files to delete:
C:\Windows\mssys.exe
C:\Windows\msupdate.exe
C:\Windows\iedll.exe
C:\Windows\cpan.dll
C:\Windows\astctl32.ocx
C:\Windows\accesss.exe
C:\Windows\clrssn.exe
C:\Windows\avpcc.dll
C:\Windows\loader.exe
C:\Windows\mtwirl32.dll
C:\Windows\win32e.exe
C:\Windows\win64.exe
C:\Windows\waol.exe
C:\Windows\winmgnt.exe
C:\Windows\notepad32.exe
C:\Windows\olehelp.exe
C:\Windows\winajbm.dll
C:\Windows\window.exe
C:\Windows\users32.exe
C:\Windows\systeem.exe
C:\Windows\time.exe
C:\Windows\systemcritical.exeS?mantec
C:\Windows\systemcritical.exe
C:\Windows\x.exe
C:\Windows\y.exe
C:\Windows\xxxvideo.hta
C:\Windows\xplugin.dll
C:\Windows\iexplorer.exe
C:\Windows\default.htm
C:\Windows\b156.exe
C:\Windows\b155.exe
C:\Windows\mrofinu1188.exe
C:\Windows\mrofinu1000106.exe
C:\Windows\ctfmon32.exe
C:\Windows\dnsrelay.dll
C:\Windows\editpad.exe
C:\Windows\ctrlpan.dll
C:\Windows\directx32.exe
C:\Windows\funniest.exe
C:\Windows\funny.exe
C:\Windows\explore.exe
C:\Windows\explorer32.exe
C:\Windows\inetinf.exe
C:\Windows\internet.exe
C:\Windows\gfmnaaa.dll
C:\Windows\helpcvs.exe
C:\Windows\msconfd.dll
C:\Windows\rundll32.vbe
C:\Windows\mswsc20.dll
C:\Windows\qttasks.exe
C:\Windows\rundll16.exe
C:\Windows\quicken.exe
C:\Windows\mswsc10.dll
C:\Windows\msspi.dll
C:\Windows\sistem.exe
C:\Windows\svcinit.exe
C:\Windows\svchost32.exe
C:\Windows\searchword.dll
C:\Windows\system32\fcCUKcyW.dll
C:\Windows\system32\nnnmjkIb.dll
C:\Windows\system32\modtrux18
C:\Windows\system32\hljwugsf.bin
C:\Windows\system32\fcCUKcyW.dll
C:\Windows\system32\sofdqoxy.ini
C:\Windows\system32\downloads.bak
C:\Windows\system32\fhsmagky.ini
C:\Windows\system32\ljJaXQki.dll
C:\Windows\system32\ikQXaJjl.ini2
C:\Windows\system32\tpuqtjpl.dll
C:\Windows\system32\ikQXaJjl.ini
C:\Windows\system32\downloads.txt
C:\Windows\system32\WycKUCcf.ini2
C:\Windows\system32\WycKUCcf.ini
C:\Windows\system32\cbXoOFXr.dll
C:\Windows\system32\rXFOoXbc.ini
C:\Windows\system32\rXFOoXbc.ini2
C:\Windows\system32\mcrh.tmp
C:\Windows\system32\lpjtqupt.ini
C:\Windows\system32\tuvWpNDs.dll
C:\Windows\system32\dbdf7c0a-.txt
C:\Windows\system32\hfuruuea.dll
C:\Windows\system32\aeuurufh.ini
C:\Windows\system32\sDNpWvut.ini2
C:\Windows\system32\sDNpWvut.ini
C:\Windows\system32\dllcache\iexplore.exe
C:\Windows\system32\hfuruuea.dll
C:\Windows\system32\cbXoOFXr.dll
C:\Windows\system32\drivers\pavboot.sys
C:\Users\Matteo\lsass.exe
C:\Users\Matteo\AppData\Roaming\Microsoft\Windows\ waiyya.exe
C:\Users\Matteo\Documents\??crosoft\m?iexec.exe
C:\Users\Matteo\Documents\microsoft\msiexec exe
C:\Windows\SMANTE~1\services.exe
folders to delete:
C:\Windows\TWF0dGVv
C:\Windows\system32\rt
C:\Windows\system32\ov
C:\Windows\system32\I3
C:\Program Files\mjc
C:\Program Files\Sakora
C:\Users\Matteo\AppData\Roaming\SpeedRunner
C:\Users\Matteo\Documents\??crosoft
C:\Users\Matteo\Documents\microsoft
C:\Program Files\Temporary
registry values to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | d0fcb874
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | MSServer
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | runner1
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | Microsoft©
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\ShellExecuteHooks | {06A1F910-762A-4660-B534-55B82571851C}
registry keys to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{00110011-4b0b-44d5-9718-90c88817369b}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{086ae192-23a6-48d6-96ec-715f53797e85}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{150fa160-130d-451f-b863-b655061432ba}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{17da0c9e-4a27-4ac5-bb75-5d24b8cdb972}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb1}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb2}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{2d38a51a-23c9-48a1-a33c-48675aa2b494}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{2e9caff6-30c7-4208-8807-e79d4ec6f806}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{467faeb2-5f5b-4c81-bae0-2a4752ca7f4e}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{5321e378-ffad-4999-8c62-03ca8155f0b3}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{587dbf2d-9145-4c9e-92c2-1f953da73773}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{6cc1c91a-ae8b-4373-a5b4-28ba1851e39a}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{79369d5c-2903-4b7a-ade2-d5e0dee14d24}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{799a370d-5993-4887-9df7-0a4756a77d00}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{98dbbf16-ca43-4c33-be80-99e6694468a4}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{a55581dc-2cdb-4089-8878-71a080b22342}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{b847676d-72ac-4393-bfff-43a1eb979352}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{bc97b254-b2b9-4d40-971d-78e0978f5f26}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{cf021f40-3e14-23a5-cba2-717765721306}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{CFA57E06-8211-46B8-92B7-A05131B0C807}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{e2ddf680-9905-4dee-8c64-0a5de7fe133c}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{e3eebbe8-9cab-4c76-b26a-747e25ebb4c6}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{e7afff2a-1b57-49c7-bf6b-e5123394c970}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{fd9bc004-8331-4457-b830-4759ff704c22}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{ff1bf4c7-4e08-4a28-a43f-9d60a9f7a880}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB}
HKEY_LOCAL_MACHINE\system\controlset001\services\p avboot
HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\pavboot
HKEY_LOCAL_MACHINE\system\controlset001\enum\root\ legacy_pavboot
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\r oot\legacy_pavboot
programs to launch on reboot:
c:\fix.reg