files to delete:
C:\fun.xls.exe
C:\AUTORUN.INF
C:\sqmdata07.sqm
C:\sqmnoopt07.sqm
C:\sqmdata08.sqm
C:\sqmnoopt08.sqm
C:\sqmnoopt09.sqm
C:\sqmdata09.sqm
C:\sqmnoopt10.sqm
C:\sqmdata10.sqm
C:\sqmdata11.sqm
C:\sqmnoopt11.sqm
C:\sqmnoopt12.sqm
C:\sqmdata12.sqm
C:\sqmdata13.sqm
C:\sqmnoopt13.sqm
C:\sqmdata14.sqm
C:\sqmnoopt14.sqm
C:\sqmdata15.sqm
C:\sqmnoopt15.sqm
C:\sqmdata16.sqm
C:\sqmnoopt16.sqm
C:\sqmdata17.sqm
C:\sqmnoopt17.sqm
C:\sqmnoopt18.sqm
C:\sqmdata18.sqm
C:\sqmnoopt19.sqm
C:\sqmdata19.sqm
C:\sqmnoopt01.sqm
C:\sqmdata01.sqm
C:\sqmdata02.sqm
C:\sqmnoopt02.sqm
C:\sqmdata03.sqm
C:\sqmnoopt03.sqm
C:\sqmdata04.sqm
C:\sqmnoopt04.sqm
C:\sqmnoopt05.sqm
C:\sqmdata05.sqm
C:\sqmdata06.sqm
C:\sqmnoopt06.sqm
C:\WINDOWS\4829031.exe
C:\WINDOWS\4921734.exe
C:\WINDOWS\4921828.exe
C:\WINDOWS\821312.exe
C:\WINDOWS\822562.exe
C:\WINDOWS\834234.exe
C:\WINDOWS\835046.exe
C:\WINDOWS\855062.exe
C:\WINDOWS\855265.exe
C:\WINDOWS\856687.exe
C:\WINDOWS\8835078.exe
C:\WINDOWS\8835281.exe
C:\WINDOWS\xml2u32h.dll
C:\WINDOWS\844750.exe
C:\WINDOWS\845968.exe
C:\WINDOWS\829187.exe
C:\WINDOWS\830046.exe
C:\WINDOWS\4855796.exe
C:\WINDOWS\4856937.exe
C:\WINDOWS\8891406.exe
C:\WINDOWS\8893046.exe
C:\WINDOWS\12903812.exe
C:\WINDOWS\12902812.exe
C:\WINDOWS\832468.exe
C:\WINDOWS\833281.exe
C:\WINDOWS\821046.exe
C:\WINDOWS\822203.exe
C:\WINDOWS\830562.exe
C:\WINDOWS\831750.exe
C:\WINDOWS\820312.exe
C:\WINDOWS\821203.exe
C:\WINDOWS\823968.exe
C:\WINDOWS\824781.exe
C:\WINDOWS\902656.exe
C:\WINDOWS\903875.exe
C:\WINDOWS\864375.exe
C:\WINDOWS\865046.exe
C:\WINDOWS\winsystem.exe
C:\WINDOWS\iTunesMusic.exe
C:\WINDOWS\bdn.com
C:\WINDOWS\base64.tmp
C:\WINDOWS\a.bat
C:\WINDOWS\mssecu.exe
C:\WINDOWS\FVProtect.exe
C:\WINDOWS\zip1.tmp
C:\WINDOWS\zip2.tmp
C:\WINDOWS\zip3.tmp
C:\WINDOWS\userconfig9x.dll
C:\WINDOWS\zipped.tmp
C:\WINDOWS\system32\msime82.exe
C:\WINDOWS\system32\msfun80.exe
C:\WINDOWS\system32\algsrvs.exe
C:\WINDOWS\system32\e2v93888.dll
C:\WINDOWS\system32\e2v93888.exe
C:\WINDOWS\system32\mx18114.dll
C:\WINDOWS\system32\mmx18114.dll
C:\WINDOWS\system32\mx17098.dll
C:\WINDOWS\system32\mmx17098.dll
C:\WINDOWS\system32\lphcljnj0el9e.exe
C:\WINDOWS\system32\noxulyny.exe
C:\WINDOWS\system32\ssurf022.dll
C:\WINDOWS\system32\ps1.exe
C:\WINDOWS\system32\regm64.dll
C:\WINDOWS\system32\regc64.dll
C:\WINDOWS\system32\psof1.exe
C:\WINDOWS\system32\sncntr.exe
C:\WINDOWS\system32\Rundl1.exe
C:\WINDOWS\system32\vbsys2.dll
C:\WINDOWS\system32\VBIEWER.OCX
C:\WINDOWS\system32\thun32.dll
C:\WINDOWS\system32\WINWGPX.EXE
C:\WINDOWS\system32\winsystem.exe
C:\WINDOWS\system32\vcatchpi.dll
C:\WINDOWS\system32\thun.dll
C:\WINDOWS\system32\sysreq.exe
C:\WINDOWS\system32\ssvchost.exe
C:\WINDOWS\system32\ssvchost.com
C:\WINDOWS\system32\temp#01.exe
