files to delete:
C:\WINDOWS\tasks\avtqnbkw.job
C:\DOCUME~1\PORTAT~1\IMPOST~1\Temp\pmnlmkKC.bat
C:\WINDOWS\kjayowrw
C:\WINDOWS\system32\TsYHOXbc.ini
C:\WINDOWS\system32\TsYHOXbc.ini2
C:\WINDOWS\system32\2cbba61a-.txt
C:\WINDOWS\system32\owkhecej.ini
C:\WINDOWS\system32\iqplyh.dll
C:\WINDOWS\system32\cpabrdiw.dll
C:\WINDOWS\system32\jecehkwo.dll
C:\WINDOWS\system32\cbXOHYsT.dll
C:\WINDOWS\system32\ssqQhgde.dll
C:\WINDOWS\system32\qoMdDtsT.dll
C:\WINDOWS\system32\drivers\phqghume.sys
C:\WINDOWS\system32\drivers\bkeymzcr.sys
C:\WINDOWS\temp\TMP9.exe
C:\WINDOWS\temp\TMP9.tmp
C:\Documents and Settings\Portatile\Impostazioni locali\Dati applicazioni\ukmousi_navps.dat
C:\Documents and Settings\Portatile\Impostazioni locali\Dati applicazioni\ukmousi.dat
C:\Documents and Settings\Portatile\Impostazioni locali\Dati applicazioni\ukmousi_nav.dat
C:\Documents and Settings\Portatile\Impostazioni locali\Dati applicazioni\ukmousi.exe
registry values to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | 27986264
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\ShellExecuteHooks | {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
registry keys to delete:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\qoMdDtsT
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{1365fdc6-d2de-4012-a6bf-234dccfe5f23}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{B0F08A9B-89E5-4001-ABDF-F65B2137640D}
HKLM\system\currentcontrolset\services\aylnlfdx
HKLM\system\controlset001\services\aylnlfdx
HKLM\system\controlset002\services\aylnlfdx
HKLM\system\currentcontrolset\enum\root\legacy_ayl nlfdx
HKLM\system\controlset001\enum\root\legacy_aylnlfd x
HKLM\system\controlset002\enum\root\legacy_aylnlfd x
HKLM\system\currentcontrolset\services\kjayowrw
HKLM\system\controlset001\services\kjayowrw
HKLM\system\controlset002\services\kjayowrw
HKLM\system\currentcontrolset\enum\root\legacy_kja yowrw
HKLM\system\controlset001\enum\root\legacy_kjayowr w
HKLM\system\controlset002\enum\root\legacy_kjayowr w