
- %ProgramFiles%\cemrep\<File name>.vbs
- %ProgramFiles%\chrome\<File name>.vbs
- %ProgramFiles%\clamscan\<File name>.vbs
- %ProgramFiles%\clamtray\<File name>.vbs
- %ProgramFiles%\clamwin\<File name>.vbs
- %ProgramFiles%\cavoar\<File name>.vbs
- %ProgramFiles%\cavmud\<File name>.vbs
- %ProgramFiles%\cavscons\<File name>.vbs
- %ProgramFiles%\cleaner\<File name>.vbs
- %ProgramFiles%\claw95\<File name>.vbs
- %ProgramFiles%\claw95cf\<File name>.vbs
- %ProgramFiles%\bdoesrv\<File name>.vbs
- %ProgramFiles%\bdss\<File name>.vbs
- %ProgramFiles%\bdsubmit\<File name>.vbs
- %ProgramFiles%\bdsubmitwiz\<File name>.vbs
- %ProgramFiles%\bdsurvey\<File name>.vbs
- %ProgramFiles%\bdswitch\<File name>.vbs
- %ProgramFiles%\bdwizreg\<File name>.vbs
- %ProgramFiles%\blackd\<File name>.vbs
- %ProgramFiles%\blackice\<File name>.vbs
- %ProgramFiles%\blindman\<File name>.vbs
- %ProgramFiles%\btini\<File name>.vbs
- %ProgramFiles%\btinint\<File name>.vbs
- %ProgramFiles%\cabalmain\<File name>.vbs
- %ProgramFiles%\cafix\<File name>.vbs
- %ProgramFiles%\cavapp\<File name>.vbs
- %ProgramFiles%\cavasm\<File name>.vbs
- %ProgramFiles%\cavaud\<File name>.vbs
- %ProgramFiles%\cavmr\<File name>.vbs
- %ProgramFiles%\bdmcon\<File name>.vbs
- %ProgramFiles%\cavemsrv\<File name>.vbs
- %ProgramFiles%\cleaner3\<File name>.vbs
- %ProgramFiles%\drvctl\<File name>.vbs
- %ProgramFiles%\cmain\<File name>.vbs
- %ProgramFiles%\drwadins\<File name>.vbs
- %ProgramFiles%\drweb\<File name>.vbs
- %ProgramFiles%\drweb32w\<File name>.vbs
- %ProgramFiles%\drweb386\<File name>.vbs
- %ProgramFiles%\drwebscd\<File name>.vbs
- %ProgramFiles%\drwebupw\<File name>.vbs
- %ProgramFiles%\drwebwcl\<File name>.vbs
- %ProgramFiles%\aswupdsv\<File name>.vbs
- %ProgramFiles%\drwreg\<File name>.vbs
- %ProgramFiles%\ecmd\<File name>.vbs
- %ProgramFiles%\egni\<File name>.vbs
- %ProgramFiles%\ehsniffer\<File name>.vbs
- %ProgramFiles%\ekrn\<File name>.vbs
- %ProgramFiles%\elementclient\<File name>.vbs
- %ProgramFiles%\etherd\<File name>.vbs
- %ProgramFiles%\eudora\<File name>.vbs
- %ProgramFiles%\dpatrolq\<File name>.vbs
- %ProgramFiles%\dnf\<File name>.vbs
- %ProgramFiles%\dvd maker\<File name>.vbs
- %ProgramFiles%\drvmap\<File name>.vbs
- %ProgramFiles%\drvirus\<File name>.vbs
- %ProgramFiles%\dislite\<File name>.vbs
- %ProgramFiles%\directftp\<File name>.vbs
- %ProgramFiles%\cmgrdian\<File name>.vbs
- %CommonProgramFiles%\<File name>.vbs
- %ProgramFiles%\copyx64\<File name>.vbs
- %ProgramFiles%\courier\<File name>.vbs
- %ProgramFiles%\cpd\<File name>.vbs
- %ProgramFiles%\csendto\<File name>.vbs
- %ProgramFiles%\bdagent\<File name>.vbs
- %ProgramFiles%\cssexc\<File name>.vbs
- %ProgramFiles%\custsetup\<File name>.vbs
- %ProgramFiles%\bdnews\<File name>.vbs
- %ProgramFiles%\cuteftp\<File name>.vbs
- %ProgramFiles%\dbtool\<File name>.vbs
- %ProgramFiles%\defensewall\<File name>.vbs
- %ProgramFiles%\defwatch\<File name>.vbs
- %ProgramFiles%\dekaron\<File name>.vbs
- %ProgramFiles%\digsby\<File name>.vbs
- %ProgramFiles%\digsby-app\<File name>.vbs
- %ProgramFiles%\custinstall\<File name>.vbs
- %ProgramFiles%\clrcche\<File name>.vbs
- %ProgramFiles%\clisvc\<File name>.vbs
- %ProgramFiles%\dbconvert\<File name>.vbs
- %WINDIR%\web\<File name>.vbs
- %ProgramFiles%\ewidoctrl\<File name>.vbs
- %ProgramFiles%\avsynmgr\<File name>.vbs
- %ProgramFiles%\aim6\<File name>.vbs
- %ProgramFiles%\aimpro\<File name>.vbs
- %ProgramFiles%\airdefense\<File name>.vbs
- %ProgramFiles%\almon\<File name>.vbs
- %ProgramFiles%\alsvc\<File name>.vbs
- %ProgramFiles%\amon\<File name>.vbs
- %ProgramFiles%\amsn\<File name>.vbs
- %ProgramFiles%\anti-trojan\<File name>.vbs
- %ProgramFiles%\antivirus\<File name>.vbs
- %ProgramFiles%\aoltbserver\<File name>.vbs
- %ProgramFiles%\armor2net\<File name>.vbs
- %ProgramFiles%\armorsurf\<File name>.vbs
- %ProgramFiles%\ash\<File name>.vbs
- %ProgramFiles%\ashavast\<File name>.vbs
- %ProgramFiles%\ashavsrv\<File name>.vbs
- %ProgramFiles%\ashchest\<File name>.vbs
- %ProgramFiles%\ashdisp\<File name>.vbs
- %ProgramFiles%\ashdug\<File name>.vbs
- %ProgramFiles%\ageofconan\<File name>.vbs
- %ProgramFiles%\ashenhcd\<File name>.vbs
- %ProgramFiles%\agb5\<File name>.vbs
- %ProgramFiles%\ackwin32\<File name>.vbs
- C:\far2\addons\<File name>.vbs
- C:\far2\documentation\<File name>.vbs
- C:\far2\encyclopedia\<File name>.vbs
- C:\far2\fexcept\<File name>.vbs
- C:\far2\plugins\<File name>.vbs
- C:\far2\pluginsdk\<File name>.vbs
- C:\msocache\all users\<File name>.vbs
- C:\perflogs\admin\<File name>.vbs
- %ProgramFiles%\360tray\<File name>.vbs
- %ProgramFiles%\a2cmd\<File name>.vbs
- %ProgramFiles%\a2guard\<File name>.vbs
- %ProgramFiles%\a2hijackfree\<File name>.vbs
- %ProgramFiles%\a2scan\<File name>.vbs
- %ProgramFiles%\a2service\<File name>.vbs
- %ProgramFiles%\a2start\<File name>.vbs
- %ProgramFiles%\a2upd\<File name>.vbs
- %ProgramFiles%\a2wizard\<File name>.vbs
- %ProgramFiles%\aavshield\<File name>.vbs
- %ProgramFiles%\about\<File name>.vbs
- %ProgramFiles%\admunch\<File name>.vbs
- %ProgramFiles%\ashlogv\<File name>.vbs
- %ProgramFiles%\ahnsd\<File name>.vbs
- %ProgramFiles%\ashmaisv\<File name>.vbs
- %ProgramFiles%\avgfwsrv\<File name>.vbs
- %ProgramFiles%\avgnpdln\<File name>.vbs
- %ProgramFiles%\avgnpsvc\<File name>.vbs
- %ProgramFiles%\avgrssvc\<File name>.vbs
- %ProgramFiles%\avgscan\<File name>.vbs
- %ProgramFiles%\avgupden\<File name>.vbs
- %ProgramFiles%\avgupsvc\<File name>.vbs
- %ProgramFiles%\avgvv\<File name>.vbs
- %ProgramFiles%\avgw\<File name>.vbs
- %ProgramFiles%\avgwizfw\<File name>.vbs
- %ProgramFiles%\avinitnt\<File name>.vbs
- %ProgramFiles%\avkserv\<File name>.vbs
- %ProgramFiles%\avkservice\<File name>.vbs
- %ProgramFiles%\avkwctl\<File name>.vbs
- %ProgramFiles%\avnotify\<File name>.vbs
