HKU\S-1-5-21-1719308311-501218547-3283189548-1000\...\Run: [WINUP] => regsvr32 "C:\Users\Paopaw\AppData\Local\Temp\reg.dll