Killall::
Snapshot::
File::
c:\windows\system32\rinhlqls.exe
Folder::
c:\documents and settings\Chris\Local Settings\Application Data\Shareaza
c:\documents and settings\Chris\Application Data\Shareaza
c:\documents and settings\Chris\Local Settings\Application Data\Ares
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"rinhlqls"=-