Registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs
Files to delete:
C:\WINDOWS\system32\mmjxydvu.ini
C:\WINDOWS\system32\ddabc.dll
C:\WINDOWS\system32\hsqqedin.dll
C:\WINDOWS\system32\syhjwsiv.dll
C:\WINDOWS\system32\ijbueckf.dll
C:\WINDOWS\system32\fkceubji.ini
C:\WINDOWS\system32\gjilaygb.dll
C:\WINDOWS\system32\cbadd.ini2
C:\WINDOWS\system32\cbadd.ini
C:\DOCUME~1\Cicco\IMPOST~1\Temp\AAX308.tmp
C:\DOCUME~1\Cicco\IMPOST~1\Temp\3q93E3.tmp
C:\DOCUME~1\Cicco\IMPOST~1\Temp\AAX13D.tmp
C:\DOCUME~1\Cicco\IMPOST~1\Temp\AAX3AE.tmp
C:\DOCUME~1\Cicco\IMPOST~1\Temp\AAX29.tmp
C:\DOCUME~1\Cicco\IMPOST~1\Temp\3169644
C:\DOCUME~1\Cicco\IMPOST~1\Temp\AAX49.tmp
C:\DOCUME~1\Cicco\IMPOST~1\Temp\AAX381.tmp
C:\DOCUME~1\Cicco\IMPOST~1\Temp\removalfile.bat
C:\WINDOWS\system32\spoolw.exe
C:\WINDOWS\system32\igfxsvc.exe
C:\WINDOWS\system32\iifcawx.dll
C:\WINDOWS\system32\mlljk.dll
C:\WINDOWS\system32\hsqqedin.dll
C:\WINDOWS\system32\gjilaygb.dll
C:\DOCUME~1\Cicco\IMPOST~1\Temp\win13C.exe
C:\DOCUME~1\Cicco\IMPOST~1\Temp\win154.bat
registry values to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run \34cc591f
registry keys to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\ShellExecuteHooks\{9AA57522-2ECD-47DF-BD38-20E7E577A464}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{38253AA1-B7CB-4562-BBDE-AB0341B440B5}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{799C1013-489B-42C4-A344-86D700895700}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{addaf5bf-de45-443a-99a8-dfb32b02cd95}