files to delete:
C:\WINDOWS\cookies.ini
C:\WINDOWS\BM2fc1aa80.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\BM2fc1aa80.txt
C:\WINDOWS\system32\geBtQIYQ.dll
C:\WINDOWS\system32\ddcBTNGy.dll
C:\WINDOWS\system32\xygrabkq.dll
C:\WINDOWS\system32\qkbargyx.ini
C:\WINDOWS\system32\gjaoclgm.ini
C:\WINDOWS\system32\nrcqcxfc.dll
C:\WINDOWS\system32\sdifuxsg.dll
C:\WINDOWS\system32\gsxufids.ini
C:\WINDOWS\system32\oyvglorc.dll
C:\WINDOWS\system32\crolgvyo.ini
C:\WINDOWS\system32\nqvlumdt.dll
C:\WINDOWS\system32\nixwjohg.dll
C:\WINDOWS\system32\ghojwxin.ini
C:\WINDOWS\system32\tdguybuo.dll
C:\WINDOWS\system32\oubyugdt.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\27d15d62-.txt
C:\WINDOWS\system32\QYIQtBeg.ini2
C:\WINDOWS\system32\QYIQtBeg.ini
C:\DOCUME~1\chiara\IMPOST~1\Temp\wavvsnet.exe
C:\DOCUME~1\chiara\IMPOST~1\Temp\rasesnet.exe
folders to delete:
C:\WINDOWS\system32\drivers\downld
registry keys to delete:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinlogonNotify\ddcBTNGy
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{3FFE90FB-0431-4ED5-AF76-8BF8AE7E0B35}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{A2E1BDD4-95FA-4D8B-BFB9-EFBB4F647C9D}
registry values to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\ShellExecuteHooks | {3FFE90FB-0431-4ED5-AF76-8BF8AE7E0B35}
programs to launch on reboot:
c:\fix.reg