File::
C:\WINDOWS\system32\sstqr.exe
C:\WINDOWS\system32\sstqr.dll
C:\WINDOWS\system32\RENAB.tmp
C:\WINDOWS\system32\RENAA.tmp
C:\WINDOWS\system32\RENA9.tmp
C:\WINDOWS\system32\ejromsxm.dll
C:\WINDOWS\Tasks\A20243CE9185C0A2.job
Folder::
C:\Program Files\Zango Programs
c:\docume~1\nickna~1\applic~1\kinddv~1
C:\VundoFix Backups
C:\Program Files\BearShare
Renv::
----a-w 2,463,744 2008-01-10 20:53:07 C:\Program Files\Advanced Registry Optimizer\aro .exe
----a-w 128,000 2008-01-06 14:35:03 C:\Program Files\CursorXP\CursorXP .exe
----a-w 68,856 2008-01-07 19:44:14 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier .exe
----a-w 579,072 2008-01-09 03:25:51 C:\Program Files\Grisoft\AVG7\avgcc .exe
----a-w 219,136 2008-01-09 01:30:27 C:\Program Files\Grisoft\AVG7\avgw .exe
----a-w 256,576 2008-01-09 00:04:54 C:\Program Files\iTunes\iTunesHelper .exe
----a-w 20,480 2008-01-10 20:40:56 C:\Program Files\McAfee\MBK\LogOnHook .exe
----a-w 4,838,952 2008-01-10 20:41:05 C:\Program Files\McAfee\MBK\McAfeeDataBackup .exe
----a-w 1,279,336 2008-01-09 03:25:30 C:\Program Files\McAfee\MWL\MWLGui .exe
----a-w 582,992 2008-01-10 20:40:56 C:\Program Files\McAfee.com\Agent\mcagent .exe
----a-w 286,720 2008-01-09 03:28:19 C:\Program Files\QuickTime\QTTask .exe
----a-w 286,720 2008-01-08 03:08:42 C:\Program Files\QuickTime\QTTask .exe
----a-w 286,720 2008-01-08 03:08:42 C:\Program Files\QuickTime\QTTask .exe
----a-w 286,720 2008-01-08 03:08:43 C:\Program Files\QuickTime\QTTask .exe
----a-w 286,720 2008-01-08 03:08:43 C:\Program Files\QuickTime\QTTask .exe
----a-w 286,720 2008-01-08 03:08:44 C:\Program Files\QuickTime\QTTask .exe
----a-w 286,720 2008-01-08 03:08:44 C:\Program Files\QuickTime\QTTask .exe
----a-w 286,720 2008-01-08 03:08:44 C:\Program Files\QuickTime\QTTask .exe
----a-w 36,640 2008-01-09 04:28:54 C:\Program Files\SiteAdvisor\6253\SiteAdv .exe
----a-w 365,568 2008-01-10 20:40:43 C:\Program Files\Unlocker\UnlockerAssistant .exe
----a-w 365,568 2008-01-10 20:27:22 C:\Program Files\Unlocker\UnlockerAssistant .exe
----a-w 365,568 2008-01-10 19:45:30 C:\Program Files\Unlocker\UnlockerAssistant .exe
----a-w 15,872 2008-01-10 00:41:34 C:\Program Files\Unlocker\UnlockerAssistant .exe
----a-w 15,872 2008-01-10 01:16:11 C:\Program Files\Unlocker\UnlockerAssistant .exe
----a-w 3,256,320 2008-01-09 01:30:39 C:\Program Files\Veoh Networks\Veoh\VeohClient .exe
----a-w 5,724,184 2008-01-09 01:33:09 C:\Program Files\Windows Live\Messenger\MsnMsgr .Exe
----a-w 5,724,184 2008-01-09 00:48:21 C:\Program Files\Windows Live\Messenger\MsnMsgr .Exe
----a-w 5,724,184 2008-01-08 23

43 C:\Program Files\Windows Live\Messenger\MsnMsgr .Exe
----a-w 5,724,184 2008-01-08 22:04:49 C:\Program Files\Windows Live\Messenger\MsnMsgr .Exe
----a-w 5,724,184 2008-01-08 02:27:58 C:\Program Files\Windows Live\Messenger\MsnMsgr .Exe
----a-w 5,724,184 2008-01-08 03:11:07 C:\Program Files\Windows Live\Messenger\MsnMsgr .Exe
----a-w 5,724,184 2008-01-08 03:11:08 C:\Program Files\Windows Live\Messenger\MsnMsgr .Exe
----a-w 5,724,184 2008-01-08 03:11:10 C:\Program Files\Windows Live\Messenger\MsnMsgr .Exe
----a-w 5,724,184 2008-01-08 03:11:14 C:\Program Files\Windows Live\Messenger\MsnMsgr .Exe
----a-w 5,724,184 2008-01-08 03:11:15 C:\Program Files\Windows Live\Messenger\MsnMsgr .Exe
----a-w 5,724,184 2008-01-08 03:11:17 C:\Program Files\Windows Live\Messenger\MsnMsgr .Exe
----a-w 5,724,184 2008-01-08 03:11:18 C:\Program Files\Windows Live\Messenger\MsnMsgr .Exe
----a-w 5,724,184 2008-01-08 03:11:19 C:\Program Files\Windows Live\Messenger\MsnMsgr .Exe
----a-w 5,724,184 2008-01-08 03:11:21 C:\Program Files\Windows Live\Messenger\MsnMsgr .Exe
----a-w 5,724,184 2008-01-08 03:11:22 C:\Program Files\Windows Live\Messenger\MsnMsgr .Exe
----a-w 5,724,184 2008-01-08 03:11:24 C:\Program Files\Windows Live\Messenger\MsnMsgr .Exe
----a-w 5,724,184 2008-01-08 03:11:25 C:\Program Files\Windows Live\Messenger\MsnMsgr .Exe
----a-w 5,724,184 2008-01-08 03:11:27 C:\Program Files\Windows Live\Messenger\MsnMsgr .Exe
----a-w 5,724,184 2008-01-08 03:11:28 C:\Program Files\Windows Live\Messenger\MsnMsgr .Exe
----a-w 15,360 2008-01-10 20:41:09 C:\WINDOWS\system32\ctfmon .exe
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{539B6280-D0AB-4BA9-8D41-A89298C45C93}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a7a6ea47-45ae-4d76-ba2f-05339b6d4f39}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"coalpoll"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"BearShare"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"6c8b1c13"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare]