KillAll::
Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winctrl32]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WLCtrl32]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws]
[-HKEY_CURRENT_USER\Software\Microsoft\affri]
[-HKEY_CURRENT_USER\Software\Microsoft\rdfa]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP]
[-HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{02E857FD-2262-415D-BC0F-124F9E6241F0}]
[-HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{33940B89-B786-4278-A55C-285A98BAAB2A}]
[-HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{CED9F311-4D80-4EFF-AEB6-909B56045850}]
[-HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{EF4CC146-43C9-4741-8D21-EB5035A4EBEC}]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Sa feBoot\Minimal\Ubh06.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Sa feBoot\Network\Ubh06.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Sa feBoot\Minimal\Ubh06.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Sa feBoot\Network\Ubh06.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\Ubh06.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Network\Ubh06.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Sa feBoot\Minimal\kqW28.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Sa feBoot\Network\kqW28.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Sa feBoot\Minimal\kqW28.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Sa feBoot\Network\kqW28.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\kqW28.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Network\kqW28.sys]
[-HKEY_LOCAL_MACHINE\system\controlset001\services\U bh06]
[-HKEY_LOCAL_MACHINE\system\controlset002\services\U bh06]
[-HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\Ubh06]
[-HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\r oot\legacy_Ubh06]
[-HKEY_LOCAL_MACHINE\system\controlset001\enum\root\ legacy_Ubh06]
[-HKEY_LOCAL_MACHINE\system\controlset002\enum\root\ legacy_Ubh06]
[-HKEY_LOCAL_MACHINE\system\controlset001\services\k qW28]
[-HKEY_LOCAL_MACHINE\system\controlset002\services\k qW28]
[-HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\kqW28]
[-HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\r oot\legacy_kqW28]
[-HKEY_LOCAL_MACHINE\system\controlset001\enum\root\ legacy_kqW28]
[-HKEY_LOCAL_MACHINE\system\controlset002\enum\root\ legacy_kqW28]
File::
C:\WINNT\system32\WinCtrl32.dll
C:\WINNT\system32\WinCtrl32.dl_
C:\WINNT\system32\entcblfg.dll
C:\WINNT\system32\opnlLcYQ.dll
C:\WINDOWS\SYSTEM32\WLCtrl32.dll
C:\WINNT\system32\faxabfiy.dll
C:\WINNT\system32\bgjqccqv.ini
C:\WINNT\system32\yifbaxaf.ini
C:\WINNT\system32\WinCtrl32.dll
C:\WINNT\system32\drivers\Ubh06.sys
C:\WINNT\system32\drivers\kqW28.sys
C:\WINNT\cookies.ini
C:\WINNT\system32\opnlLcYQ.dll
C:\DOCUME~1\PAGLIO~1\IMPOST~1\Temp\nnnOeEVM.dll
C:\WINNT\system32\geBrsRkl.dll
Driver::
C:\WINNT\system32\drivers\Ubh06.sys
C:\WINNT\system32\drivers\kqW28.sys