files to delete:
C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\winsHEsBewN.exe
C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\winefPBnqCl.exe
C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\winMAIzKAkWTOdQ .exe
C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\winbnshb.exe
C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\winnP0NzYdKiI.e xe
C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\wingPNnqr.exe
C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\winl2Ye60B.exe
C:\WINDOWS\system32\pejoyawa
C:\WINDOWS\system32\anifiwil.ini
C:\WINDOWS\system32\liwifina.dll
C:\WINDOWS\system32\ligutafo.dll
C:\WINDOWS\system32\obarezes.ini
C:\WINDOWS\system32\~.exe
C:\WINDOWS\system32\sezerabo.dll
C:\WINDOWS\system32\miwajiho.dll
C:\WINDOWS\system32\eyotahif.ini
C:\WINDOWS\system32\jejowada.dll
C:\WINDOWS\system32\fihatoye.dll
C:\WINDOWS\system32\oserepov.ini
C:\WINDOWS\system32\vopereso.dll
C:\WINDOWS\system32\kenahozi.dll
C:\WINDOWS\system32\okariroz.ini
C:\WINDOWS\system32\jutepeso.dll
C:\WINDOWS\system32\zorirako.dll
C:\WINDOWS\system32\TDSSvvbj.log
C:\WINDOWS\system32\TDSSnmxh.dll
C:\WINDOWS\system32\TDSShrxr.dat
C:\WINDOWS\system32\TDSSlxcp.dll
C:\WINDOWS\system32\TDSSmtvd.dat
C:\WINDOWS\system32\rokeyuki.dll
c:\windows\system32\miwajiho.dll
C:\WINDOWS\rundtl32.exe
c:\windows\system32\miwajiho.dll
C:\WINDOWS\system32\yetuheke.dll
C:\WINDOWS\system32\gavapufa.dll
registry values to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | CPMfbeb6465
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | hujidiveja
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\SharedTaskScheduler | {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}
registry keys to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\Browser Helper Objects\{2fd24415-ac26-4594-820a-23004af875f5}
registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs