registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs
files to delete:
C:\dnenvq.exe
C:\1752020416
C:\srkw.exe
C:\sqmdata07.sqm
C:\sqmdata08.sqm
C:\sqmnoopt07.sqm
C:\sqmnoopt08.sqm
C:\sqmdata05.sqm
C:\sqmnoopt05.sqm
C:\sqmnoopt06.sqm
C:\sqmdata04.sqm
C:\sqmdata06.sqm
C:\sqmnoopt04.sqm
C:\sqmdata03.sqm
C:\sqmnoopt03.sqm
C:\sqmnoopt02.sqm
C:\sqmdata02.sqm
C:\sqmnoopt01.sqm
C:\sqmdata01.sqm
C:\it1.exe
C:\jxbytp.exe
C:\it.exe
C:\d.exe
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\543009.tmp
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\839948.tmp
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\emp_03.exe
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\csrssc.exe
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\cznsbfi37uhbehj fgdf.tmp
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\2041070926.exe
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\veue873ikesg4t. tmp
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\winlogin.exe
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\removalfile.bat
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\removefiles.txt temp
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\jar_cache55598. tmp
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\jar_cache55599. tmp
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\jar_cache55596. tmp
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\jar_cache55597. tmp
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\h2r41A.tmp
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\r2h419.tmp
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\r2h416.tmp
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\h2r417.tmp
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\h2r414.tmp
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\r2h413.tmp
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\h2r411.tmp
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\r2h410.tmp
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\h2r40E.tmp
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\r2h40D.tmp
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\h2r40B.tmp
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\r2h40A.tmp
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\21102008(002).j pg
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\21102008(001).j pg
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\21102008.jpg
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\21092008.jpg
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\25082008(002).j pg
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\4007479794.exe
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\3511698544.exe
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\88664386.exe
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\654456530.exe
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\178519030.exe
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\1781669376.exe
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\....jpg
C:\DOCUME~1\giuseppe\IMPOST~1\Temp\chkpoi.dat
C:\WINDOWS\ewozebvf.exe
C:\WINDOWS\system32\rar.exe
C:\WINDOWS\system32\gh14rs.txt
C:\WINDOWS\system32\jsne87fidgf.dll
C:\WINDOWS\system32\wvUOFWPH.dll
C:\WINDOWS\system32\xxyxYsRh.dll
C:\WINDOWS\system32\jsne87fidgf.dll
C:\WINDOWS\system32\ddcBSLfF.dll
C:\WINDOWS\system32\1.exe
C:\WINDOWS\system32\pitovlhn.ini
C:\WINDOWS\system32\dpsbqm.dll
C:\WINDOWS\system32\dgfywvgi.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\634e7111-.txt
C:\WINDOWS\system32\wjnfokvw.ini
C:\WINDOWS\system32\hwsbibgm.dll
C:\WINDOWS\system32\wvkofnjw.dll
C:\WINDOWS\system32\ddcBSLfF.dll
C:\WINDOWS\system32\FfLSBcdd.ini
C:\WINDOWS\system32\FfLSBcdd.ini2
C:\WINDOWS\system32\drivers\ethzwnca.sys
C:\WINDOWS\system32\drivers\TDSSmxoe.sys
registry values to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\ShellExecuteHooks | {47080957-7903-41FC-B655-CEBA0A65E64A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\SharedTaskScheduler | {C5BF49A2-94F3-42BD-F434-3604812C897D}
registry keys to delete:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvUOFWPH
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{C5BF49A2-94F3-42BD-F434-3604812C897D}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{F69C7AE9-4DFD-48C1-B2D0-56D7B4AD707F}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{47080957-7903-41FC-B655-CEBA0A65E64A}
HKLM\system\currentcontrolset\services\ethzwnca
HKLM\system\controlset001\services\ethzwnca
HKLM\system\controlset002\services\ethzwnca
HKLM\system\currentcontrolset\enum\root\legacy_eth zwnca
HKLM\system\controlset001\enum\root\legacy_ethzwnc a
HKLM\system\controlset002\enum\root\legacy_ethzwnc a
HKLM\system\currentcontrolset\services\TDSSserv.sy s
HKLM\system\controlset001\services\TDSSserv.sys
HKLM\system\controlset002\services\TDSSserv.sys
HKLM\system\currentcontrolset\emun\root\legacy_TDS Sserv.sys
HKLM\system\controlset001\enum\root\legacy_TDSSser v.sys
HKLM\system\controlset002\enum\root\legacy_TDSSser v.sys