folders to delete:
C:\DOCUME~1\Mauro\IMPOST~1\Temp\Rar$DR06.703
C:\DOCUME~1\Mauro\IMPOST~1\Temp\Rar$DR05.078
files to delete:
C:\DOCUME~1\Mauro\IMPOST~1\Temp\_A00F29BE28.exe
C:\DOCUME~1\Mauro\IMPOST~1\Temp\wJQs.exe
C:\WINDOWS\system32\__c00A4439.exe
C:\WINDOWS\system32\__c00D4691.dat
C:\WINDOWS\system32\__c0072EE.exe
C:\WINDOWS\system32\__c00DC589.exe
C:\WINDOWS\system32\__c009A88A.exe
C:\WINDOWS\system32\wpv161234083759.cpx
C:\WINDOWS\system32\wpv431236443041.cpx
C:\WINDOWS\system32\digeste.dll
C:\WINDOWS\system32\trz379.tmp
C:\WINDOWS\system32\__c00E8012.exe
C:\WINDOWS\temp\BN1D0.tmp
C:\WINDOWS\temp\BNB8.tmp
C:\WINDOWS\temp\BN2.tmp
C:\WINDOWS\Tgazusasiyuw.dll
C:\Documents and Settings\Mauro\Mauro.exe
C:\DOCUME~1\Mauro\IMPOST~1\Temp\_A00F29BE28.exe
C:\WINDOWS\system32\__c00D4691.dat
c:\WINDOWS\system32\winwil32.DLL
c:\windows\system32\hafgxbh.dll
C:\WINDOWS\temp\taozjazq.ini
registry values to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | Svaru
registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | System
registry keys to delete:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ceyjzqtp
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c00D4691
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winwil32
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\\{6A676AA3-2B43-401A-95E1-82098D2C04AB}
HKLM\system\currentcontrolset\services\typcubka
HKLM\system\controlset001\services\typcubka
HKLM\system\controlset002\services\typcubka
HKLM\system\currentcontrolset\enum\root\legacy_typ cubka
HKLM\system\controlset001\enum\root\legacy_typcubk a
HKLM\system\controlset002\enum\root\legacy_typcubk a