KillAll::
File::
d:\torrentfiles\LoviVkontakte\VkontakteService.exe
d:\torrentfiles\LoviVkontakte\lovivkontakte.exe
c:\program files\Ask.com\GenericAskToolbar.dll
c:\windows\C5C1C0F0D62F4DBF81D4D7EF397C228B.TMP
Driver::
LoviVkontakteService
Folder::
C:\32788R22FWJFW
d:\torrentfiles\LoviVkontakte
c:\program files\Ask.com
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"=-
[-HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[-HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[-HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LoviVkontakte"=-
RegLock::
[HKEY_USERS\S-1-5-21-1599197451-2005375074-830068836-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{CCD19F46-32B8-DDC2-E6EA-D9B9AF8014BB}*]
"maelobjgchpkocglgadaaaoohk"=hex:65,61,6d,68,6d,64,64,63,63,62,00,6e
"maelobjgchpkocdlbcokafobgc"=hex:6b,61,6f,65,69,6c,65,63,70,6f,63,6e,62,69,6a,
70,63,65,6a,6f,6e,6e,00,00
[HKEY_USERS\S-1-5-21-1599197451-2005375074-830068836-1000\Software\SecuROM\License information*]
"datasecu"=hex:0a,04,bc,4b,0e,d1,97,72,56,f5,53,2f,35,f1,00,d7,05,41,5a,3b,63,
c3,56,f0,ae,27,65,3c,97,42,fa,5e,10,5c,d1,ff,4c,02,97,79,6e,92,ea,dd,2f,cb,\
"rkeysecu"=hex:07,f1,74,19,cf,30,34,a0,1e,d0,e4,1c,4f,98,c5,12
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
Reboot::