File::
C:\WINDOWS\system32\nlrqbsmf.ini
C:\WINDOWS\system32\cpxgjqyh.ini
C:\WINDOWS\system32\bbmkbdsx.ini
C:\WINDOWS\system32\nidhlwne.ini
C:\WINDOWS\system32\bjjskdjr.tmp
C:\WINDOWS\system32\dghoamio.dll
C:\WINDOWS\system32\ykjonbrr.dll
C:\WINDOWS\system32\suamuncj.dll
C:\WINDOWS\system32\huokpyov.dll
C:\WINDOWS\system32\bgdotytc.dll
C:\WINDOWS\system32\vttqdynj.dll
C:\WINDOWS\system32\yjkrfwqv.dll
C:\WINDOWS\b153.exe_old
C:\WINDOWS\system32\mwtkrtfp.dll
C:\WINDOWS\system32\xlmnfgcu.dll
C:\WINDOWS\system32\opsiukvi.dll
C:\WINDOWS\system32\akicwaft.dll
C:\Program Files\Symantec\sadyty77798.exe
C:\Documents and Settings\Prashant Bisht\Application Data\Microsoft\Windows\kyqeihy.exe
Folder::
C:\Program Files\Dot1XCfg
C:\Program Files\Drmupgds
C:\Program Files\Insider
C:\Program Files\QdrPack
C:\Program Files\Router
C:\Program Files\WinAble
C:\Documents and Settings\Prashant Bisht\Application Data\WinTouch
C:\Program Files\Perfect Information
Registry::
[-HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About
:Home"
"SubscribedURL"="About
:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\24bc6bad]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\A3A9ACA8AFAEAAAC]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM278f5831]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dot1XCfg]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Drmupgds]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Insider]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QdrPack9]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Router]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinAble]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinTouch]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XLMonitor]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sadyty]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SfKg6w]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]