Threat Database Worms Malware.Rahack

Malware.Rahack

Malware.Rahack is a harmful worm. Once Malware.Rahack is inside a PC, it will scan the network for vulnerable computer systems that are running Radmin remote administration tool, and then it will infect them. Malware.Rahack gives unauthorized users access and control over an infected PC. Malware.Rahack is also known to infect HTML files and create a start-up registry entry.

Aliases

6 security vendors flagged this file as malicious.

Anti-Virus Software Detection
- Win32/Allaple.worm.B
- Worm:Win32/Allaple.A
- W32/Allaple-F
- WORM_ALLAPLE.IK
- W32/RAHack
- Net-Worm.Win32.Allaple.a

File System Details

Malware.Rahack may create the following file(s):
# File Name Detections
1. %ProgramFiles%\NetMeeting\rsewzjqn.exe
2. %Windir%\pchealth\helpctr\System\CompatCtr\jbnxjtkn.exe
3. %Windir%\pchealth\helpctr\System\DVDUpgrd\shrrtjet.exe
4. %Windir%\pchealth\helpctr\System\NetDiag\hsjqschn.exe
5. %Windir%\pchealth\helpctr\System\panels\sncncweb.exe
6. %ProgramFiles%\Common Files\System\ado\tsektjkj.exe
7. %Windir%\pchealth\helpctr\System\CompatCtr\hrtbebze.exe
8. %Windir%\pchealth\helpctr\System\CompatCtr\zlhqrlbx.exe
9. %Windir%\pchealth\helpctr\System\errors\jcjjlqnq.exe
10. %Windir%\pchealth\helpctr\System\panels\nntlskwn.exe
11. c:\Inetpub\wwwroot\kkvwbsrw.exe
12. c:\tvsknrse.exe
13. %Windir%\pchealth\helpctr\System\CompatCtr\tnslrrhk.exe
14. %Windir%\pchealth\helpctr\System\ErrMsg\vlvxqrek.exe
15. %Windir%\pchealth\helpctr\System\NetDiag\xrvxszvs.exe
16. %Windir%\pchealth\helpctr\System\rc\qbrblthb.exe

