files to delete:
C:\WINDOWS\system32\GjRrAcdd.ini
C:\WINDOWS\system32\GjRrAcdd.ini2
C:\WINDOWS\system32\lwrusxqp.ini
C:\WINDOWS\system32\pqxsurwl.dll
C:\WINDOWS\system32\oubvuj.dll
C:\WINDOWS\system32\savpxieq.dll
C:\WINDOWS\system32\83651f3d-.txt
C:\WINDOWS\system32\nzzltt.dll
C:\WINDOWS\system32\gfllbeai.dll
C:\WINDOWS\system32\zbbwwu.dll
C:\WINDOWS\system32\tmxmnylc.dll
C:\WINDOWS\system32\pybxkgtq.ini
C:\WINDOWS\system32\qtgkxbyp.dll
C:\WINDOWS\system32\rovhvupc.ini
C:\WINDOWS\system32\cpuvhvor.dll
C:\WINDOWS\system32\fxdaxori.ini
C:\WINDOWS\system32\iroxadxf.dll
C:\WINDOWS\system32\jfgfbe.dll
C:\WINDOWS\system32\xkyolffj.dll
C:\WINDOWS\system32\lvjarmev.ini
C:\WINDOWS\system32\mrjcxv.dll
C:\WINDOWS\system32\fnuejmtf.dll
C:\WINDOWS\system32\vrteiiok.ini
C:\WINDOWS\system32\koiietrv.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\xdeguvys.ini
C:\WINDOWS\system32\syvugedx.dll
C:\WINDOWS\system32\oohqwd.dll
C:\WINDOWS\system32\yuhgdmdl.dll
C:\WINDOWS\system32\umabrxie.ini
C:\WINDOWS\system32\eixrbamu.dll
C:\WINDOWS\system32\hgdzbm.dll
C:\WINDOWS\system32\oxbelryv.dll
C:\WINDOWS\system32\riyoyvrc.ini
C:\WINDOWS\system32\pyqvja.dll
C:\WINDOWS\system32\slroojlh.ini
C:\WINDOWS\system32\mldfxm.dll
C:\WINDOWS\system32\ddcArRjG.dll
C:\WINDOWS\system32\jkkJyYqn.dll
C:\WINDOWS\System32\jkkJyYqn.dll
C:\WINDOWS\System32\uktwtfps.dll
C:\WINDOWS\System32\ddcArRjG.dll
C:\WINDOWS\System32\jkkJyYqn.dll
C:\WINDOWS\System32\oubvuj.dll
registry values to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\ShellExecuteHooks | {B0B3393C-62D1-44D8-ABF5-08E0F067F29E}
registry keys to delete:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkkJyYqn
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{01727D36-EF6D-47CA-A063-03FF25BCBA46}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{0990E89B-7FBE-413E-B992-24D70FCBE614}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{0921139F-49B4-4B6A-9394-D4FF027E74B9}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{28F62842-CBFA-45E3-9D5E-694C312C1A07}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{4C805996-5C9D-4657-B5EF-4E06AE2F98FB}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{4EF686F0-1DB7-4F6B-B841-083C2AAD6A77}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{5F27E264-2704-41CD-B3C0-D1512C219E57}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{98FD985C-0759-43B1-9973-2CDDDE3BCA64}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{9FBA159A-DB4C-4656-B699-F1518B322A61}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{B072886D-8544-4C54-80AA-C7CB20F2974F}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{B0B3393C-62D1-44D8-ABF5-08E0F067F29E}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{52d2a7da-f56e-4358-a6d2-300b6b50d064}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{CBA99539-287D-4C13-87A0-D3B6A0478FAC}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{F00E989E-5167-4B43-9539-CB75C2B1ADD8}