files to delete:
C:\WINDOWS\system32\byxurrs.dll
C:\WINDOWS\system32\rjqolcfl.dll
C:\WINDOWS\system32\vtsqp.dll
C:\WINDOWS\system32\jmndcgaj.dll
C:\WINDOWS\system32\iqaergfi.dll
C:\WINDOWS\system32\spoolw.exe
C:\WINDOWS\system32\igfxsvc.exe
C:\WINDOWS\SYSTEM32\byxurrs.dll
C:\WINDOWS\SYSTEM32\rjqolcfl.dll
C:\WINDOWS\SYSTEM32\winepi32.dll
C:\WINDOWS\SYSTEM32\winmbj32.dll
C:\WINDOWS\winepi32.dll
C:\WINDOWS\winmbj32.dll
registry keys to delete:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\byxurrs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rjqolcfl
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winepi32
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winmbj32
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{89A1E40D-0254-4F99-B9AE-B60A2D8754A9}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKLM\Software\Microsoft\Windows\CurrentVersion\Exp lorer\Browser Helper Objects\{E7A0BC06-99F4-4E2D-A0C1-C5CF41162E73}
Registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs