files to delete:
C:\WINDOWS\system32\clkcnt.txt
C:\WINDOWS\system32\iiffDUlM.dll
C:\WINDOWS\system32\wvUnMeDS.dll
C:\WINDOWS\system32\SAKjlUvw.ini2
C:\WINDOWS\system32\SAKjlUvw.ini
C:\WINDOWS\system32\XHgPoUvw.ini2
C:\WINDOWS\system32\XHgPoUvw.ini
C:\WINDOWS\system32\mpVvDJlm.ini2
C:\WINDOWS\system32\mpVvDJlm.ini
C:\WINDOWS\system32\mTtAaccf.ini2
C:\WINDOWS\system32\mTtAaccf.ini
C:\WINDOWS\system32\UvvDdMoq.ini2
C:\WINDOWS\system32\UvvDdMoq.ini
C:\WINDOWS\system32\gOprtvut.ini2
C:\WINDOWS\system32\gOprtvut.ini
C:\WINDOWS\system32\QqtuDJlm.ini2
C:\WINDOWS\system32\QqtuDJlm.ini
C:\WINDOWS\system32\AyyHNqss.ini2
C:\WINDOWS\system32\AyyHNqss.ini
C:\WINDOWS\system32\mnoXyccf.ini2
C:\WINDOWS\system32\mnoXyccf.ini
C:\WINDOWS\system32\EgMWDJlm.ini2
C:\WINDOWS\system32\EgMWDJlm.ini
C:\WINDOWS\system32\OYcbcMoq.ini2
C:\WINDOWS\system32\OYcbcMoq.ini
C:\WINDOWS\system32\TuxIknnn.ini2
C:\WINDOWS\system32\TuxIknnn.ini
C:\WINDOWS\system32\kjTBLnmp.ini2
C:\WINDOWS\system32\kjTBLnmp.ini
C:\WINDOWS\system32\hiSuCcfe.ini2
C:\WINDOWS\system32\hiSuCcfe.ini
C:\WINDOWS\system32\MlUDffii.ini2
C:\WINDOWS\system32\MlUDffii.ini
C:\WINDOWS\system32\winview8x.dll
C:\WINDOWS\system32\syscheck32.dll
C:\WINDOWS\system32\apiview2.dll
folders to delete:
C:\found.000
files to move:
C:\WINDOWS\tasks\ejswcc.job | c:\pippo\ejswcc.job
registry values to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\ShellExecuteHooks | {BA44CBC8-E16A-4F36-B066-4D75699E171D}
registry keys to delete:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvUnMeDS
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{BA44CBC8-E16A-4F36-B066-4D75699E171D}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{A5693AF6-FF5B-4F63-9A0E-4F22D7E511B7}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{BBEEBE4F-3EDA-40F4-A0AB-87593EE49C56}
programs to launch on reboot:
c:\fix.reg