- %ProgramFiles%\avpcc\<File name>.vbs
- %ProgramFiles%\avpm\<File name>.vbs
- %ProgramFiles%\avscan\<File name>.vbs
- %ProgramFiles%\avgemc\<File name>.vbs
- %ProgramFiles%\avgcc\<File name>.vbs
- %ProgramFiles%\avginet\<File name>.vbs
- %ProgramFiles%\avgdiag\<File name>.vbs
- %ProgramFiles%\avgamsvr\<File name>.vbs
- %ProgramFiles%\ashpopwz\<File name>.vbs
- %ProgramFiles%\ashserv\<File name>.vbs
- %ProgramFiles%\ashsimp2\<File name>.vbs
- %ProgramFiles%\ashsimpl\<File name>.vbs
- %ProgramFiles%\ashskpcc\<File name>.vbs
- %ProgramFiles%\ashskpck\<File name>.vbs
- %ProgramFiles%\ashupd\<File name>.vbs
- %ProgramFiles%\ashwebsv\<File name>.vbs
- %ProgramFiles%\ash_updatemediator\<File name>.vbs
- %ProgramFiles%\b2\<File name>.vbs
- %ProgramFiles%\backweb-4476822\<File name>.vbs
- %ProgramFiles%\aswregsvr\<File name>.vbs
- %ProgramFiles%\autostartexplorer\<File name>.vbs
- %ProgramFiles%\autotrace\<File name>.vbs
- %ProgramFiles%\avadmin\<File name>.vbs
- %ProgramFiles%\avcenter\<File name>.vbs
- %ProgramFiles%\avciman\<File name>.vbs
- %ProgramFiles%\avcmd\<File name>.vbs
- %ProgramFiles%\avconfig\<File name>.vbs
- %ProgramFiles%\avconsol\<File name>.vbs
- %ProgramFiles%\ashquick\<File name>.vbs
- %ProgramFiles%\autodown\<File name>.vbs
- %WINDIR%\system\<File name>.vbs
- %ProgramFiles%\exit_av\<File name>.vbs
- %ProgramFiles%\fameh32\<File name>.vbs
- %ProgramFiles%\isuac\<File name>.vbs
- %ProgramFiles%\itunes\<File name>.vbs
- %ProgramFiles%\java\<File name>.vbs
- %ProgramFiles%\k-meleon\<File name>.vbs
- %ProgramFiles%\kav\<File name>.vbs
- %ProgramFiles%\kavmm\<File name>.vbs
- %ProgramFiles%\kavpf\<File name>.vbs
- %ProgramFiles%\kavpfw\<File name>.vbs
- %ProgramFiles%\kavstart\<File name>.vbs
- %ProgramFiles%\kavsvc\<File name>.vbs
- %ProgramFiles%\konnekt\<File name>.vbs
- %ProgramFiles%\launcher\<File name>.vbs
- %ProgramFiles%\licmgr\<File name>.vbs
- %ProgramFiles%\livesrv\<File name>.vbs
- %ProgramFiles%\liveupdate\<File name>.vbs
- %ProgramFiles%\logwatnt\<File name>.vbs
- %ProgramFiles%\lotroclient\<File name>.vbs
- %ProgramFiles%\lpfw\<File name>.vbs
- %ProgramFiles%\lucallbackproxy\<File name>.vbs
- %ProgramFiles%\issvc\<File name>.vbs
- %ProgramFiles%\lucheck\<File name>.vbs
- %ProgramFiles%\ispwdsvc\<File name>.vbs
- %ProgramFiles%\isafe\<File name>.vbs
- %ProgramFiles%\ih8run\<File name>.vbs
- %ProgramFiles%\ilaunchr\<File name>.vbs
- %ProgramFiles%\imapp\<File name>.vbs
- %ProgramFiles%\imnotfy\<File name>.vbs
- %ProgramFiles%\impcnt\<File name>.vbs
- %ProgramFiles%\incmail\<File name>.vbs
- %ProgramFiles%\inocit\<File name>.vbs
- %ProgramFiles%\inorpc\<File name>.vbs
- %ProgramFiles%\inort\<File name>.vbs
- %ProgramFiles%\inotask\<File name>.vbs
- %ProgramFiles%\inouptng\<File name>.vbs
- %ProgramFiles%\inphasenxd\<File name>.vbs
- %ProgramFiles%\installcavs\<File name>.vbs
- %ProgramFiles%\installlicense\<File name>.vbs
- %ProgramFiles%\installlsp\<File name>.vbs
- %ProgramFiles%\instlsp\<File name>.vbs
- %ProgramFiles%\internet explorer\<File name>.vbs
- %ProgramFiles%\iris\<File name>.vbs
- %ProgramFiles%\iron\<File name>.vbs
- %ProgramFiles%\ispnews\<File name>.vbs
- %ProgramFiles%\luconfig\<File name>.vbs
- %ProgramFiles%\luinit\<File name>.vbs
- %ProgramFiles%\luupdate\<File name>.vbs
- %ProgramFiles%\mp3tray\<File name>.vbs
- %ProgramFiles%\mpeng\<File name>.vbs
- %ProgramFiles%\mpftray\<File name>.vbs
- %ProgramFiles%\mpssvc\<File name>.vbs
- %ProgramFiles%\msbuild\<File name>.vbs
- %ProgramFiles%\msimn\<File name>.vbs
- %ProgramFiles%\msmpsvc\<File name>.vbs
- %ProgramFiles%\ezantivirusregistrationcheck\<File name>.vbs
- %ProgramFiles%\msn6\<File name>.vbs
- %ProgramFiles%\mva\<File name>.vbs
- %ProgramFiles%\mvc\<File name>.vbs
- %ProgramFiles%\myagtsvc\<File name>.vbs
- %ProgramFiles%\myagttry\<File name>.vbs
- %ProgramFiles%\navapsvc\<File name>.vbs
- %ProgramFiles%\navlu32\<File name>.vbs
- %ProgramFiles%\navstub\<File name>.vbs
- %ProgramFiles%\navw32\<File name>.vbs
- %ProgramFiles%\mp3theater\<File name>.vbs
- %ProgramFiles%\msnmsgr\<File name>.vbs
- %ProgramFiles%\mp3toystray\<File name>.vbs
- %ProgramFiles%\mp3toys\<File name>.vbs
- %ProgramFiles%\monsysnt\<File name>.vbs
- %ProgramFiles%\monlite\<File name>.vbs
- %ProgramFiles%\magent\<File name>.vbs
- %ProgramFiles%\malwareremoval\<File name>.vbs
- %ProgramFiles%\maplestory\<File name>.vbs
- %ProgramFiles%\maxthon\<File name>.vbs
- %ProgramFiles%\mcmnhdlr\<File name>.vbs
- %ProgramFiles%\mcregwiz\<File name>.vbs
- %ProgramFiles%\mcshield\<File name>.vbs
- %ProgramFiles%\iexplore\<File name>.vbs
- %ProgramFiles%\mcupdmgr\<File name>.vbs
- %ProgramFiles%\ih8\<File name>.vbs
- %ProgramFiles%\memstring\<File name>.vbs
- %ProgramFiles%\microsoft analysis services\<File name>.vbs
- %ProgramFiles%\microsoft office\<File name>.vbs
- %ProgramFiles%\microsoft sql server compact edition\<File name>.vbs
- %ProgramFiles%\microsoft sync framework\<File name>.vbs
- %ProgramFiles%\microsoft synchronization services\<File name>.vbs
- %ProgramFiles%\mir3game\<File name>.vbs
- %ProgramFiles%\miranda32\<File name>.vbs
- %ProgramFiles%\luna\<File name>.vbs
- %ProgramFiles%\miro\<File name>.vbs
- %ProgramFiles%\mfpmp\<File name>.vbs
- %ProgramFiles%\f-sched\<File name>.vbs
- %ProgramFiles%\mcvsshld\<File name>.vbs
- %ProgramFiles%\cavq\<File name>.vbs
- %ProgramFiles%\fsav\<File name>.vbs
- %ProgramFiles%\fsav32\<File name>.vbs
- %ProgramFiles%\fsavaui\<File name>.vbs
- %ProgramFiles%\fsavgui\<File name>.vbs
- %ProgramFiles%\fsavstrt\<File name>.vbs
- %ProgramFiles%\fsavwsch\<File name>.vbs
- %ProgramFiles%\fsavwscr\<File name>.vbs
- %ProgramFiles%\fsbwsys\<File name>.vbs
- %ProgramFiles%\fsdbuh\<File name>.vbs
- %ProgramFiles%\fsdc\<File name>.vbs
