Code:
KILLALL::
File::
C:\WINDOWS\system32\hviatwxg.exe
C:\WINDOWS\system32\durpjwdg.dll
Folder::
C:\VundoFix Backups
C:\Documents and Settings\Andy\Application Data\Azureus
C:\Program Files\Azureus
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BM333e2456"=-
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Azureus\\Azureus.exe"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d534d8cd-7463-11db-b423-0013729216ee}]