systemroot+ tlogon.exesystemroot+securitylogsmfcexp.exesystemroot+systemmuisvcbak.exetrojanspy.win32.agent.d.exe
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionunmfcexpHKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionunsvcbak