KillAll::
File::
c:\windows\system32\@д
c:\windows\system32\ц®NЂ
c:\windows\system32\wlaajg.exe
c:\windows\sorry.exe
Driver::
Folder::
c:\program files\Common Files\C4DBE443a
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"24673:TCP"=-
FileLook::
c:\windows\system32\4
c:\windows\system32\drivers\ylelsz.sys
DirLook::