Windows Registry Editor Version 5.00 [-HKEY_CURRENT_USER\Software\Acronis] [HKEY_CURRENT_USER\Software\BillP Studios\Detected\Services] "C:\\PROGRAM FILES\\COMODO\\COMODO GEEKBUDDY\\CLPSLS.exe"=- "C:\\PROGRAM FILES\\COMODO\\COMODO INTERNET SECURITY\\cmdagent.exe"=- "C:\\PROGRAM FILES (X86)\\Comodo\\Dragon\\DRAGON_UPDATER.EXE"=- [HKEY_CURRENT_USER\Software\BillP Studios\Detected\Startup] "C:\\Program Files (x86)\\Acronis\\TrueImageHome\\TrueImageMonitor.exe"=- "C:\\Program Files (x86)\\Common Files\\Acronis\\Schedule2\\schedhlp.exe"=- "C:\\PROGRAM FILES\\COMODO\\COMODO INTERNET SECURITY\\CFP.EXE"=- "C:\\PROGRAM FILES (X86)\\COMMON FILES\\ACRONIS\\TRUEIMAGEHOME\\TDRPAPI.DLL"=- "C:\\Program Files (x86)\\Acronis\\TrueImageHome\\OnlineBackupStandalone\\TrueImageMonitor.exe"=- [HKEY_CURRENT_USER\Software\BillP Studios\WinPatrol\ActiveRun] "C:\\PROGRAM FILES (X86)\\COMMON FILES\\ACRONIS\\SCHEDULE2\\SCHEDHLP.EXE"=- "C:\\PROGRAM FILES\\COMODO\\COMODO INTERNET SECURITY\\CFP.EXE"=- "C:\\PROGRAM FILES (X86)\\ACRONIS\\TRUEIMAGEHOME\\ONLINEBACKUPSTANDALONE\\TRUEIMAGEMONITOR.EXE"=- "C:\\PROGRAM FILES (X86)\\ACRONIS\\TRUEIMAGEHOME\\TRUEIMAGEMONITOR.EXE"=- [HKEY_CURRENT_USER\Software\BillP Studios\WinPatrol\ActiveRun] "C:\\PROGRAM FILES (X86)\\COMMON FILES\\ACRONIS\\SCHEDULE2\\SCHEDHLP.EXE"=- "C:\\PROGRAM FILES\\COMODO\\COMODO INTERNET SECURITY\\CFP.EXE"=- "C:\\PROGRAM FILES (X86)\\ACRONIS\\TRUEIMAGEHOME\\ONLINEBACKUPSTANDALONE\\TRUEIMAGEMONITOR.EXE"=- "C:\\PROGRAM FILES (X86)\\ACRONIS\\TRUEIMAGEHOME\\TRUEIMAGEMONITOR.EXE"=- [HKEY_CURRENT_USER\Software\BillP Studios\WinPatrol\Run] "C:\\Program Files\\COMODO\\COMODO Internet Security\\cfp.exe -h"=- "C:\\Windows\\system32\\guard64.dll"=- "C:\\Program Files (x86)\\Acronis\\TrueImageHome\\OnlineBackupStandalone\\TrueImageMonitor.exe"=- "C:\\Program Files (x86)\\Acronis\\TrueImageHome\\TrueImageMonitor.exe"=- "C:\\Program Files (x86)\\Common Files\\Acronis\\Schedule2\\schedhlp.exe"=- [HKEY_CURRENT_USER\Software\BillP Studios\WinPatrol\Services] "Norton 360"=- "SBSD Security Center Service"=- "Norton Internet Security"=- "Acronis Scheduler2 Service"=- "Acronis Nonstop Backup service"=- "ThreatFire"=- "COMODO livePCsupport Service"=- "COMODO Internet Security Helper Service"=- "COMODO Dragon Update Service"=- [HKEY_CURRENT_USER\Software\BillP Studios\WinPatrol\UnInstall] "Comodo Dragon"=- "{04A3A6B0-8E19-49BB-82FF-65C5A55F917D}"=- "{986A654F-F1E4-11DD-9FCA-005056C00008}"=- "{9A5509EE-5579-46C1-B566-5065545547F9}"=- "{CD79CE4F-A5E5-11DF-AD00-005056C00008}"=- [HKEY_CURRENT_USER\Software\BillP Studios\WinPatrol\UnInstall64] "{4EAB2511-0135-48CA-A47B-CE1E6836793A}"=- "{DBCF0030-9149-11DE-B8B6-005056C00008}"=- [HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache] "C:\\Program Files (x86)\\Comodo\\Dragon\\dragon.exe"=- "C:\\Program Files (x86)\\Paragon Software\\Backup and Recovery 10 Home Special Edition\\program\\launcher.exe"=- "C:\\Program Files (x86)\\Paragon Software\\Migrate OS to SSD 2.0 Special Edition\\program\\migrateos.exe"=- "C:\\Program Files (x86)\\Paragon Software\\Drive Copy 10 Personal SE\\program\\launcher.exe"=- "C:\\Program Files (x86)\\Acronis\\TrueImageHome\\TrueImageLauncher.exe"=- "C:\\Program Files (x86)\\Acronis\\TrueImageHome\\OnlineBackupStandalone\\ob_client_standard.exe"=- "C:\\Program Files\\COMODO\\COMODO Internet Security\\cfp.exe"=- "C:\\Program Files (x86)\\Hosts_Anti_Adwares_PUPs\\HOSTS_Anti-Adware.exe"=- "C:\\Program Files\\COMODO\\COMODO Internet Security\\cisbf.exe"=- "C:\\Program Files\\COMODO\\COMODO Internet Security\\CisTray.exe"=- "C:\\Program Files\\COMODO\\COMODO Internet Security\\cmdagent.exe"=- "C:\\Program Files\\COMODO\\COMODO Internet Security\\virtkiosk.exe"=- [-HKEY_CURRENT_USER\Software\ComodoGroup] [-HKEY_CURRENT_USER\Software\Microsoft\IntelliPoint\AppSpecific\AntiLogger.exe] [-HKEY_CURRENT_USER\Software\Microsoft\IntelliPoint\AppSpecific\Babylon.exe] [-HKEY_CURRENT_USER\Software\Microsoft\IntelliPoint\AppSpecific\cfp.exe] [-HKEY_CURRENT_USER\Software\Microsoft\IntelliPoint\AppSpecific\cfplogvw.exe] [-HKEY_CURRENT_USER\Software\Microsoft\IntelliPoint\AppSpecific\cfpupdat.exe] [-HKEY_CURRENT_USER\Software\Microsoft\IntelliPoint\AppSpecific\dragon.exe] [-HKEY_CURRENT_USER\Software\Microsoft\IntelliPoint\AppSpecific\schedhlp.exe] [-HKEY_CURRENT_USER\Software\Microsoft\IntelliPoint\AppSpecific\TrueImageMonitor.exe] [-HKEY_CURRENT_USER\Software\Zentimo\Drives\USB*VID_3538&PID_0054*1B82FFF5D89015\Volumes\**?*Volume{c084a884-8442-11df-8e0f-001966d302f4}*\AutoRun\Processes\OnAfterDeviceInsert\Process01]