C:\WINDOWS\system32\taack.exe
C:\WINDOWS\system32\taack.dat
C:\WINDOWS\system32\h@tkeysh@@k.dll
C:\WINDOWS\system32\emesx.dll
C:\WINDOWS\system32\hoproxy.dll
C:\WINDOWS\system32\hxiwlgpm.exe
C:\WINDOWS\system32\hxiwlgpm.dat
C:\WINDOWS\system32\dpcproxy.exe
C:\WINDOWS\system32\anticipator.dll
C:\WINDOWS\system32\akttzn.exe
C:\WINDOWS\system32\awtoolb.dll
C:\WINDOWS\system32\bsva-egihsg52.exe
C:\WINDOWS\system32\bdn.com
C:\WINDOWS\system32\medup012.dll
C:\WINDOWS\system32\mwin32.exe
C:\WINDOWS\system32\mtr2.exe
C:\WINDOWS\system32\newsd32.exe
C:\WINDOWS\system32\netode.exe
C:\WINDOWS\system32\msvchost.exe
C:\WINDOWS\system32\msnbho.dll
C:\WINDOWS\system32\msgp.exe
C:\WINDOWS\system32\medup020.dll
C:\WINDOWS\system32\mssecu.exe
C:\WINDOWS\system32\winlogonpc.exe
C:\WINDOWS\system32\phcljnj0el9e.bmp
C:\WINDOWS\system32\blphcljnj0el9e.scr
C:\DOCUME~1\pc\IMPOST~1\Temp\.tt2.tmp
C:\DOCUME~1\pc\IMPOST~1\Temp\.tt2.tmp.vbs
C:\DOCUME~1\pc\IMPOST~1\Temp\.tt5.tmp.exe
C:\DOCUME~1\pc\IMPOST~1\Temp\.tt5.tmp
C:\DOCUME~1\pc\IMPOST~1\Temp\.tt4.tmp.vbs
C:\DOCUME~1\pc\IMPOST~1\Temp\.tt4.tmp
C:\DOCUME~1\pc\IMPOST~1\Temp\.tt7.tmp
C:\DOCUME~1\pc\IMPOST~1\Temp\.tt6.tmp
C:\DOCUME~1\pc\IMPOST~1\Temp\.tt6.tmp.vbs
C:\DOCUME~1\pc\IMPOST~1\Temp\.ttA.tmp
C:\DOCUME~1\pc\IMPOST~1\Temp\.tt8.tmp.vbs
C:\DOCUME~1\pc\IMPOST~1\Temp\.tt8.tmp
C:\DOCUME~1\pc\IMPOST~1\Temp\.ttB.tmp
C:\Documents and Settings\pc\Impostazioni locali\Temp\.tt5.tmp.exe
C:\WINDOWS\system32\spoolw.exe
C:\WINDOWS\system32\igfxsvc.exe
C:\Documents and Settings\All Users\Dati applicazioni\jopkjivs\pwtsrspe.exe
C:\Programmi\syxnguc\ensetui.dll
C:\WINDOWS\iexplore_32.exe
C:\WINDOWS\w32dbg.exe
C:\Programmi\KB09103.exe
C:\Programmi\KB26249.exe
C:\Programmi\altcmd\altcmd32.dll
folders to delete:
C:\WINDOWS\system32\smp
C:\WINDOWS\mslagent
C:\Programmi\syxnguc
C:\Programmi\akl
C:\Documents and Settings\All Users\Dati applicazioni\jopkjivs
C:\Programmi\altcmd
C:\Programmi\Inet Delivery
registry values to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | IMJPMIG8.2
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | lphcljnj0el9e
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | inrhcgjnj0el9e
HKLM\Software\Microsoft\Windows\CurrentVersion\pol icies\Explorer\Run | v32cEItW4I
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ShellServiceObjectDelayLoad | ensetui
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ShellServiceObjectDelayLoad | E2 Lib
registry keys to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{32131238-5434-4234-4234-432432423432}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{3BB7B7BC-42BB-3396-877C-5D3CFD5B0007}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{72A128E0-2240-40c8-9E92-5387D64F839E}
programs to launch on reboot:
c:\fix.reg