addsgn A7679BF0AA0208F24AD4C6711C891295412BFCF689FA4F1C0CE6C5BC50D6F2A05F449500B730757AF009D9632C14B6EF41CFA8720C59BD94AC36A4D0440BBAF2 8 a variant of Win32/Kryptik.ACMS (ESET)
zoo %SystemDrive%\DOCUMENTS AND SETTINGS\PAZZO\ГЛАВНОЕ МЕНЮ\ПРОГРАММЫ\АВТОЗАГРУЗКА\7VK3UD9QZS.EXE
bl 22484A6A966D666DD733A7A7AA326242 117248
addsgn A7679B1BB9D24D720B132B1D9A37ED05258AFC310C16E1877AC3C5BC5011F430DDE83C333E559D8EAE687A60B91449FA7D18AD8A55DAB02CEAF214D138F92273 8 a variant of Win32/Kryptik.ACMS 1
zoo %SystemDrive%\DOCUMENTS AND SETTINGS\PAZZO\ГЛАВНОЕ МЕНЮ\ПРОГРАММЫ\АВТОЗАГРУЗКА\KGXC999QLN4.EXE
bl 49131E2CF121500B4FDB2D51AFE0A95E 317440
chklst
delvir
zoo %SystemDrive%\DOCUMENTS AND SETTINGS\PAZZO\ГЛАВНОЕ МЕНЮ\ПРОГРАММЫ\АВТОЗАГРУЗКА\ZKHFHXQ2PBA.EXE
delall %SystemDrive%\DOCUMENTS AND SETTINGS\PAZZO\ГЛАВНОЕ МЕНЮ\ПРОГРАММЫ\АВТОЗАГРУЗКА\ZKHFHXQ2PBA.EXE
zoo %SystemDrive%\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\QPN7GI3.DLL
delref %SystemDrive%\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\QPN7GI3.DLL
zoo %SystemRoot%\OKYYA.SYS
delref %SystemRoot%\OKYYA.SYS
delref COPY
delref HTTP://WWW.YAHOO.COM
delref HTTP://WWW.YANDEX.RU/?CLID=140504
exec "C:\PROGRAM FILES\MAIL.RU\GUARD\GUARDMAILRU.EXE" /UNINSTALL
exec C:\PROGRAM FILES\MAIL.RU\SPUTNIK\MAILRUSPUTNIK_RFRMEDIAGET_MPCLN8746.EXE UNINSTALL
exec C:\PROGRAM FILES\TICNO\TABS\UNINSTALL.EXE
exec C:\PROGRAM FILES\TICNO\MULTIBAR\UNINSTALL.EXE
exec RUNDLL32.EXE C:\PROGRA~1\YAHOO!\COMPAN~1\INSTALLS\CPN\YCOMP5~1.DLL,DLLCOMMAND UI
exec MSIEXEC.EXE /I{FBFBBDD0-EC37-4152-BB77-7D54322AF953}
regt 14
regt 12
regt 18
deltmp
delnfr
czoo
restart