File::
C:\WINDOWS\system32\ntos.exe,
C:\WINDOWS\system\svchost32.exe
C:\WINDOWS\system32\wsnpoem
C:\WINDOWS\system\svchost32.exe
C:\WINDOWS\system32\conf.dat
C:\wndxkef.exe
C:\WINDOWS\system\cmd.exe
C:\WINDOWS\ShowBmp.exe
C:\WINDOWS\system32\uaD6OIO8.dll
C:\WINDOWS\system32\cSdjS18l.dll
C:\WINDOWS\system32\i4Ow80f0.dll
C:\WINDOWS\system32\r0kw74WI.dll
C:\WINDOWS\system32\pNmN6HAd.dll
C:\WINDOWS\system32\BnuyTyUP.dll
C:\WINDOWS\system32\3GKLMQi2.dll
C:\WINDOWS\system32\0PnGQ35r.dll
C:\WINDOWS\system32\bhc65CXL.dll
C:\WINDOWS\system32\B1JbnEw4.dll
C:\WINDOWS\system32\cLFwCpxJ.dll
C:\WINDOWS\system32\midimapd.dll
Folder::
C:\VundoFix Backups
C:\qoobox
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1285AE1E-4ED2-435B-B54A-0D730470251D}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{669CFA6D-450B-4d88-A9D7-D2371E845370}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo Messenger"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"=-