files to delete:
C:\WINDOWS\system32\wertyu.dll
C:\WINDOWS\system32\av.exe
C:\WINDOWS\system32\getwn32.dll
C:\WINDOWS\Clc1200e.INI
C:\WINDOWS\system32\drivers\TDSSmqlt.sys
registry keys to delete:
HKLM\system\currentcontrolset\services\TDSSserv.sy s
HKLM\system\controlset001\services\TDSSserv.sys
HKLM\system\controlset002\services\TDSSserv.sys
registry values to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | svchost.exe
registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | System