files to delete:
C:\WINDOWS\system32\secpol.exe
C:\WINDOWS\system32\fsmgmt.dll.tmp
C:\WINDOWS\system32\fsmgmt.dll
C:\WINDOWS\systhost.exe
C:\DOCUME~1\GABRIE~1.GAB\IMPOST~1\Temp\P60K8200803 23.html
C:\DOCUME~1\GABRIE~1.GAB\IMPOST~1\Temp\689211B7.TM P
C:\DOCUME~1\GABRIE~1.GAB\IMPOST~1\Temp\88zkmnw9.ln k
C:\DOCUME~1\GABRIE~1.GAB\IMPOST~1\Temp\vmi4r34s.ln k
C:\WINDOWS\lwsys32.exe
Registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs
registry keys to delete:
HKLM\Software\Microsoft\WindowsNT\CurrentVersion\W inlogon\Notify\fsmgmt
registry values to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\pol icies\Explorer\Run | YF65J4R49V
HKLM\Software\Microsoft\Windows\CurrentVersion\pol icies\Explorer\Run | update32
HKLM\SYSTEM\CurrentControlSet\Services\SharedAcces s\Parameters\FirewallPolicy\StandardProfile\Author izedApplications\List | C:\WINDOWS\system32\%%%%%.exe