files to delete:
C:\Windows\system32\wvUmmllk.dll
C:\Windows\system32\nqqqAJjl.ini2
C:\Windows\system32\jnkcawlb.ini
C:\Windows\system32\nqqqAJjl.ini
C:\Windows\system32\hefsoiuy.ini
C:\Windows\system32\KTvCKnpo.ini2
C:\Windows\system32\KTvCKnpo.ini
C:\Windows\system32\sfjghjuq.ini
C:\Windows\system32\koaiymam.ini
C:\Windows\system32\ainvlplw.ini
C:\Windows\system32\hahogluk.ini
C:\Windows\system32\clkcnt.txt
C:\Windows\system32\ssjcqhmb.ini
C:\Windows\system32\eNXHkUvw.ini2
C:\Windows\system32\eNXHkUvw.ini
C:\Windows\vbksrofa.dll
C:\Windows\mpfanvqg.dll
C:\Windows\system32\wvUkHXNe.dll
C:\Users\Enrico\AppData\Local\Temp\stdcons.exe
registry values to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | MSServer
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | advap32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ShellServiceObjectDelayLoad | vbksrofa
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ShellServiceObjectDelayLoad | mpfanvqg
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\ShellExecuteHooks | {EF4CC146-43C9-4741-8D21-EB5035A4EBEC}
registry keys to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{83A2F9B1-01A2-4AA5-87D1-45B6B8505E96}]
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{E2055062-F4D1-4CF2-99A6-EB7903D57059}]
programs to launch on reboot:
c:\fix.reg