KillAll::
File::
c:\windows\system32\`АВбђJ&†
c:\windows\system32\f2a1d7d7.exe
c:\windows\system32\mkpvzvk.exe
Driver::
Folder::
c:\program files\Common Files\B3AEB2AFa
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"18432:TCP"=-
RegLock::
[HKEY_USERS\S-1-5-21-1454471165-616249376-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]
DirLook::
c:\synergetnewest