http://safezone.cc/forum/showthread.php?t=10479
KillAll::
Collect::
c:\windows\system32\mjqfel.exe
c:\windows\system32\b3b057b.exe
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,"
RegLock::
[HKEY_USERS\S-1-5-21-1417001333-1958367476-1801674531-500\Software\Microsoft\Internet Explorer\User Preferences]
FileLook::
c:\windows\system32\setupapi.dll