Registry Details

Malware.Rahack may create the following registry entry or registry entries:
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01E9E265-66BE-04A9-BADD-A06BE2E36897}]
(Default) = "%ProgramFiles%\Adobe\Acrobat 6.0\Reader\HowTo\ENU\rvwwbqje.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{048BF78C-E618-0789-65EC-7B42EEBABDDC}\LocalServer32]
(Default) = "stbettewjejlbbhe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A0F1486-35D6-89D7-D882-CA1A59862B6E}]
(Default) = "%Windir%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\kkrtrbns.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B6FF80D-5D50-5935-4BAD-4C4C5294B2E1}\LocalServer32]
(Default) = "jnntqkhhnesweehb"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0BD9D438-2B62-1078-724B-E27EBD7F7A8F}]
(Default) = "%ProgramFiles%\Adobe\Acrobat 6.0\Reader\HowTo\ENU\xjshnvvh.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{110F9774-FAAC-0A3E-8A58-182D5A948013}\LocalServer32]
(Default) = "sjbltkesnsrhqhjh"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{118AD934-6512-CF10-DF50-2B2755D07C2F}]
(Default) = "%Windir%\pchealth\helpctr\System\UpdateCtr\rrbvcsbb.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{171FA199-C05B-5BF3-69B2-7E67EA910DA5}\LocalServer32]
(Default) = "sxxetlhlkvjvhtek"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1BB5D22A-38E3-3CDD-6FC2-017E4B687843}]
(Default) = "%ProgramFiles%\Adobe\Acrobat 6.0\Reader\HowTo\ENU\zxtlktls.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2373A33D-199F-43E5-6694-07C4E1CFE31C}\LocalServer32]
(Default) = "bvjsejrslhkhesjn"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2DC54B40-2536-69E8-382F-178E0D784F47}]
(Default) = "%Windir%\pchealth\helpctr\System\sysinfo\rbcjjwqr.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{346436FA-5138-50DA-D412-0870CE39768B}\LocalServer32]
(Default) = "vjhzscrvrztlrjwc"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{363304E6-ADDF-9355-8F4C-D71315751C40}]
(Default) = "%ProgramFiles%\Adobe\Acrobat 6.0\Reader\HowTo\ENU\jcjcvqtr.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{37128C75-4B63-71FC-DD33-D9492FBB2EFB}\LocalServer32]
(Default) = "ncrwhhsjtnzlnkbn"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3A4B53AC-423A-E7CA-C4DA-B78A959F8C03}]
(Default) = "%Windir%\pchealth\helpctr\System\CompatCtr\tnslrrhk.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C1D709C-0F4D-5DA4-2232-7AFD13C0C23F}\LocalServer32]
(Default) = "ztjxlkwbbknqjlbn"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4222E084-9879-6354-96E0-20C15ACDC125}]
(Default) = "%ProgramFiles%\Adobe\Acrobat 6.0\Reader\HowTo\ENU\tjqlrkhx.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{46FFC275-F95A-DD9C-490B-4A7903F8E16C}\LocalServer32]
(Default) = "nevxqrjesnsjbbkt"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{490CDDA9-7D56-3D09-CC3C-5136306CC8A0}]
(Default) = "%ProgramFiles%\Adobe\Acrobat 6.0\Reader\plug_ins\PictureTasks\Howto\tbzrsrxv.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4C80FDD5-398A-C978-C78B-16A1293DD4DE}\LocalServer32]
(Default) = "tshjnkznwbnbntrk"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E4B1243-6951-DA75-041E-CEB3D83811A0}]
(Default) = "%Windir%\pchealth\helpctr\System\UpdateCtr\trkhkjxz.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50DF717F-2804-A197-85E1-B236DAE4BB1F}\LocalServer32]
(Default) = "klsqhhktbjnbkrrq"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{52B27C6B-4485-B5DC-7ACC-40C9603EF49C}]
(Default) = [pathname with a string SHARE]\bhrhnkht.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{56F8EF1A-30C4-77DB-B4A1-F7FB92D83438}\LocalServer32]
(Default) = "jsrqkwqeetjtswbr"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B974BBE-61BD-D89A-783C-6F06BBE18E40}]
(Default) = "%Windir%\pchealth\helpctr\System\Remote Assistance\wesnhzec.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{61CA20C2-A0DD-6AB8-4CA0-BCB8C40945FC}\LocalServer32]
(Default) = "xbeellhvjkvvwevb"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{643D6D97-3E52-70FB-581D-BC9391FA03A1}]
(Default) = [pathname with a string SHARE]\bcwvzwbh.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64F1CF06-0CDB-2C1E-9F31-AB06848B06CA}\LocalServer32]
(Default) = "lsqhsrnzjkjtsxhe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{68B4E7F8-6512-EF00-DF46-2E62C2F0A63F}]
(Default) = "%ProgramFiles%\adobe\acrobat 6.0\reader\howto\enu\elrkexns.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72737CBC-9B11-C3AC-D03C-37102C5BD6F9}\LocalServer32]
(Default) = "scrbxhnztkcznevk"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{76126225-3758-4FE5-19E1-0942B74619EF}]
(Default) = "%ProgramFiles%\adobe\acrobat 6.0\reader\elbkcznj.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{79910627-6A00-CDCE-579B-2C3D5BA84B34}\LocalServer32]
(Default) = "kkzlknrqjhkehtzh"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7D2E936C-285C-5A66-3FE8-B76B480783C6}]
(Default) = "%Windir%\pchealth\helpctr\System\sysinfo\vkchbbxh.exe"
(Default) = "%ProgramFiles%\Adobe\Acrobat 6.0\Reader\HowTo\ENU\qkezbwtr.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03276388-B4D4-8F3B-502B-0901696414AA}\LocalServer32]
(Default) = "bbnelsllxevtneqn"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{048BF78C-E618-0789-65EC-7B42EEBABDDC}]
(Default) = "%Windir%\pchealth\helpctr\System\CompatCtr\jbnxjtkn.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B44EB36-CB81-9FE3-EB6F-ED253BC824C5}\LocalServer32]
(Default) = "ktrhshhljntbbtxr"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B6FF80D-5D50-5935-4BAD-4C4C5294B2E1}]
(Default) = [pathname with a string SHARE]\czjevcet.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F550331-2ECD-706B-E9A8-48721438E36F}\LocalServer32]
(Default) = "rteblnqklbhrttnl"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{110F9774-FAAC-0A3E-8A58-182D5A948013}]
(Default) = "%Windir%\pchealth\helpctr\System\sysinfo\cntbrbzr.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1329366B-3CA3-C056-4832-FDA8BAC1351F}\LocalServer32]
(Default) = "whsvzbrhetvshlsk"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{171FA199-C05B-5BF3-69B2-7E67EA910DA5}]
(Default) = "%ProgramFiles%\NetMeeting\rsewzjqn.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{22FAED41-A1FA-DC51-2326-669AA778CE49}\LocalServer32]
(Default) = "wbnkwecbltjjkvvk"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2373A33D-199F-43E5-6694-07C4E1CFE31C}]
(Default) = "C:\Inetpub\wwwroot\kkvwbsrw.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{326CE86B-F468-EA85-5628-FD4D0FFDBB85}\LocalServer32]
(Default) = "rhskvbleetwbnklh"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{346436FA-5138-50DA-D412-0870CE39768B}]
(Default) = "%Windir%\pchealth\helpctr\Vendors\CN=Microsoft Corporation,L=Redmond,S=Washington,C=US\Remote Assistance\vxwqhwzs.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{36A4D260-82A5-40A1-1185-87B6D34F389A}\LocalServer32]
(Default) = "bwhqnvbbrsqrqwek"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{37128C75-4B63-71FC-DD33-D9492FBB2EFB}]
(Default) = "%Windir%\pchealth\helpctr\System\Remote Assistance\Interaction\Server\ccthwjlr.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3AE1D8CD-A6F7-40FE-B888-56FCBA8BCA46}\LocalServer32]
(Default) = "kllnkjslevjhlbck"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3C1D709C-0F4D-5DA4-2232-7AFD13C0C23F}]
(Default) = [pathname with a string SHARE]\qjllsjhl.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{445FAB9E-1031-CFBE-81C7-7F3ABEF2B143}\LocalServer32]
(Default) = "nkrjctbrxkhkbetj"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{46FFC275-F95A-DD9C-490B-4A7903F8E16C}]
(Default) = "%Windir%\pchealth\helpctr\System\CompatCtr\hrtbebze.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{496EDDD0-77F0-D9A4-9F5D-DD23EC9698F2}\LocalServer32]
(Default) = "vwxslqslkcleljes"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4C80FDD5-398A-C978-C78B-16A1293DD4DE}]
(Default) = "%ProgramFiles%\Microsoft Visual Studio\nxhtnbrt.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F82FDE5-2426-891D-5E88-22E06725D2A6}\LocalServer32]
(Default) = "llhbnhsjlxvljtcn"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{50DF717F-2804-A197-85E1-B236DAE4BB1F}]
(Default) = "%ProgramFiles%\Microsoft Visual Studio\srzectxw.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{541C14FC-A3AA-C18E-DBF1-600A7FA7940B}\LocalServer32]
(Default) = "jjeslvrnlevwzhkj"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{56F8EF1A-30C4-77DB-B4A1-F7FB92D83438}]
(Default) = "%Windir%\pchealth\helpctr\System\UpdateCtr\lwklbvze.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{616F8160-B381-7FEA-D13A-58E0EF4C12E8}\LocalServer32]
(Default) = "srjkshstsxkqrxck"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{61CA20C2-A0DD-6AB8-4CA0-BCB8C40945FC}]
(Default) = "%ProgramFiles%\Adobe\Acrobat 6.0\Reader\HowTo\ENU\nxxhexkh.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6455A07B-5629-2D89-9412-B3A2DD705BDE}\LocalServer32]
(Default) = "ksjnwrtrhnrhsqnz"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64F1CF06-0CDB-2C1E-9F31-AB06848B06CA}]
(Default) = "%Windir%\pchealth\helpctr\System\panels\nntlskwn.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6B999886-BE16-4EAA-FC21-EC8583C15B00}\LocalServer32]
(Default) = "jkjxwhzlqrejjktz"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72737CBC-9B11-C3AC-D03C-37102C5BD6F9}]
(Default) = [pathname with a string SHARE]\bnbtzwxt.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{78EF8F66-B7A9-1D01-86F9-8BEC6B7E14B1}\LocalServer32]
(Default) = "slkxwtbvsehekqkr"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{79910627-6A00-CDCE-579B-2C3D5BA84B34}]
(Default) = [pathname with a string SHARE]\xrljqjzn.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7D2FAF53-4ADD-C43A-4E61-1B61075FC924}\LocalServer32]
