files to delete:
C:\WINDOWS\system32\ssqNFUMG.dll
C:\WINDOWS\system32\efcDSIAQ.dll
C:\WINDOWS\system32\qoMcbcAS.dll
C:\WINDOWS\system32\qewmlgkx.dll
C:\WINDOWS\system32\mqomwqnv.dll
C:\WINDOWS\system32\npksuvtp.dll
C:\WINDOWS\system32\ptvuskpn.tmp
C:\WINDOWS\system32\ptvuskpn.ini
C:\WINDOWS\system32\ptvuskpn.ini2
C:\WINDOWS\system32\osxxtkiw.dll
C:\WINDOWS\system32\rvxexygj.dll
C:\WINDOWS\system32\swbhjwqd.tmp
C:\WINDOWS\system32\swbhjwqd.ini
C:\WINDOWS\system32\awttronk.dll
C:\WINDOWS\system32\iyypqnrr.dll
C:\WINDOWS\system32\rrnqpyyi.tmp
C:\WINDOWS\system32\rrnqpyyi.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\opnliged.dll
C:\WINDOWS\system32\cbxwwwus.dll
C:\WINDOWS\system32\wvuvspqo.dll
C:\WINDOWS\system32\byxvvvvt.dll
C:\WINDOWS\system32\srkqy.exe
C:\WINDOWS\system32\iiffddcy.dll
C:\WINDOWS\system32\rrnqpyyi.ini2
C:\WINDOWS\system32\wvuvsspo.dll
C:\WINDOWS\system32\erelbjfu.dll
C:\WINDOWS\system32\owuqsjnn.dll
C:\WINDOWS\system32\ifqfflgf.dll
C:\WINDOWS\system32\fglffqfi.tmp
C:\WINDOWS\system32\fglffqfi.ini
C:\WINDOWS\system32\fglffqfi.ini2
C:\WINDOWS\system32\fsimjccc.dll
C:\WINDOWS\system32\fgynynbw.dll
C:\WINDOWS\system32\QAISDcfe.ini2
C:\WINDOWS\system32\wbnynygf.ini
C:\WINDOWS\system32\QAISDcfe.ini
C:\WINDOWS\system32\cirqqju.exe
C:\Documents and Settings\mm.MARCO\myaxlhj.exe
C:\Documents and Settings\mm.MARCO\qebumw.exe
C:\WINDOWS\BM0b36e839.txt
C:\WINDOWS\BM0b36e839.xml
C:\WINDOWS\pskt.ini
C:\U.exe
registry values to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | BM0b36e839
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | 0805dba5
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\ShellExecuteHooks | {D976B84B-808C-4357-9CBB-55BF1F7CEBE7}
SharedAccess\Parameters\FirewallPolicy\StandardPro file\AuthorizedApplications\List | C:\WINDOWS\system32\srkqy.exe
SharedAccess\Parameters\FirewallPolicy\StandardPro file\AuthorizedApplications\List | C:\Documents and Settings\mm.MARCO\myaxlhj.exe
SharedAccess\Parameters\FirewallPolicy\StandardPro file\AuthorizedApplications\List | C:\Documents and Settings\mm.MARCO\qebumw.exe
SharedAccess\Parameters\FirewallPolicy\StandardPro file\AuthorizedApplications\List | C:\WINDOWS\system32\cirqqju.exe
registry keys to delete:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ssqNFUMG
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM0b36e839
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{D976B84B-808C-4357-9CBB-55BF1F7CEBE7}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{E5327C7F-444E-407E-B44D-7F5657794AD5}