files to delete:
C:\WINDOWS\eqvwamkl.dll
C:\WINDOWS\wnslvxtf.dll
C:\WINDOWS\ewte.exe
C:\WINDOWS\nfavxwdbkvn.dll
C:\WINDOWS\fdkowvbp.dll
C:\WINDOWS\grswptdl.exe
C:\DOCUME~1\Michele\IMPOST~1\Temp\removalfile.bat
C:\WINDOWS\system32\nnnnNheC.dll
C:\WINDOWS\temp\cch~1420c419d0.htp
C:\WINDOWS\temp\cch~1420c40dae.htp
C:\WINDOWS\temp\cch~14ff07dd2.htp
C:\WINDOWS\temp\cch~14ff0798a.htp
C:\DOCUME~1\Michele\IMPOST~1\Temp\vistasp1.exe.bat
C:\DOCUME~1\Michele\IMPOST~1\Temp\vistasp1.exe
C:\DOCUME~1\Michele\IMPOST~1\Temp\lwpwer.exe.bat
C:\DOCUME~1\Michele\IMPOST~1\Temp\lwpwer.exe
C:\DOCUME~1\Michele\IMPOST~1\Temp\s1265.php.bat
C:\DOCUME~1\Michele\IMPOST~1\Temp\bindsrv2.exe.bat
C:\DOCUME~1\Michele\IMPOST~1\Temp\bindsrv2.exe
C:\DOCUME~1\Michele\IMPOST~1\Temp\atmadm2.exe.bat
C:\DOCUME~1\Michele\IMPOST~1\Temp\atmadm2.exe
folders to delete:
C:\WINDOWS\privacy_danger
registry keys to delete:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\nnnnNheC
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{265E6540-2B95-4A81-9AF9-1456522F975B}
registry values to replace with dummy:
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\ShellExecuteHooks | {911551E5-4B0F-4021-BD18-A24F9E558A94}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ShellServiceObjectDelayLoad | eqvwamkl
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ShellServiceObjectDelayLoad | wnslvxtf
programs to launch on reboot:
c:\fix.reg