(Default) = "eevseekrvrlwclhw"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01E9E265-66BE-04A9-BADD-A06BE2E36897}\LocalServer32]
(Default) = "rterljnsqklvcvve"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03276388-B4D4-8F3B-502B-0901696414AA}]
(Default) = "%Windir%\pchealth\helpctr\System\sysinfo\jrtqcssx.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A0F1486-35D6-89D7-D882-CA1A59862B6E}\LocalServer32]
(Default) = "sckebqktxvzwceks"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B44EB36-CB81-9FE3-EB6F-ED253BC824C5}]
(Default) = "%ProgramFiles%\adobe\acrobat 6.0\reader\howto\enu\cwelqkks.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0BD9D438-2B62-1078-724B-E27EBD7F7A8F}\LocalServer32]
(Default) = "hnklernqqsrjtrhv"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F550331-2ECD-706B-E9A8-48721438E36F}]
(Default) = "%Windir%\pchealth\helpctr\System\sysinfo\bjlkjrls.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{118AD934-6512-CF10-DF50-2B2755D07C2F}\LocalServer32]
(Default) = "bnjekwhnnzknhqrl"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1329366B-3CA3-C056-4832-FDA8BAC1351F}]
(Default) = "%ProgramFiles%\Adobe\Acrobat 6.0\Reader\HowTo\ENU\jhtkcrqk.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1BB5D22A-38E3-3CDD-6FC2-017E4B687843}\LocalServer32]
(Default) = "knhclhklkjbrhjwb"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{22FAED41-A1FA-DC51-2326-669AA778CE49}]
(Default) = "%ProgramFiles%\Microsoft Visual Studio\jehkxqtn.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2DC54B40-2536-69E8-382F-178E0D784F47}\LocalServer32]
(Default) = "nsbtrqthwsskkseb"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{326CE86B-F468-EA85-5628-FD4D0FFDBB85}]
(Default) = "[file and pathname of the sample #1]"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{363304E6-ADDF-9355-8F4C-D71315751C40}\LocalServer32]
(Default) = "qbrrxsbjlzrzwrhh"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{36A4D260-82A5-40A1-1185-87B6D34F389A}]
(Default) = "%Windir%\pchealth\helpctr\System\Remote Assistance\Interaction\Client\wbjbjelb.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3A4B53AC-423A-E7CA-C4DA-B78A959F8C03}\LocalServer32]
(Default) = "klbknzxxrbjjxkwt"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3AE1D8CD-A6F7-40FE-B888-56FCBA8BCA46}]
(Default) = "%Windir%\pchealth\helpctr\System\Remote Assistance\Interaction\Client\ttzvrbzr.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4222E084-9879-6354-96E0-20C15ACDC125}\LocalServer32]
(Default) = "lxetcqvrwjvntcce"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{445FAB9E-1031-CFBE-81C7-7F3ABEF2B143}]
(Default) = "%ProgramFiles%\Microsoft Visual Studio\ehlbrqvs.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{490CDDA9-7D56-3D09-CC3C-5136306CC8A0}\LocalServer32]
(Default) = "bbkwnjxxsehllcnl"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{496EDDD0-77F0-D9A4-9F5D-DD23EC9698F2}]
(Default) = "%ProgramFiles%\Common Files\System\ado\tsektjkj.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E4B1243-6951-DA75-041E-CEB3D83811A0}\LocalServer32]
(Default) = "ljetlzreshsbzwse"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4F82FDE5-2426-891D-5E88-22E06725D2A6}]
(Default) = "C:\tvsknrse.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{52B27C6B-4485-B5DC-7ACC-40C9603EF49C}\LocalServer32]
(Default) = "tnkwkqrwqbrjcsck"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{541C14FC-A3AA-C18E-DBF1-600A7FA7940B}]
(Default) = "%Windir%\pchealth\helpctr\System\ErrMsg\vlvxqrek.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5B974BBE-61BD-D89A-783C-6F06BBE18E40}\LocalServer32]
(Default) = "kvlkelxrjbwcbhql"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{616F8160-B381-7FEA-D13A-58E0EF4C12E8}]
(Default) = "%ProgramFiles%\Adobe\Acrobat 6.0\Reader\HowTo\ENU\ktensxxh.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{643D6D97-3E52-70FB-581D-BC9391FA03A1}\LocalServer32]
(Default) = "bzetejslnlblezbe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6455A07B-5629-2D89-9412-B3A2DD705BDE}]
(Default) = "%ProgramFiles%\Microsoft Visual Studio\snrlrkcn.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{68B4E7F8-6512-EF00-DF46-2E62C2F0A63F}\LocalServer32]
(Default) = "jsqnbwktrtseqtbb"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6B999886-BE16-4EAA-FC21-EC8583C15B00}]
(Default) = "%ProgramFiles%\Adobe\Acrobat 6.0\Reader\HowTo\ENU\jclbnjhk.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{76126225-3758-4FE5-19E1-0942B74619EF}\LocalServer32]
(Default) = "ntllhesrswxcjkzl"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{78EF8F66-B7A9-1D01-86F9-8BEC6B7E14B1}]
(Default) = "%Windir%\pchealth\helpctr\System\Remote Assistance\Common\seshhtth.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7D2E936C-285C-5A66-3FE8-B76B480783C6}\LocalServer32]
(Default) = "xhellbvwlkzjwenc"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7D2FAF53-4ADD-C43A-4E61-1B61075FC924}]

Related Posts

Trending

Most Viewed

Loading...