files to delete:
C:\WINDOWS\BMdb16f8df.txt
C:\WINDOWS\pskt.ini
C:\WINDOWS\BMdb16f8df.xml
C:\WINDOWS\system32\g96.exe
C:\WINDOWS\system32\lhdzidectspnl.dll
C:\WINDOWS\system32\ydidbogmizdeb.exe
C:\WINDOWS\system32\yayyVomm.dll
C:\WINDOWS\system32\pmnMGxvU.dll
C:\WINDOWS\system32\pmnlmllI.dll
C:\WINDOWS\system32\ncnyhwvu.dll
C:\WINDOWS\system32\jzotqj.dll
C:\WINDOWS\system32\xryujdca.dll
C:\WINDOWS\system32\hfgcnxgc.ini
C:\WINDOWS\system32\ghsulfcd.dll
C:\WINDOWS\system32\cxfpce.dll
C:\WINDOWS\system32\fvgxtnaw.dll
C:\WINDOWS\system32\bwihgxxf.ini
C:\WINDOWS\system32\djjbkybb.dll
C:\WINDOWS\system32\edoogn.dll
C:\WINDOWS\system32\tqqlfkld.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\jbeoyoua.ini
C:\WINDOWS\system32\vjstepmt.dll
C:\WINDOWS\system32\jqvntkma.dll
C:\WINDOWS\system32\owiwzt.dll
C:\WINDOWS\system32\nraaxfbt.ini
C:\WINDOWS\system32\d3060f3d-.txt
C:\WINDOWS\system32\mkyqyydv.dll
C:\WINDOWS\system32\hjkwpmpf.dll
C:\WINDOWS\system32\dexuuoka.dll
C:\WINDOWS\system32\hrpggq.dll
C:\WINDOWS\system32\fpmpwkjh.ini
C:\WINDOWS\system32\Illmlnmp.ini2
C:\WINDOWS\system32\Illmlnmp.ini
C:\WINDOWS\system32\ctfmon.exe
C:\sqmdata07.sqm
C:\sqmnoopt07.sqm
C:\sqmnoopt08.sqm
C:\sqmdata08.sqm
C:\sqmnoopt09.sqm
C:\sqmdata09.sqm
C:\sqmnoopt10.sqm
C:\sqmdata10.sqm
C:\sqmnoopt11.sqm
C:\sqmdata11.sqm
C:\sqmnoopt12.sqm
C:\sqmdata12.sqm
C:\sqmnoopt13.sqm
C:\sqmdata13.sqm
C:\sqmdata14.sqm
C:\sqmnoopt14.sqm
C:\sqmdata15.sqm
C:\sqmnoopt15.sqm
C:\sqmdata16.sqm
C:\sqmnoopt16.sqm
C:\sqmdata17.sqm
C:\sqmnoopt17.sqm
C:\sqmnoopt18.sqm
C:\sqmdata18.sqm
C:\sqmdata19.sqm
C:\sqmnoopt19.sqm
C:\sqmdata00.sqm
C:\sqmnoopt00.sqm
C:\sqmdata01.sqm
C:\sqmnoopt01.sqm
C:\sqmnoopt02.sqm
C:\sqmdata02.sqm
C:\sqmnoopt03.sqm
C:\sqmdata03.sqm
C:\sqmnoopt04.sqm
C:\sqmdata04.sqm
C:\sqmnoopt05.sqm
C:\sqmdata05.sqm
C:\sqmnoopt06.sqm
C:\sqmdata06.sqm
files to move:
C:\Programmi\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe | C:\Programmi\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
C:\Programmi\CyberLink\PowerDVD\bak\PDVDServ.exe | C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe
C:\Programmi\DAEMON Tools\bak\daemon.exe | C:\Programmi\DAEMON Tools\daemon.exe
C:\Programmi\Google\GoogleToolbarNotifier\bak\Goog leToolbarNotifier.exe | C:\Programmi\Google\GoogleToolbarNotifier\GoogleTo olbarNotifier.exe
C:\Programmi\IPM\Adsl\DataWay\bak\dslstat.exe | C:\Programmi\IPM\Adsl\DataWay\dslstat.exe
C:\Programmi\Java\jre1.6.0_03\bin\bak\jusched.exe | C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\bak\ctfmon.exe | C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\bak\hkcmd.exe | C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\bak\igfxpers.exe | C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\bak\igfxtray.exe | C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\bak\NeroCheck.exe | C:\WINDOWS\system32\NeroCheck.exe
registry values to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\ShellExecuteHooks | {08BED96E-5A7D-42E7-9049-D2FB4978BEBC}
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | BMdb16f8df
registry keys to delete:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnMGxvU
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{08BED96E-5A7D-42E7-9049-D2FB4978BEBC}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{40b06e17-1497-77be-31d6-106ac79597f4}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{C05C01D2-5437-4F3B-9F3F-0E4060AF9A6F}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{c7d3899b-cbb3-4d7d-a7a6-94ad5e2730ad}
HKEY_LOCAL_MACHINE\system\controlset002\services\a sc3550p
HKEY_LOCAL_MACHINE\system\controlset001\asc3550p
HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\asc3550p
programs to launch on reboot:
c:\fix.reg