http://safezone.cc/forum/showthread.php?t=10808
KillAll::
Collect::
c:\windows\system32\qsiuqir.exe
c:\windows\system32\nlvwzmy.exe
c:\windows\system32\*›ж¦2WЂL
c:\windows\system32\*Ыо¦2WЂL
c:\windows\system32\*»k§2WЂL
c:\windows\mkdrv.sys
Driver::
mkdrv
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2113:TCP"=-
RegLock::
[HKEY_USERS\S-1-5-21-1708537768-789336058-1417001333-500\Software\Microsoft\Internet Explorer\User Preferences]