Registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs
Files to delete:
C:\WINDOWS\system32\drivers\hidr.exe
C:\WINDOWS\system32\drivers\hidrrr.exe
C:\WINDOWS\system32\drivers\hldrrr.exe
C:\WINDOWS\system32\drivers\srosa.sys
C:\WINDOWS\system32\drivers\pci32.sys
C:\WINDOWS\system32\drivers\hldrrr.ex_
C:\WINDOWS\system32\wintems.exe
c:\WINDOWS\system32\hlpuybtr.exe
C:\WINDOWS\system32\hldrrr.exe
c:\Documents and Settings\
user\Dati applicazioni\hidires\m_hook.sys
c:\Documents and Settings\
user\Dati applicazioni\hidires\hidr.exe
c:\Documents and Settings\
user\Dati applicazioni\hidires\srosa.sys
c:\Documents and Settings\
user\Dati applicazioni\hidn\hidn2.exe
c:\Documents and Settings\
user\Dati applicazioni\hidn\hldrrr.exe
folders to delete:
c:\WINDOWS\exefld
c:\WINDOWS\exefnd
c:\temp
C:\WINDOWS\system32\drivers\down
c:\Documents and Settings\
user\Dati applicazioni\hidires
c:\Documents and Settings\
user\Dati applicazioni\hidn
registry keys to delete:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\m_hook
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\pci32
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\srosa
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\R oot\LEGACY_M_HOOK
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\R oot\LEGACY_SROSA
registry values to delete:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run | hldrrr