Files to delete:
c:\windows\system32\drivers\hwtdzomb.sys
c:\windows\system32\CF1468.exe
c:\windows\system32\config\systemprofile\Dati applicazioni\mxncqh.dat
c:\windows\system32\mswins.sys
c:\docume~1\Matteo\IMPOST~1\Temp\kwwalpgr.sys
Drivers to disable:
kwwalpgr
hwtdzomb
Registry keys to delete:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_kwwalpgr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_kwwalpgr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_kwwalpgr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_kwwalpgr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_kwwalpgr
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kwwalpgr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\kwwalpgr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\kwwalpgr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\kwwalpgr
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\kwwalpgr
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_hwtdzomb
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_hwtdzomb
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_hwtdzomb
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_hwtdzomb
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_hwtdzomb
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hwtdzomb
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\hwtdzomb
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\hwtdzomb
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\hwtdzomb
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\hwtdzomb