- %ProgramFiles%\fsdfwd\<File name>.vbs
- %ProgramFiles%\fsdiag\<File name>.vbs
- %ProgramFiles%\fsdiagui\<File name>.vbs
- %ProgramFiles%\fsfwwsch\<File name>.vbs
- %ProgramFiles%\fsfwwscr\<File name>.vbs
- %ProgramFiles%\fsgetwab\<File name>.vbs
- %ProgramFiles%\fsgk32\<File name>.vbs
- %ProgramFiles%\fsgk32st\<File name>.vbs
- %ProgramFiles%\fsguidll\<File name>.vbs
- %ProgramFiles%\fsauach\<File name>.vbs
- %ProgramFiles%\fsguiexe\<File name>.vbs
- %ProgramFiles%\fsaua\<File name>.vbs
- %ProgramFiles%\freshclam\<File name>.vbs
- %ProgramFiles%\far\<File name>.vbs
- %ProgramFiles%\fch32\<File name>.vbs
- %ProgramFiles%\fdm\<File name>.vbs
- %ProgramFiles%\fdmwi\<File name>.vbs
- %ProgramFiles%\filezilla\<File name>.vbs
- %ProgramFiles%\firebird\<File name>.vbs
- %ProgramFiles%\firefox\<File name>.vbs
- %ProgramFiles%\firesvc\<File name>.vbs
- %ProgramFiles%\firetray\<File name>.vbs
- %ProgramFiles%\flashfxp\<File name>.vbs
- %ProgramFiles%\flashgot\<File name>.vbs
- %ProgramFiles%\flock\<File name>.vbs
- %ProgramFiles%\foxit\<File name>.vbs
- %ProgramFiles%\fpavserver\<File name>.vbs
- %ProgramFiles%\fpavupdm\<File name>.vbs
- %ProgramFiles%\fprottray\<File name>.vbs
- %ProgramFiles%\fpscan\<File name>.vbs
- %ProgramFiles%\fptrayproc\<File name>.vbs
- %ProgramFiles%\fpwin\<File name>.vbs
- %ProgramFiles%\fsample\<File name>.vbs
- %ProgramFiles%\fshdll32\<File name>.vbs
- %ProgramFiles%\fshelp\<File name>.vbs
- %ProgramFiles%\fsihcomp\<File name>.vbs
- %ProgramFiles%\gnotify\<File name>.vbs
- %ProgramFiles%\googledesktop\<File name>.vbs
- %ProgramFiles%\googletalk\<File name>.vbs
- %ProgramFiles%\googleupdate\<File name>.vbs
- %ProgramFiles%\guardgni\<File name>.vbs
- %ProgramFiles%\guardnt\<File name>.vbs
- %ProgramFiles%\gw\<File name>.vbs
- %ProgramFiles%\icqlite\<File name>.vbs
- %ProgramFiles%\helpctr\<File name>.vbs
- %ProgramFiles%\hipsdiag\<File name>.vbs
- %ProgramFiles%\hregmon\<File name>.vbs
- %ProgramFiles%\hrres\<File name>.vbs
- %ProgramFiles%\hsockpe\<File name>.vbs
- %ProgramFiles%\httplook\<File name>.vbs
- %ProgramFiles%\iamapp\<File name>.vbs
- %ProgramFiles%\iamserv\<File name>.vbs
- %ProgramFiles%\icq\<File name>.vbs
- %ProgramFiles%\gg\<File name>.vbs
- %ProgramFiles%\helper\<File name>.vbs
- %ProgramFiles%\giantantispywareupdater\<File name>.vbs
- %ProgramFiles%\giantantispywaremain\<File name>.vbs
- %ProgramFiles%\ge\<File name>.vbs
- %ProgramFiles%\gcasserv\<File name>.vbs
- %ProgramFiles%\fsihs\<File name>.vbs
- %ProgramFiles%\fslaunch\<File name>.vbs
- %ProgramFiles%\fsm32\<File name>.vbs
- %ProgramFiles%\fsma32\<File name>.vbs
- %ProgramFiles%\fsmb32\<File name>.vbs
- %ProgramFiles%\fspc\<File name>.vbs
- %ProgramFiles%\fspex\<File name>.vbs
- %ProgramFiles%\ieregfix\<File name>.vbs
- %ProgramFiles%\fsqh\<File name>.vbs
- %ProgramFiles%\ieuser\<File name>.vbs
- %ProgramFiles%\fssg\<File name>.vbs
- %ProgramFiles%\fsstm\<File name>.vbs
- %ProgramFiles%\fssw\<File name>.vbs
- %ProgramFiles%\fstlui\<File name>.vbs
- %ProgramFiles%\fsuninst\<File name>.vbs
- %ProgramFiles%\fsus\<File name>.vbs
- %ProgramFiles%\ftpte\<File name>.vbs
- %ProgramFiles%\gc\<File name>.vbs
- %ProgramFiles%\fshotfix\<File name>.vbs
- %ProgramFiles%\gcasdtserv\<File name>.vbs
- %ProgramFiles%\fssm32\<File name>.vbs
- D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\<File name>.vbs
- <Drive name for removable media>:\<File name>.vbs
- %ProgramFiles%\scanningprocess\<File name>.vbs
- %ProgramFiles%\sched\<File name>.vbs
- %ProgramFiles%\sdhelp\<File name>.vbs
- %ProgramFiles%\sdinvoker\<File name>.vbs
- %ProgramFiles%\sdloader\<File name>.vbs
- %ProgramFiles%\sdraw\<File name>.vbs
- %ProgramFiles%\sdtrayapp\<File name>.vbs
- %ProgramFiles%\seamonkey\<File name>.vbs
- %ProgramFiles%\seccenter\<File name>.vbs
- %ProgramFiles%\sfagent\<File name>.vbs
- %ProgramFiles%\sigtool\<File name>.vbs
- %ProgramFiles%\simpress\<File name>.vbs
- %ProgramFiles%\sitecli\<File name>.vbs
- %ProgramFiles%\skype\<File name>.vbs
- %ProgramFiles%\skypepm\<File name>.vbs
- %ProgramFiles%\smartftp\<File name>.vbs
- %ProgramFiles%\smath\<File name>.vbs
- %ProgramFiles%\smc\<File name>.vbs
- %ProgramFiles%\sndsrvc\<File name>.vbs
- %ProgramFiles%\scanner\<File name>.vbs
- %ProgramFiles%\sniffer\<File name>.vbs
- %ProgramFiles%\scalc\<File name>.vbs
- %ProgramFiles%\savscan\<File name>.vbs
- %ProgramFiles%\ravtimer\<File name>.vbs
- %ProgramFiles%\rcimlby\<File name>.vbs
- %ProgramFiles%\realmon\<File name>.vbs
- %ProgramFiles%\reference assemblies\<File name>.vbs
- %ProgramFiles%\register\<File name>.vbs
- %ProgramFiles%\removeit\<File name>.vbs
- %ProgramFiles%\remover\<File name>.vbs
- %ProgramFiles%\rescue\<File name>.vbs
- %ProgramFiles%\rfwmain\<File name>.vbs
- %ProgramFiles%\rq\<File name>.vbs
- %ProgramFiles%\rtvscan\<File name>.vbs
- %ProgramFiles%\rulaunch\<File name>.vbs
- %ProgramFiles%\runsetup\<File name>.vbs
- %ProgramFiles%\safari\<File name>.vbs
- %ProgramFiles%\sarcli\<File name>.vbs
- %ProgramFiles%\sargui\<File name>.vbs
- %ProgramFiles%\savadminservice\<File name>.vbs
- %ProgramFiles%\savmain\<File name>.vbs
- %ProgramFiles%\savprogress\<File name>.vbs
- %ProgramFiles%\sbase\<File name>.vbs
- %ProgramFiles%\so3d\<File name>.vbs
- %ProgramFiles%\soffice\<File name>.vbs
- %ProgramFiles%\spamcfg\<File name>.vbs
- %ProgramFiles%\tca\<File name>.vbs
- %ProgramFiles%\teatimer\<File name>.vbs
- %ProgramFiles%\tgsvcstp\<File name>.vbs
- %ProgramFiles%\thebat\<File name>.vbs
- %ProgramFiles%\thgnard\<File name>.vbs
- %ProgramFiles%\thunderbird\<File name>.vbs
- %ProgramFiles%\tmas\<File name>.vbs
- %ProgramFiles%\tmlisten\<File name>.vbs
- %ProgramFiles%\trtddptr\<File name>.vbs
- %ProgramFiles%\tmntsrv\<File name>.vbs
- %ProgramFiles%\tmproxy\<File name>.vbs
