files to delete:
C:\WINDOWS\qdnkewfa.dll
C:\WINDOWS\system32\geBtSMfF.dll
C:\WINDOWS\system32\urqRjkjj.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\FfMStBeg.ini2
C:\WINDOWS\system32\FfMStBeg.ini
C:\WINDOWS\mgsvflkw.dll
C:\WINDOWS\temlxopqwsp.dll
registry values to delete:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ShellServiceObjectDelayLoad | mgsvflkw
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ShellServiceObjectDelayLoad | qdnkewfa
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\ShellExecuteHooks | {8E1BFC0E-8AD2-424D-AC8A-06038481516E}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects | {8E1BFC0E-8AD2-424D-AC8A-06038481516E}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects | {952A0FBE-E225-450F-A518-E55805DAF6AC}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects | {E29A5B8B-5242-49AE-A064-91E644F932CB}
registry keys to delete:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\urqRjkjj