files to delete:
C:\WINDOWS\system32\VDJTEfhk.ini
C:\WINDOWS\system32\VDJTEfhk.ini2
C:\WINDOWS\system32\rXxHOXbc.ini
C:\WINDOWS\system32\rXxHOXbc.ini2
C:\WINDOWS\system32\ycJPoXbc.ini
C:\WINDOWS\system32\ycJPoXbc.ini2
C:\WINDOWS\system32\vobkhqmb.ini
C:\WINDOWS\system32\YcJjPXbc.ini
C:\WINDOWS\system32\YcJjPXbc.ini2
C:\WINDOWS\system32\mjllnplf.ini
C:\WINDOWS\system32\OUtDNqss.ini
C:\WINDOWS\system32\OUtDNqss.ini2
C:\WINDOWS\system32\a3f8f0ee-.txt
C:\WINDOWS\system32\dJkTwGgh.ini
C:\WINDOWS\system32\dJkTwGgh.ini2
C:\DOCUME~1\Cecilia\IMPOST~1\Temp\STS7.tmp
C:\DOCUME~1\Cecilia\IMPOST~1\Temp\DIO4.tmp
C:\DOCUME~1\Cecilia\IMPOST~1\Temp\MAR3.tmp
C:\DOCUME~1\Cecilia\IMPOST~1\Temp\DIO7.tmp
C:\DOCUME~1\Cecilia\IMPOST~1\Temp\STS6.tmp
C:\DOCUME~1\Cecilia\IMPOST~1\Temp\DIO3.tmp
C:\DOCUME~1\Cecilia\IMPOST~1\Temp\MAR2.tmp
C:\DOCUME~1\Cecilia\IMPOST~1\Temp\STS4.tmp
C:\DOCUME~1\Cecilia\IMPOST~1\Temp\DIO2.tmp
C:\DOCUME~1\Cecilia\IMPOST~1\Temp\MAR1.tmp
C:\DOCUME~1\Cecilia\IMPOST~1\Temp\DIO5.tmp
C:\DOCUME~1\Cecilia\IMPOST~1\Temp\MAR4.tmp
C:\DOCUME~1\Cecilia\IMPOST~1\Temp\STSA.tmp
C:\DOCUME~1\Cecilia\IMPOST~1\Temp\DIO6.tmp
C:\DOCUME~1\Cecilia\IMPOST~1\Temp\MAR5.tmp
C:\DOCUME~1\Cecilia\IMPOST~1\Temp\STS9.tmp
C:\WINDOWS\system32\sagg.exe
registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs
registry keys to delete:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbXrQhFx
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ddcBQhiI
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\efcBtrOh
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\geBspppp
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\geBtRiGY
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkkIYpnO
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\khfDwxvV
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\qoMccCtR
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rqRKeEuv
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\yayXOiGX
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\yayYpqoM