files to delete:
C:\DOCUME~1\Pippo\IMPOST~1\Temp\ljJCtqRJ.bat
C:\WINDOWS\seeukluba.exe
C:\WINDOWS\salrtybek.exe
C:\WINDOWS\jikglond.exe
C:\WINDOWS\jiklagka.exe
C:\WINDOWS\tobmygers.exe
C:\WINDOWS\tobykke.exe
C:\WINDOWS\klopnidret.exe
C:\WINDOWS\jungertab.exe
C:\WINDOWS\iddqdops.exe
C:\WINDOWS\skaaanret.exe
C:\WINDOWS\zibaglertz.exe
C:\WINDOWS\aazalirt.exe
C:\WINDOWS\ronitfst.exe
C:\WINDOWS\system32\ijPWxyxx.ini
C:\WINDOWS\system32\ijPWxyxx.ini2
C:\WINDOWS\system32\jkkIAPGW.dll
C:\WINDOWS\system32\3f614f4c-.txt
C:\WINDOWS\system32\rpbsroyj.ini
C:\WINDOWS\system32\xxyxWPji.dll
C:\WINDOWS\system32\awttqpqR.dll
C:\WINDOWS\temp\tmp3.exe
C:\WINDOWS\temp\tmp3.tmp
C:\WINDOWS\temp\tmp19.exe
C:\WINDOWS\temp\tmp19.tmp
C:\WINDOWS\temp\tmp4C.exe
C:\WINDOWS\temp\tmp4C.tmp
C:\WINDOWS\system32\jyorsbpr.dll
C:\WINDOWS\sysguard.exe
C:\WINDOWS\system32\awttqpqR.dll
C:\WINDOWS\system32\xxyxWPji.dll
C:\WINDOWS\tasks\gyokqong.job
registry values to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | 34428b32
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\ShellExecuteHooks | {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
registry keys to delete:
HKLM\system\currentcontrolset\services\asc3550p
HKLM\system\controlset001\services\asc3550p
HKLM\system\controlset002\services\asc3550p
HKLM\system\currentcontrolset\enun\root\legacy_asc 3550p
HKLM\system\controlset001\enun\root\legacy_asc3550 p
HKLM\system\controlset002\enun\root\legacy_asc3550 p
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awttqpqR
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{0C90AFF8-9BA1-4F99-BCE7-47F549B51A17}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}