File::
C:\WINDOWS\yotk.exe
C:\WINDOWS\ktlu.exe
C:\WINDOWS\vymp.exe
C:\WINDOWS\system32\rmfw22.exe
C:\WINDOWS\ziio.exe
C:\WINDOWS\system32\dgkd0.exe
C:\WINDOWS\system32\womsoy.dll
C:\WINDOWS\system32\womsoyk.exe
C:\WINDOWS\system32\ngjxakin.sys
C:\WINDOWS\system32\ijzhatde.sys
C:\WINDOWS\system32\yzztkmsn.dll
C:\WINDOWS\system32\apsggjba.dll
C:\WINDOWS\system32\tjfyabyt.exe
C:\WINDOWS\system32\lpzhatde.exe
C:\WINDOWS\system32\opshcbty.dll
C:\WINDOWS\system32\apzhctde.dll
C:\WINDOWS\system32\dfqnabib.exe
C:\WINDOWS\system32\mndshsrv.dll
C:\WINDOWS\system32\snfybbyt.sys
C:\WINDOWS\system32\gpzhatde.sys
C:\WINDOWS\system32\erjxakin.sys
C:\WINDOWS\system32\aoqnabib.sys
C:\WINDOWS\system32\smdsbsrv.sys
C:\WINDOWS\system32\zxmsdwin.dll
C:\WINDOWS\system32\gjcwptw.dll
C:\WINDOWS\system32\skqncbib.dll
C:\WINDOWS\system32\zptlcsys.dll
C:\WINDOWS\system32\pjjxedwd.dll
C:\WINDOWS\system32\mpwdeapi.dll
C:\WINDOWS\system32\ozfyebyt.dll
C:\WINDOWS\system32\mndshsrv.dll
C:\WINDOWS\system32\s2da2f323.dll
Folder::
C:\Program Files\Ipwindows
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{15E0A74E-30FD-6E54-A349-6BE33DE5FCE8}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{32023698-6984-8541-9654-698745012523}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{32596546-2036-9451-6058-658402589723}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{35671234-7890-ABCD-CDEF-567801237653}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3D698451-2015-6358-9871-2015987452D3}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{43512378-9874-5641-1025-985420368734}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{50940F85-F015-14F1-A05F-F69858AC6D05}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54FAE856-AD58-20CB-A025-CD4895FA6E45}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{55694105-5108-9405-3695-954187462155}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5A069845-2036-6084-9054-6087502480A5}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7A041F13-A111-12A3-B0CF-F99818AA68A7}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{87FD640A-158F-48AC-FD14-1597F14A9778}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A629FF4F-ACDB-5C90-A098-FACB3456A26A}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B490415F-65F8-B5C5-D8BA-9405FB12054B}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"IpWins"=-
[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\shellexecutehooks]
"{B490415F-65F8-B5C5-D8BA-9405FB12054B}"=-
"{55694105-5108-9405-3695-954187462155}"=-
"{7C8D1401-A58D-A81C-CD24-A5915C4517C7}"=-
"{5A069845-2036-6084-9054-6087502480A5}"=-
"{32596546-2036-9451-6058-658402589723}"=-
"{7A041F13-A111-12A3-B0CF-F99818AA68A7}"=-
"{3D698451-2015-6358-9871-2015987452D3}"=-
"{A629FF4F-ACDB-5C90-A098-FACB3456A26A}"=-
"{32023698-6984-8541-9654-698745012523}"=-
"{7FD45A54-9875-698F-E56E-65102358FDF7}"=-
"{87FD640A-158F-48AC-FD14-1597F14A9778}"=-
"{54FAE856-AD58-20CB-A025-CD4895FA6E45}"=-
"{35671234-7890-ABCD-CDEF-567801237653}"=-
"{43512378-9874-5641-1025-985420368734}"=-
"{50940F85-F015-14F1-A05F-F69858AC6D05}"=-