- %ProgramFiles%\tnbutil\<File name>.vbs
- %ProgramFiles%\totalcmd\<File name>.vbs
- %ProgramFiles%\tracelog\<File name>.vbs
- %ProgramFiles%\traymon\<File name>.vbs
- %ProgramFiles%\trillian\<File name>.vbs
- %ProgramFiles%\trojanguarder\<File name>.vbs
- %ProgramFiles%\trojanhunter\<File name>.vbs
- %ProgramFiles%\sysinfo\<File name>.vbs
- %ProgramFiles%\tbmon\<File name>.vbs
- %ProgramFiles%\symwsc\<File name>.vbs
- %ProgramFiles%\symsport\<File name>.vbs
- %ProgramFiles%\symproxysvc\<File name>.vbs
- %ProgramFiles%\spider\<File name>.vbs
- %ProgramFiles%\spiderml\<File name>.vbs
- %ProgramFiles%\spidernt\<File name>.vbs
- %ProgramFiles%\spiderui\<File name>.vbs
- %ProgramFiles%\sporder\<File name>.vbs
- %ProgramFiles%\spybotsd\<File name>.vbs
- %ProgramFiles%\sro_client\<File name>.vbs
- %ProgramFiles%\start_diag\<File name>.vbs
- %ProgramFiles%\ravmon\<File name>.vbs
- %ProgramFiles%\streetsolkshim\<File name>.vbs
- %ProgramFiles%\stopsignav\<File name>.vbs
- %ProgramFiles%\svcntaux\<File name>.vbs
- %ProgramFiles%\swagent\<File name>.vbs
- %ProgramFiles%\swdoctor\<File name>.vbs
- %ProgramFiles%\swdsvc\<File name>.vbs
- %ProgramFiles%\sweb\<File name>.vbs
- %ProgramFiles%\swriter\<File name>.vbs
- %ProgramFiles%\symantecrootinstaller\<File name>.vbs
- %ProgramFiles%\symlcsvc\<File name>.vbs
- %ProgramFiles%\spbbcsvc\<File name>.vbs
- %ProgramFiles%\submitfiles\<File name>.vbs
- %ProgramFiles%\tmpfw\<File name>.vbs
- %ProgramFiles%\rat\<File name>.vbs
- %ProgramFiles%\pxsupport\<File name>.vbs
- %ProgramFiles%\oaui\<File name>.vbs
- %ProgramFiles%\ofcpfwsvc\<File name>.vbs
- %ProgramFiles%\oget\<File name>.vbs
- %ProgramFiles%\oladdin\<File name>.vbs
- %ProgramFiles%\onaccessinstaller\<File name>.vbs
- %ProgramFiles%\opera\<File name>.vbs
- %ProgramFiles%\oscheck\<File name>.vbs
- %ProgramFiles%\outlook\<File name>.vbs
- %ProgramFiles%\outpost\<File name>.vbs
- %ProgramFiles%\partin\<File name>.vbs
- %ProgramFiles%\partin9x\<File name>.vbs
- %ProgramFiles%\partinfo\<File name>.vbs
- %ProgramFiles%\partinnt\<File name>.vbs
- %ProgramFiles%\pavfires\<File name>.vbs
- %ProgramFiles%\pavfnsvr\<File name>.vbs
- %ProgramFiles%\pavkre\<File name>.vbs
- %ProgramFiles%\pavprot\<File name>.vbs
- %ProgramFiles%\pavproxy\<File name>.vbs
- %ProgramFiles%\pavprsrv\<File name>.vbs
- %ProgramFiles%\oasrv\<File name>.vbs
- %ProgramFiles%\pavsrv51\<File name>.vbs
- %ProgramFiles%\nwservice\<File name>.vbs
- %ProgramFiles%\nvcte\<File name>.vbs
- %ProgramFiles%\netstatviewer\<File name>.vbs
- %ProgramFiles%\netxray\<File name>.vbs
- %ProgramFiles%\nisoptui\<File name>.vbs
- %ProgramFiles%\nod\<File name>.vbs
- %ProgramFiles%\nod32\<File name>.vbs
- %ProgramFiles%\nod32krn\<File name>.vbs
- %ProgramFiles%\nod32kui\<File name>.vbs
- %ProgramFiles%\notifyha\<File name>.vbs
- %ProgramFiles%\notstart\<File name>.vbs
- %ProgramFiles%\npavtray\<File name>.vbs
- %ProgramFiles%\npfmsg\<File name>.vbs
- %ProgramFiles%\nsmdtr\<File name>.vbs
- %ProgramFiles%\nssserv\<File name>.vbs
- %ProgramFiles%\nsstray\<File name>.vbs
- %ProgramFiles%\ntoskrnl\<File name>.vbs
- %ProgramFiles%\ntrtscan\<File name>.vbs
- %ProgramFiles%\ntxconfig\<File name>.vbs
- %ProgramFiles%\nupgrade\<File name>.vbs
- %ProgramFiles%\nvcod\<File name>.vbs
- %ProgramFiles%\nvcut\<File name>.vbs
- %ProgramFiles%\pccguide\<File name>.vbs
- %ProgramFiles%\pccntmon\<File name>.vbs
- %ProgramFiles%\pccpfw\<File name>.vbs
- %ProgramFiles%\ps\<File name>.vbs
- %ProgramFiles%\psctrls\<File name>.vbs
- %ProgramFiles%\pshost\<File name>.vbs
- %ProgramFiles%\psimsvc\<File name>.vbs
- %ProgramFiles%\pxagent\<File name>.vbs
- %ProgramFiles%\pxconsole\<File name>.vbs
- %ProgramFiles%\pxl\<File name>.vbs
- %ProgramFiles%\pxl1\<File name>.vbs
- %ProgramFiles%\ragfree\<File name>.vbs
- %ProgramFiles%\pxreset\<File name>.vbs
- %ProgramFiles%\python\<File name>.vbs
- %ProgramFiles%\qhwscsvc\<File name>.vbs
- %ProgramFiles%\qip\<File name>.vbs
- %ProgramFiles%\qklez\<File name>.vbs
- %ProgramFiles%\qrtfix\<File name>.vbs
- %ProgramFiles%\quaranti\<File name>.vbs
- %ProgramFiles%\quickstart\<File name>.vbs
- %ProgramFiles%\ragexe\<File name>.vbs
- %ProgramFiles%\processviewer\<File name>.vbs
- %ProgramFiles%\protect\<File name>.vbs
- %ProgramFiles%\privatebrowser\<File name>.vbs
- %ProgramFiles%\prevxsetup\<File name>.vbs
- %ProgramFiles%\prevsrv\<File name>.vbs
- %ProgramFiles%\pctav\<File name>.vbs
- %ProgramFiles%\pertsk\<File name>.vbs
- %ProgramFiles%\pidgin\<File name>.vbs
- %ProgramFiles%\pm\<File name>.vbs
- %ProgramFiles%\pm8flash\<File name>.vbs
- %ProgramFiles%\pmagic\<File name>.vbs
- %ProgramFiles%\pmagic9x\<File name>.vbs
- %ProgramFiles%\pmagicbt\<File name>.vbs
- %ProgramFiles%\rapget\<File name>.vbs
- %ProgramFiles%\polutil\<File name>.vbs
- %ProgramFiles%\pmagicnt\<File name>.vbs
- %ProgramFiles%\ppfw\<File name>.vbs
- %ProgramFiles%\pqboot32\<File name>.vbs
- %ProgramFiles%\pqbw\<File name>.vbs
- %ProgramFiles%\pqpe\<File name>.vbs
- %ProgramFiles%\pqpe9x\<File name>.vbs
- %ProgramFiles%\pqpent\<File name>.vbs
- %ProgramFiles%\preconfig\<File name>.vbs
- %ProgramFiles%\preupd\<File name>.vbs
- %ProgramFiles%\pcctlcom\<File name>.vbs
- %ProgramFiles%\postinstall\<File name>.vbs
- %ProgramFiles%\twelvesky2\<File name>.vbs
- %ProgramFiles%\uiscan\<File name>.vbs
- %ProgramFiles%\una\<File name>.vbs
- %PROGRAMDATA%\microsoft toolkit\<File name>.vbs
- %PROGRAMDATA%\mozilla\<File name>.vbs
- %PROGRAMDATA%\oracle\<File name>.vbs
- %PROGRAMDATA%\package cache\<File name>.vbs
- %PROGRAMDATA%\start menu\<File name>.vbs
- %PROGRAMDATA%\sun\<File name>.vbs
- %PROGRAMDATA%\templates\<File name>.vbs
- C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\<File name>.vbs
- %WINDIR%\cursors\<File name>.vbs
