Files to delete:
C:\WINDOWS\system32\xukrmyo.dll
C:\DOCUME~1\FRANCE~1\IMPOST~1\Temp\~tmpb.exe
C:\DOCUME~1\FRANCE~1\IMPOST~1\Temp\a.exe
C:\WINDOWS\system32\vpc32.exe
Folders to delete:
C:\Programmi\ClamWin
C:\VIRUSfighter
C:\Programmi\Zango
C:\Programmi\ShoppingReport
registry keys to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{37B85A21-692B-4205-9CAD-2626E4993404}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{07AA283A-43D7-4CBE-A064-32A21112D94D}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{100EB1FD-D03E-47FD-81F3-EE91287F9465}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{F6104497-54FD-4688-9162-5115CC8AB0FB}
files to move:
C:\Programmi\Medion\PowerVCR II\bak\Agent.exe | C:\Programmi\Medion\PowerVCR II\Agent.exe
C:\Programmi\MUSICMATCH\MUSICMATCH Jukebox\bak\mmtask.exe | C:\Programmi\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Programmi\MUSICMATCH\MUSICMATCH Jukebox\bak\mm_tray.exe | C:\Programmi\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Programmi\QuickTime\bak\qttask.exe | C:\Programmi\QuickTime\qttask.exe
C:\WINDOWS\system32\bak\ctfmon.exe | C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\bak\NeroCheck.exe | C:\WINDOWS\system32\NeroCheck.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\E_F ATIAIE.EXE | C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATIA IE.EXE