files to delete:
C:\WINDOWS\system32\f3PSSavr.VVVscr
C:\WINDOWS\system32\bootvi.dll
C:\WINDOWS\service32.exe
C:\WINDOWS\lsass32.exe
C:\WINDOWS\system32\winlft32.dll
C:\WINDOWS\new_drv.sys
registry values to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\pol icies\Explorer\Run | 6G98D2X74V
HKLM\Software\Microsoft\Windows\CurrentVersion\pol icies\Explorer\Run | Service
registry keys to delete:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winlft32
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{A8FA25EF-5B09-459D-9B62-C4AF79808457}
HKLM\system\currentcontrolset\services\new_drv
HKLM\system\controlset001\services\new_drv
HKLM\system\controlset002\services\new_drv
HKLM\system\currentcontrolset\services\{FBE1D620-5418-4aae-A0F0-316D590663A1}
HKLM\system\controlset001\services\{FBE1D620-5418-4aae-A0F0-316D590663A1}
HKLM\system\controlset002\services\{FBE1D620-5418-4aae-A0F0-316D590663A1}