- C:\totalcmd\language\<File name>.vbs
- C:\users\public\<File name>.vbs
- %HOMEPATH%\<File name>.vbs
- %WINDIR%\addins\<File name>.vbs
- %WINDIR%\appcompat\<File name>.vbs
- %WINDIR%\apppatch\<File name>.vbs
- %WINDIR%\assembly\<File name>.vbs
- %WINDIR%\bitlockerdiscoveryvolumecontents\<File name>.vbs
- %WINDIR%\branding\<File name>.vbs
- %PROGRAMDATA%\microsoft\<File name>.vbs
- %PROGRAMDATA%\microsoft help\<File name>.vbs
- C:\users\default\<File name>.vbs
- %WINDIR%\csc\<File name>.vbs
- %PROGRAMDATA%\desktop\<File name>.vbs
- %ProgramFiles(x86)%\msbuild\<File name>.vbs
- %ProgramFiles(x86)%\opera\<File name>.vbs
- %ProgramFiles(x86)%\pidgin\<File name>.vbs
- %ProgramFiles(x86)%\qip 2012\<File name>.vbs
- %ProgramFiles(x86)%\reference assemblies\<File name>.vbs
- %ProgramFiles(x86)%\steam\<File name>.vbs
- %ProgramFiles(x86)%\uninstall information\<File name>.vbs
- %ProgramFiles(x86)%\winamp\<File name>.vbs
- %ProgramFiles(x86)%\windows defender\<File name>.vbs
- %ProgramFiles(x86)%\windows mail\<File name>.vbs
- %ProgramFiles(x86)%\windows media player\<File name>.vbs
- %ProgramFiles(x86)%\windows nt\<File name>.vbs
- %ProgramFiles(x86)%\windows photo viewer\<File name>.vbs
- %ProgramFiles(x86)%\windows portable devices\<File name>.vbs
- %ProgramFiles(x86)%\windows sidebar\<File name>.vbs
- %PROGRAMDATA%\adobe\<File name>.vbs
- %PROGRAMDATA%\application data\<File name>.vbs
- %PROGRAMDATA%\documents\<File name>.vbs
- %ProgramFiles(x86)%\mozilla firefox\<File name>.vbs
- %PROGRAMDATA%\favorites\<File name>.vbs
- %WINDIR%\web\<File name>.vbs
- %WINDIR%\debug\<File name>.vbs
- %WINDIR%\remotepackages\<File name>.vbs
- %WINDIR%\schcache\<File name>.vbs
- %WINDIR%\schemas\<File name>.vbs
- %WINDIR%\security\<File name>.vbs
- %WINDIR%\serviceprofiles\<File name>.vbs
- %WINDIR%\setup\<File name>.vbs
- %WINDIR%\shellnew\<File name>.vbs
- %WINDIR%\softwaredistribution\<File name>.vbs
- %WINDIR%\speech\<File name>.vbs
- %WINDIR%\digitallocker\<File name>.vbs
- %WINDIR%\system\<File name>.vbs
- %WINDIR%\syswow64\<File name>.vbs
- %WINDIR%\tapi\<File name>.vbs
- %WINDIR%\tasks\<File name>.vbs
- %WINDIR%\temp\<File name>.vbs
- %WINDIR%\tracing\<File name>.vbs
- %WINDIR%\twain_32\<File name>.vbs
- %WINDIR%\vss\<File name>.vbs
- %WINDIR%\registration\<File name>.vbs
- %WINDIR%\prefetch\<File name>.vbs
- %WINDIR%\resources\<File name>.vbs
- %WINDIR%\policydefinitions\<File name>.vbs
- %WINDIR%\pla\<File name>.vbs
- %WINDIR%\downloaded program files\<File name>.vbs
- %WINDIR%\en-us\<File name>.vbs
- %WINDIR%\fonts\<File name>.vbs
- %WINDIR%\globalization\<File name>.vbs
- %WINDIR%\help\<File name>.vbs
- %WINDIR%\ime\<File name>.vbs
- %WINDIR%\inf\<File name>.vbs
- %WINDIR%\installer\<File name>.vbs
- %ProgramFiles(x86)%\mirc\<File name>.vbs
- %WINDIR%\l2schemas\<File name>.vbs
- %ProgramFiles(x86)%\mozilla thunderbird\<File name>.vbs
- %WINDIR%\logs\<File name>.vbs
- %WINDIR%\microsoft.net\<File name>.vbs
- %WINDIR%\migration\<File name>.vbs
- %WINDIR%\modemlogs\<File name>.vbs
- %WINDIR%\offline web pages\<File name>.vbs
- %WINDIR%\panther\<File name>.vbs
- %WINDIR%\pchealth\<File name>.vbs
- %WINDIR%\performance\<File name>.vbs
- %WINDIR%\livekernelreports\<File name>.vbs
- %WINDIR%\ehome\<File name>.vbs
- %WINDIR%\media\<File name>.vbs
- %ProgramFiles(x86)%\microsoft.net\<File name>.vbs
- %ProgramFiles(x86)%\microsoft visual studio 8\<File name>.vbs
- %ProgramFiles(x86)%\microsoft visual studio .net 2003\<File name>.vbs
- %ProgramFiles%\virusnews\<File name>.vbs
- %ProgramFiles%\vistaux\<File name>.vbs
- %ProgramFiles%\visthlic\<File name>.vbs
- %ProgramFiles%\visthupd\<File name>.vbs
- %ProgramFiles%\vrfwsvc\<File name>.vbs
- %ProgramFiles%\vrmonsvc\<File name>.vbs
- %ProgramFiles%\vrrw32\<File name>.vbs
- %ProgramFiles%\vshwin32\<File name>.vbs
- %ProgramFiles%\vsmon\<File name>.vbs
- %ProgramFiles%\vsserv\<File name>.vbs
- %ProgramFiles%\vsstat\<File name>.vbs
- %ProgramFiles%\wclose\<File name>.vbs
- %ProgramFiles%\webfiltr\<File name>.vbs
- %ProgramFiles%\webmoney\<File name>.vbs
- %ProgramFiles%\webproxy\<File name>.vbs
- %ProgramFiles%\webscanx\<File name>.vbs
- %ProgramFiles%\wil\<File name>.vbs
- %ProgramFiles%\viritexp\<File name>.vbs
- %ProgramFiles%\vcrmon\<File name>.vbs
- %ProgramFiles%\viruskeeper\<File name>.vbs
- %ProgramFiles%\vettray\<File name>.vbs
- %ProgramFiles%\vchk\<File name>.vbs
- %ProgramFiles%\updclient\<File name>.vbs
- %ProgramFiles%\uninstallcavs\<File name>.vbs
- %ProgramFiles%\uninstaller\<File name>.vbs
- %ProgramFiles%\uninstalllsp\<File name>.vbs
- %ProgramFiles%\unoinfo\<File name>.vbs
- %ProgramFiles%\unopkg\<File name>.vbs
- %ProgramFiles%\unp_test\<File name>.vbs
- %ProgramFiles%\up2date\<File name>.vbs
- %ProgramFiles%\updater\<File name>.vbs
- %ProgramFiles%\winaw32\<File name>.vbs
- %ProgramFiles%\neowatchtray\<File name>.vbs
- %ProgramFiles%\updaterui\<File name>.vbs
- %ProgramFiles%\upsobmaker\<File name>.vbs
- %ProgramFiles%\usdownloader\<File name>.vbs
- %ProgramFiles%\uupd\<File name>.vbs
- %ProgramFiles%\vba32ecm\<File name>.vbs
- %ProgramFiles%\vba32ifs\<File name>.vbs
- %ProgramFiles%\vba32ldr\<File name>.vbs
- %ProgramFiles%\vba32pp3\<File name>.vbs
- %ProgramFiles%\vbsntw\<File name>.vbs
- %ProgramFiles%\uninstall information\<File name>.vbs
- %ProgramFiles%\upgrepl\<File name>.vbs
- %ProgramFiles%\winrar\<File name>.vbs
- %ProgramFiles%\winbaram\<File name>.vbs
- %ProgramFiles%\windows journal\<File name>.vbs
- %ProgramFiles%\xcommsvr\<File name>.vbs
- %ProgramFiles%\yahoomessenger\<File name>.vbs
- %ProgramFiles%\yahoosync\<File name>.vbs
- %ProgramFiles%\ybclient\<File name>.vbs
- %ProgramFiles%\ymsgr_tray\<File name>.vbs
- %ProgramFiles%\zapro\<File name>.vbs
