files to delete:
C:\DOCUME~1\MILENA~1\IMPOST~1\Temp\no.gif
C:\DOCUME~1\MILENA~1\IMPOST~1\Temp\yes.gif
C:\DOCUME~1\MILENA~1\IMPOST~1\Temp\2.gif
C:\DOCUME~1\MILENA~1\IMPOST~1\Temp\4.gif
C:\DOCUME~1\MILENA~1\IMPOST~1\Temp\3.gif
C:\DOCUME~1\MILENA~1\IMPOST~1\Temp\1.gif
C:\DOCUME~1\MILENA~1\IMPOST~1\Temp\6.gif
C:\DOCUME~1\MILENA~1\IMPOST~1\Temp\5.gif
C:\DOCUME~1\MILENA~1\IMPOST~1\Temp\7.gif
C:\DOCUME~1\MILENA~1\IMPOST~1\Temp\8.gif
C:\DOCUME~1\MILENA~1\IMPOST~1\Temp\9.gif
C:\WINDOWS\system32\wpv301236698933.cpx.exe
C:\WINDOWS\system32\drivers\82aa79ea.sys
C:\WINDOWS\system32\emqsys.dll
C:\WINDOWS\temp\CA757295.exe
C:\WINDOWS\temp\98B3EB78.exe
C:\WINDOWS\temp\FE3C1040.exe
C:\WINDOWS\temp\5FA824E9.exe
C:\WINDOWS\temp\3EA22447.exe
C:\WINDOWS\temp\0F4F87CB.exe
C:\WINDOWS\temp\24382590.exe
C:\WINDOWS\temp\1D8B5688.exe
C:\WINDOWS\temp\2F9242D5.exe
C:\WINDOWS\temp\DF3780AF.exe
C:\WINDOWS\TEMP\2F9242D5.exe
registry values to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | 31107
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | wmagent.exe
registry keys to delete:
HKEY_LOCAL_MACHINE\system\controlset003\services\8 2aa79ea
HKEY_LOCAL_MACHINE\system\controlset002\services\8 2aa79ea
HKEY_LOCAL_MACHINE\system\controlset001\services\8 2aa79ea
HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\82aa79ea
HKEY_LOCAL_MACHINE\system\controlset003\enum\root\ legacy_82aa79ea
HKEY_LOCAL_MACHINE\system\controlset002\enum\root\ legacy_82aa79ea
HKEY_LOCAL_MACHINE\system\controlset001\enum\root\ legacy_82aa79ea
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\r oot\legacy_82aa79ea