- %ProgramFiles%\zatutor\<File name>.vbs
- %ProgramFiles%\viritsvc\<File name>.vbs
- %ProgramFiles%\zauninst\<File name>.vbs
- %ProgramFiles%\zonealarm\<File name>.vbs
- %ProgramFiles(x86)%\adobe\<File name>.vbs
- %CommonProgramFiles(x86)%\<File name>.vbs
- %ProgramFiles(x86)%\google\<File name>.vbs
- %ProgramFiles(x86)%\internet explorer\<File name>.vbs
- %ProgramFiles(x86)%\k-lite codec pack\<File name>.vbs
- %ProgramFiles(x86)%\microsoft analysis services\<File name>.vbs
- %ProgramFiles(x86)%\microsoft office\<File name>.vbs
- %ProgramFiles%\wsctool\<File name>.vbs
- %ProgramFiles%\zlclient\<File name>.vbs
- %ProgramFiles%\wsm\<File name>.vbs
- %ProgramFiles%\wsftpgui\<File name>.vbs
- %ProgramFiles%\writespid\<File name>.vbs
- %ProgramFiles%\wrctrl\<File name>.vbs
- %ProgramFiles%\windows mail\<File name>.vbs
- %ProgramFiles%\windows media player\<File name>.vbs
- %ProgramFiles%\windows nt\<File name>.vbs
- %ProgramFiles%\windows photo viewer\<File name>.vbs
- %ProgramFiles%\windows portable devices\<File name>.vbs
- %ProgramFiles%\windows sidebar\<File name>.vbs
- %ProgramFiles%\windump\<File name>.vbs
- %ProgramFiles%\wincmd32\<File name>.vbs
- %ProgramFiles%\winmail\<File name>.vbs
- %ProgramFiles%\windowlist\<File name>.vbs
- %ProgramFiles%\winroute\<File name>.vbs
- %ProgramFiles%\winssnotify\<File name>.vbs
- %ProgramFiles%\wish\<File name>.vbs
- %ProgramFiles%\wlloginproxy\<File name>.vbs
- %ProgramFiles%\wlmail\<File name>.vbs
- %ProgramFiles%\wltuser\<File name>.vbs
- %ProgramFiles%\woool\<File name>.vbs
- %ProgramFiles%\wow\<File name>.vbs
- %ProgramFiles%\windows defender\<File name>.vbs
- %ProgramFiles%\wradmin\<File name>.vbs
- %ProgramFiles%\winss\<File name>.vbs
- <SYSTEM32>\<File name>.vbs
- %ProgramFiles%\neowatchlog\<File name>.vbs
- %ProgramFiles%\msnmsgr\<File name>.vbs
- %ProgramFiles%\cavmud\<File name>.vbs
- %ProgramFiles%\cavoar\<File name>.vbs
- %ProgramFiles%\cavq\<File name>.vbs
- %ProgramFiles%\cavscons\<File name>.vbs
- %ProgramFiles%\cavse\<File name>.vbs
- %ProgramFiles%\cavsn\<File name>.vbs
- %ProgramFiles%\cavsub\<File name>.vbs
- %ProgramFiles%\cavsubmit\<File name>.vbs
- %ProgramFiles%\cavumas\<File name>.vbs
- %ProgramFiles%\cavuserupd\<File name>.vbs
- %ProgramFiles%\cavvl\<File name>.vbs
- %ProgramFiles%\ccapp\<File name>.vbs
- %ProgramFiles%\ccevtmgr\<File name>.vbs
- %ProgramFiles%\ccleaner\<File name>.vbs
- %ProgramFiles%\ccproxy\<File name>.vbs
- %ProgramFiles%\ccsetmgr\<File name>.vbs
- %ProgramFiles%\cemrep\<File name>.vbs
- %ProgramFiles%\chrome\<File name>.vbs
- %ProgramFiles%\clamscan\<File name>.vbs
- %ProgramFiles%\cavmr\<File name>.vbs
- %ProgramFiles%\clamtray\<File name>.vbs
- %ProgramFiles%\cavemsrv\<File name>.vbs
- %ProgramFiles%\cavasm\<File name>.vbs
- %ProgramFiles%\backweb-4476822\<File name>.vbs
- %ProgramFiles%\bdagent\<File name>.vbs
- %ProgramFiles%\bdmcon\<File name>.vbs
- %ProgramFiles%\bdnews\<File name>.vbs
- %ProgramFiles%\bdoesrv\<File name>.vbs
- %ProgramFiles%\bdss\<File name>.vbs
- %ProgramFiles%\bdsubmit\<File name>.vbs
- %ProgramFiles%\bdsubmitwiz\<File name>.vbs
- %ProgramFiles%\bdsurvey\<File name>.vbs
- %ProgramFiles%\bdswitch\<File name>.vbs
- %ProgramFiles%\bdwizreg\<File name>.vbs
- %ProgramFiles%\blackd\<File name>.vbs
- %ProgramFiles%\blackice\<File name>.vbs
- %ProgramFiles%\blindman\<File name>.vbs
- %ProgramFiles%\btini\<File name>.vbs
- %ProgramFiles%\btinint\<File name>.vbs
- %ProgramFiles%\cabalmain\<File name>.vbs
- %ProgramFiles%\cafix\<File name>.vbs
- %ProgramFiles%\cavapp\<File name>.vbs
- %ProgramFiles%\cavaud\<File name>.vbs
- %ProgramFiles%\clamwin\<File name>.vbs
- %ProgramFiles%\claw95\<File name>.vbs
- %ProgramFiles%\claw95cf\<File name>.vbs
- %ProgramFiles%\dpatrolq\<File name>.vbs
- %ProgramFiles%\drvctl\<File name>.vbs
- %ProgramFiles%\drvirus\<File name>.vbs
- %ProgramFiles%\drvmap\<File name>.vbs
- %ProgramFiles%\drwadins\<File name>.vbs
- %ProgramFiles%\drweb\<File name>.vbs
- %ProgramFiles%\drweb32w\<File name>.vbs
- %ProgramFiles%\drweb386\<File name>.vbs
- %ProgramFiles%\etherd\<File name>.vbs
- %ProgramFiles%\drwebscd\<File name>.vbs
- %ProgramFiles%\drwebwcl\<File name>.vbs
- %ProgramFiles%\drwreg\<File name>.vbs
- %ProgramFiles%\dvd maker\<File name>.vbs
- %ProgramFiles%\ecmd\<File name>.vbs
- %ProgramFiles%\egni\<File name>.vbs
- %ProgramFiles%\ehsniffer\<File name>.vbs
- %ProgramFiles%\ekrn\<File name>.vbs
- %ProgramFiles%\elementclient\<File name>.vbs
- %ProgramFiles%\dislite\<File name>.vbs
- %ProgramFiles%\dnf\<File name>.vbs
- %ProgramFiles%\directftp\<File name>.vbs
- %ProgramFiles%\digsby-app\<File name>.vbs
- %ProgramFiles%\digsby\<File name>.vbs
- %ProgramFiles%\cleaner3\<File name>.vbs
- %ProgramFiles%\clisvc\<File name>.vbs
- %ProgramFiles%\clrcche\<File name>.vbs
- %ProgramFiles%\cmain\<File name>.vbs
- %ProgramFiles%\cmgrdian\<File name>.vbs
- %CommonProgramFiles%\<File name>.vbs
- %ProgramFiles%\copyx64\<File name>.vbs
- %ProgramFiles%\courier\<File name>.vbs
- %ProgramFiles%\b2\<File name>.vbs
- %ProgramFiles%\csendto\<File name>.vbs
- %ProgramFiles%\cpd\<File name>.vbs
- %ProgramFiles%\custinstall\<File name>.vbs
- %ProgramFiles%\custsetup\<File name>.vbs
- %ProgramFiles%\cuteftp\<File name>.vbs
- %ProgramFiles%\dbconvert\<File name>.vbs
- %ProgramFiles%\dbtool\<File name>.vbs
- %ProgramFiles%\defensewall\<File name>.vbs
- %ProgramFiles%\defwatch\<File name>.vbs
- %ProgramFiles%\dekaron\<File name>.vbs
- %ProgramFiles%\cleaner\<File name>.vbs
- %ProgramFiles%\cssexc\<File name>.vbs
- %ProgramFiles%\drwebupw\<File name>.vbs
- %ProgramFiles%\avsynmgr\<File name>.vbs
- %ProgramFiles%\avgvv\<File name>.vbs
- %ProgramFiles%\agb5\<File name>.vbs
- %ProgramFiles%\ageofconan\<File name>.vbs
- %ProgramFiles%\ahnsd\<File name>.vbs
- %ProgramFiles%\aim6\<File name>.vbs
- %ProgramFiles%\aimpro\<File name>.vbs
- %ProgramFiles%\airdefense\<File name>.vbs
- %ProgramFiles%\almon\<File name>.vbs
- %ProgramFiles%\alsvc\<File name>.vbs
- %ProgramFiles%\amon\<File name>.vbs
- %ProgramFiles%\amsn\<File name>.vbs
- %ProgramFiles%\anti-trojan\<File name>.vbs
- %ProgramFiles%\antivirus\<File name>.vbs
- %ProgramFiles%\aoltbserver\<File name>.vbs
- %ProgramFiles%\armor2net\<File name>.vbs
- %ProgramFiles%\armorsurf\<File name>.vbs
- %ProgramFiles%\ash\<File name>.vbs
- %ProgramFiles%\ashavast\<File name>.vbs
- %ProgramFiles%\ashavsrv\<File name>.vbs
- %ProgramFiles%\ashchest\<File name>.vbs
- %ProgramFiles%\admunch\<File name>.vbs
- %ProgramFiles%\ashdisp\<File name>.vbs
- %ProgramFiles%\ackwin32\<File name>.vbs
- %ProgramFiles%\aavshield\<File name>.vbs
- <Drive name for removable media>:\autorun.inf
- C:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\<File name>.vbs
- C:\far2\addons\<File name>.vbs
- C:\far2\documentation\<File name>.vbs
- C:\far2\encyclopedia\<File name>.vbs
- C:\far2\fexcept\<File name>.vbs
- C:\far2\plugins\<File name>.vbs
- C:\far2\pluginsdk\<File name>.vbs
- C:\msocache\all users\<File name>.vbs
- C:\perflogs\admin\<File name>.vbs
- %ProgramFiles%\360tray\<File name>.vbs
- %ProgramFiles%\a2cmd\<File name>.vbs
- %ProgramFiles%\a2guard\<File name>.vbs
- %ProgramFiles%\a2hijackfree\<File name>.vbs
- %ProgramFiles%\a2scan\<File name>.vbs
- %ProgramFiles%\a2service\<File name>.vbs
- %ProgramFiles%\a2start\<File name>.vbs
- %ProgramFiles%\a2upd\<File name>.vbs
- %ProgramFiles%\a2wizard\<File name>.vbs
- %ProgramFiles%\about\<File name>.vbs
- %ProgramFiles%\ashdug\<File name>.vbs
- %ProgramFiles%\ashenhcd\<File name>.vbs
- %ProgramFiles%\ashlogv\<File name>.vbs
- %ProgramFiles%\avgemc\<File name>.vbs
- %ProgramFiles%\avgfwsrv\<File name>.vbs
- %ProgramFiles%\avginet\<File name>.vbs
- %ProgramFiles%\avgnpdln\<File name>.vbs
- %ProgramFiles%\avgnpsvc\<File name>.vbs
- %ProgramFiles%\avgrssvc\<File name>.vbs
- %ProgramFiles%\avgscan\<File name>.vbs
- %ProgramFiles%\avgupden\<File name>.vbs
- %ProgramFiles%\avpm\<File name>.vbs
- %ProgramFiles%\avgupsvc\<File name>.vbs
- %ProgramFiles%\avgw\<File name>.vbs
- %ProgramFiles%\avgwizfw\<File name>.vbs
- %ProgramFiles%\avinitnt\<File name>.vbs
- %ProgramFiles%\avkserv\<File name>.vbs
- %ProgramFiles%\avkservice\<File name>.vbs
- %ProgramFiles%\avkwctl\<File name>.vbs
- %ProgramFiles%\avnotify\<File name>.vbs
- %ProgramFiles%\avpcc\<File name>.vbs
- %ProgramFiles%\avgcc\<File name>.vbs
- %ProgramFiles%\avgdiag\<File name>.vbs
- %ProgramFiles%\avgamsvr\<File name>.vbs
- %ProgramFiles%\avconsol\<File name>.vbs
- %ProgramFiles%\avconfig\<File name>.vbs
- %ProgramFiles%\ashpopwz\<File name>.vbs
- %ProgramFiles%\ashquick\<File name>.vbs
- %ProgramFiles%\ashserv\<File name>.vbs
- %ProgramFiles%\ashsimp2\<File name>.vbs
- %ProgramFiles%\ashsimpl\<File name>.vbs
- %ProgramFiles%\ashskpcc\<File name>.vbs
- %ProgramFiles%\ashskpck\<File name>.vbs
- %ProgramFiles%\ashupd\<File name>.vbs
- %ProgramFiles%\avscan\<File name>.vbs
- %ProgramFiles%\ash_updatemediator\<File name>.vbs
- %ProgramFiles%\ashwebsv\<File name>.vbs
- %ProgramFiles%\aswupdsv\<File name>.vbs
- %ProgramFiles%\autodown\<File name>.vbs
- %ProgramFiles%\autostartexplorer\<File name>.vbs
- %ProgramFiles%\autotrace\<File name>.vbs
- %ProgramFiles%\avadmin\<File name>.vbs
- %ProgramFiles%\avcenter\<File name>.vbs
- %ProgramFiles%\avciman\<File name>.vbs
- %ProgramFiles%\avcmd\<File name>.vbs
- %ProgramFiles%\ashmaisv\<File name>.vbs
- %ProgramFiles%\aswregsvr\<File name>.vbs
- %ProgramFiles%\eudora\<File name>.vbs
- %ProgramFiles%\ewidoctrl\<File name>.vbs
- %ProgramFiles%\exit_av\<File name>.vbs
- %ProgramFiles%\issvc\<File name>.vbs
- %ProgramFiles%\isuac\<File name>.vbs
- %ProgramFiles%\itunes\<File name>.vbs
- %ProgramFiles%\java\<File name>.vbs
- %ProgramFiles%\k-meleon\<File name>.vbs
- %ProgramFiles%\kav\<File name>.vbs
- %ProgramFiles%\kavmm\<File name>.vbs
- %ProgramFiles%\kavpf\<File name>.vbs
- %ProgramFiles%\lucallbackproxy\<File name>.vbs
- %ProgramFiles%\kavpfw\<File name>.vbs
- %ProgramFiles%\kavsvc\<File name>.vbs
- %ProgramFiles%\konnekt\<File name>.vbs
- %ProgramFiles%\launcher\<File name>.vbs
- %ProgramFiles%\licmgr\<File name>.vbs
- %ProgramFiles%\livesrv\<File name>.vbs
- %ProgramFiles%\liveupdate\<File name>.vbs
- %ProgramFiles%\logwatnt\<File name>.vbs
- %ProgramFiles%\lotroclient\<File name>.vbs
- %ProgramFiles%\ispnews\<File name>.vbs
- %ProgramFiles%\ispwdsvc\<File name>.vbs
- %ProgramFiles%\kavstart\<File name>.vbs
- %ProgramFiles%\lpfw\<File name>.vbs
- %ProgramFiles%\iris\<File name>.vbs
- %ProgramFiles%\ih8run\<File name>.vbs
- %ProgramFiles%\ilaunchr\<File name>.vbs
- %ProgramFiles%\imapp\<File name>.vbs
- %ProgramFiles%\imnotfy\<File name>.vbs
- %ProgramFiles%\impcnt\<File name>.vbs
- %ProgramFiles%\incmail\<File name>.vbs
- %ProgramFiles%\inocit\<File name>.vbs
- %ProgramFiles%\inorpc\<File name>.vbs
- %ProgramFiles%\inort\<File name>.vbs
- %ProgramFiles%\inotask\<File name>.vbs
- %ProgramFiles%\inouptng\<File name>.vbs
- %ProgramFiles%\inphasenxd\<File name>.vbs
- %ProgramFiles%\installcavs\<File name>.vbs
- %ProgramFiles%\installlicense\<File name>.vbs
- %ProgramFiles%\installlsp\<File name>.vbs
- %ProgramFiles%\instlsp\<File name>.vbs
- %ProgramFiles%\internet explorer\<File name>.vbs
- %ProgramFiles%\iron\<File name>.vbs
- %ProgramFiles%\iexplore\<File name>.vbs
- %ProgramFiles%\isafe\<File name>.vbs
- %ProgramFiles%\navw32\<File name>.vbs
- %ProgramFiles%\lucheck\<File name>.vbs
- %ProgramFiles%\mp3theater\<File name>.vbs
- %ProgramFiles%\mp3toystray\<File name>.vbs
- %ProgramFiles%\mp3tray\<File name>.vbs
- %ProgramFiles%\mpeng\<File name>.vbs
- %ProgramFiles%\mpftray\<File name>.vbs
- %ProgramFiles%\mpssvc\<File name>.vbs
- %ProgramFiles%\msbuild\<File name>.vbs
- %ProgramFiles%\msimn\<File name>.vbs
- %ProgramFiles%\msmpsvc\<File name>.vbs
- %ProgramFiles%\luconfig\<File name>.vbs
- %ProgramFiles%\msn6\<File name>.vbs
- %ProgramFiles%\mva\<File name>.vbs
- %ProgramFiles%\mvc\<File name>.vbs
- %ProgramFiles%\myagtsvc\<File name>.vbs
- %ProgramFiles%\myagttry\<File name>.vbs
- %ProgramFiles%\navapsvc\<File name>.vbs
- %ProgramFiles%\navlu32\<File name>.vbs
- %ProgramFiles%\navstub\<File name>.vbs
- %ProgramFiles%\monsysnt\<File name>.vbs
- %ProgramFiles%\monlite\<File name>.vbs
- %ProgramFiles%\mp3toys\<File name>.vbs
- %ProgramFiles%\miro\<File name>.vbs
- %ProgramFiles%\miranda32\<File name>.vbs
- %ProgramFiles%\luinit\<File name>.vbs
- %ProgramFiles%\luupdate\<File name>.vbs
- %ProgramFiles%\magent\<File name>.vbs
- %ProgramFiles%\malwareremoval\<File name>.vbs
- %ProgramFiles%\maplestory\<File name>.vbs
- %ProgramFiles%\maxthon\<File name>.vbs
- %ProgramFiles%\mcmnhdlr\<File name>.vbs
- %ProgramFiles%\mcregwiz\<File name>.vbs
- %ProgramFiles%\ieuser\<File name>.vbs
- %ProgramFiles%\mcshield\<File name>.vbs
- %ProgramFiles%\ih8\<File name>.vbs
- %ProgramFiles%\mcvsshld\<File name>.vbs
- %ProgramFiles%\mfpmp\<File name>.vbs
- %ProgramFiles%\microsoft analysis services\<File name>.vbs
- %ProgramFiles%\microsoft office\<File name>.vbs
- %ProgramFiles%\microsoft sql server compact edition\<File name>.vbs
- %ProgramFiles%\microsoft sync framework\<File name>.vbs
- %ProgramFiles%\microsoft synchronization services\<File name>.vbs
- %ProgramFiles%\mir3game\<File name>.vbs
- %ProgramFiles%\mcupdmgr\<File name>.vbs
- %ProgramFiles%\luna\<File name>.vbs
- %ProgramFiles%\memstring\<File name>.vbs
- %ProgramFiles%\ieregfix\<File name>.vbs
- %ProgramFiles%\icqlite\<File name>.vbs
- %ProgramFiles%\icq\<File name>.vbs
- %ProgramFiles%\fsav\<File name>.vbs
- %ProgramFiles%\fsav32\<File name>.vbs
- %ProgramFiles%\fsavaui\<File name>.vbs
- %ProgramFiles%\fsavgui\<File name>.vbs
- %ProgramFiles%\fsavstrt\<File name>.vbs
- %ProgramFiles%\fsavwsch\<File name>.vbs
- %ProgramFiles%\fsavwscr\<File name>.vbs
- %ProgramFiles%\fsbwsys\<File name>.vbs
- %ProgramFiles%\fsdbuh\<File name>.vbs
- %ProgramFiles%\fsdc\<File name>.vbs
- %ProgramFiles%\fsdfwd\<File name>.vbs
- %ProgramFiles%\fsdiag\<File name>.vbs
- %ProgramFiles%\fsdiagui\<File name>.vbs
- %ProgramFiles%\fsfwwsch\<File name>.vbs
- %ProgramFiles%\fsfwwscr\<File name>.vbs
- %ProgramFiles%\fsgetwab\<File name>.vbs
- %ProgramFiles%\fsgk32\<File name>.vbs
- %ProgramFiles%\fsample\<File name>.vbs
- %ProgramFiles%\fpwin\<File name>.vbs
- %ProgramFiles%\fsauach\<File name>.vbs
- %ProgramFiles%\freshclam\<File name>.vbs
- %ProgramFiles%\fptrayproc\<File name>.vbs
- %ProgramFiles%\firesvc\<File name>.vbs
- %ProgramFiles%\f-sched\<File name>.vbs
- %ProgramFiles%\fameh32\<File name>.vbs
- %ProgramFiles%\far\<File name>.vbs
- %ProgramFiles%\fch32\<File name>.vbs
- %ProgramFiles%\fdm\<File name>.vbs
- %ProgramFiles%\fdmwi\<File name>.vbs
- %ProgramFiles%\filezilla\<File name>.vbs
- %ProgramFiles%\firebird\<File name>.vbs
- %ProgramFiles%\fsgk32st\<File name>.vbs
- %ProgramFiles%\navwnt\<File name>.vbs
- %ProgramFiles%\firefox\<File name>.vbs
- %ProgramFiles%\flashfxp\<File name>.vbs
- %ProgramFiles%\flashgot\<File name>.vbs
- %ProgramFiles%\flock\<File name>.vbs
- %ProgramFiles%\foxit\<File name>.vbs
- %ProgramFiles%\fpavserver\<File name>.vbs
- %ProgramFiles%\fpavupdm\<File name>.vbs
- %ProgramFiles%\fprottray\<File name>.vbs
- %ProgramFiles%\fpscan\<File name>.vbs
- %ProgramFiles%\ezantivirusregistrationcheck\<File name>.vbs
- %ProgramFiles%\firetray\<File name>.vbs
- %ProgramFiles%\fsqh\<File name>.vbs
- %ProgramFiles%\fsguidll\<File name>.vbs
- %ProgramFiles%\fshotfix\<File name>.vbs
- %ProgramFiles%\giantantispywareupdater\<File name>.vbs
- %ProgramFiles%\gnotify\<File name>.vbs
- %ProgramFiles%\googledesktop\<File name>.vbs
- %ProgramFiles%\googletalk\<File name>.vbs
- %ProgramFiles%\googleupdate\<File name>.vbs
- %ProgramFiles%\guardgni\<File name>.vbs
- %ProgramFiles%\guardnt\<File name>.vbs
- %ProgramFiles%\fsaua\<File name>.vbs
- %ProgramFiles%\gw\<File name>.vbs
- %ProgramFiles%\helper\<File name>.vbs
- %ProgramFiles%\hipsdiag\<File name>.vbs
- %ProgramFiles%\hregmon\<File name>.vbs
- %ProgramFiles%\hrres\<File name>.vbs
- %ProgramFiles%\hsockpe\<File name>.vbs
- %ProgramFiles%\httplook\<File name>.vbs
- %ProgramFiles%\iamapp\<File name>.vbs
- %ProgramFiles%\iamserv\<File name>.vbs
- %ProgramFiles%\ge\<File name>.vbs
- %ProgramFiles%\helpctr\<File name>.vbs
- %ProgramFiles%\giantantispywaremain\<File name>.vbs
- %ProgramFiles%\gg\<File name>.vbs
- %ProgramFiles%\gcasserv\<File name>.vbs
- %ProgramFiles%\gcasdtserv\<File name>.vbs
- %ProgramFiles%\fsihcomp\<File name>.vbs
- %ProgramFiles%\fsihs\<File name>.vbs
- %ProgramFiles%\fslaunch\<File name>.vbs
- %ProgramFiles%\fsm32\<File name>.vbs
- %ProgramFiles%\fsma32\<File name>.vbs
- %ProgramFiles%\fsmb32\<File name>.vbs
- %ProgramFiles%\fspc\<File name>.vbs
- %ProgramFiles%\fsguiexe\<File name>.vbs
- %ProgramFiles%\fspex\<File name>.vbs
- %ProgramFiles%\fshdll32\<File name>.vbs
- %ProgramFiles%\fssf\<File name>.vbs
- %ProgramFiles%\fssm32\<File name>.vbs
- %ProgramFiles%\fsstm\<File name>.vbs
- %ProgramFiles%\fssw\<File name>.vbs
- %ProgramFiles%\fstlui\<File name>.vbs
- %ProgramFiles%\fsuninst\<File name>.vbs
- %ProgramFiles%\fsus\<File name>.vbs
- %ProgramFiles%\ftpte\<File name>.vbs
- %ProgramFiles%\fshelp\<File name>.vbs
- %ProgramFiles%\gc\<File name>.vbs
- %ProgramFiles%\fssg\<File name>.vbs
- D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\<File name>.vbs