Apuva! Spyaxe-ohjelma ei jätä rauhaan. Pyydän nöyrimmästi apua (mahd. yksinkertaisesti selitettynä, olen amatööri). HJT-logi tässä: Logfile of HijackThis v1.99.1 Scan saved at 18:13:04, on 29.12.2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Norman\Nvc\BIN\NPFSVICE.EXE C:\Norman\bin\ZANDA.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\wdfmgr.exe C:\Norman\Nvc\BIN\NVCSCHED.EXE C:\Norman\Nvc\BIN\nipsvc.exe C:\Norman\bin\NJEEVES.EXE C:\Norman\Nvc\bin\nvcoas.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\nvctrl.exe C:\WINDOWS\system32\mssearchnet.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Norman\bin\ZLH.EXE C:\Program Files\Microsoft AntiSpyware\gcasServ.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Norman\Nvc\BIN\NIP.EXE C:\Norman\Nvc\bin\cclaw.exe C:\Norman\Npf\BIN\npfmsg2.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\Program Files\Internet Explorer\iexplore.exe C:\DOCUME~1\Eero\LOCALS~1\Temp\Tilapäinen kansio 3 hijackthis.zip\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.utu.fi/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.utu.fi/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O2 - BHO: (no name) - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hpEFAF.tmp (file missing) O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll (file missing) O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1121071860546 O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE O23 - Service: Norman Type-R - Unknown owner - C:\Norman\Nvc\BIN\NPFSVICE.EXE O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\bin\ZANDA.EXE O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Siirrä HjT omaan hakemistoonsa -> c:\hjt\HijackThis.exe Fixaa HjT:llä (do a system scan only, merkkaa ja paina fix checked): O2 - BHO: (no name) - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hpEFAF.tmp (file missing) O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll (file missing) Hae smitrem täältä -> http://noahdfear.geekstogo.com/click counter/click.php?id=1 Tallenna työpöydälle ja tuplaklikkaa sitä, jolloin se luo smitRem-kansion työpöydälle. Käynnistä vikasietotilaan (paina F8 käynnistyksen yhteydessä, kunnes tulee valikko. Valitse valikosta vikasietotila), avaa smitRem-kansio ja tuplaklikkaa RunThis.bat. Seuraa ohjeita. Käynnistä kone uudestaan, lähetä uusi HjT-loki ja c:\smitfiles.txt-tiedoston sisältö.
En ole aivan varma, pääsinkö siihen vikasietotilaan. Konetta käynnistettäessä painoin F8:a ja ruutuun tuli: "Please select boot device: SM-HL-DT-ST DVD-RW GWA-4163B PM-SAMSUNG SP1604N ESC to boot using defaults" Ja aina sen jälkeen kone aukeaa ihan normaalisti. Niin että millaiselta sen vikasietotilan kuuluisi näyttää? Smitrem haettu, eikä se RunThis.bat näytä tekevän mitään. Sen muistio näyttää tältä: @echo off VER|find "Windows 2000">NUL IF NOT ERRORLEVEL 1 GOTO notice VER|find "Windows XP">NUL IF NOT ERRORLEVEL 1 GOTO notice VER|find "Windows 95">NUL IF NOT ERRORLEVEL 1 GOTO notice1 VER|find "Windows 98">NUL IF NOT ERRORLEVEL 1 GOTO notice1 VER|find "Windows Millennium">NUL IF NOT ERRORLEVEL 1 GOTO notice1 VER|find "Windows 2003">NUL IF NOT ERRORLEVEL 1 GOTO notice echo Unsupported Version goto end :notice color 1F cls @echo off echo. echo. echo. echo ÉÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ» echo º º echo º Trojan-Spy.HTML.smitfraud.c Killer º echo º º echo º by noahdfear º echo º º echo º version 2.8 © º echo º º echo ÈÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍͼ echo. echo This tool was tailored to remove smitfraud.c and variants echo. echo If you do not trust the source, close this window. echo. echo noahdfear does not assume any liability echo. echo for damage or loss from running this tool echo. echo Use at your own risk!! echo. echo. echo. echo. pause cls @echo off echo. echo. echo This tool will also clean out the contents of temp folders echo. echo and the Prefetch folder. It will also run disk cleanup echo. echo to clear the Temporary Internet Files on this user profile, echo. echo as well as empty the recycle bin. echo. echo. echo. echo. pause cls GOTO menu2 :notice1 cls @echo off echo. echo. echo. echo ÉÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ» echo º º echo º Trojan-Spy.HTML.smitfraud.c Killer º echo º º echo º by noahdfear º echo º º echo º version 2.8 © º echo º º echo ÈÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍͼ echo. echo This tool was tailored to remove smitfraud.c and variants echo. echo If you do not trust the source, close this window. echo. echo noahdfear does not assume any liability echo. echo for damage or loss from running this tool echo. echo Use at your own risk!! echo. echo Press 1 to continue or E to exit echo. echo. echo. echo. CHOICE /C:1E /N IF errorlevel==2 GOTO done IF errorlevel==1 GOTO menu3 cls :menu3 cls @echo off echo. echo. echo This tool will also clean out the contents of temp folders. echo. echo It will also run disk cleanup to clear the Temporary Internet Files echo. echo as well as empty the recycle bin echo. echo. echo Press 1 to continue or E to exit echo. echo. echo. echo. CHOICE /C:1E /N IF errorlevel==2 GOTO done IF errorlevel==1 GOTO menu2 cls :menu2 cls @echo off VER|find "Windows 2000">NUL IF NOT ERRORLEVEL 1 GOTO NT VER|find "Windows XP">NUL IF NOT ERRORLEVEL 1 GOTO NT VER|find "Windows 95">NUL IF NOT ERRORLEVEL 1 GOTO win VER|find "Windows 98">NUL IF NOT ERRORLEVEL 1 GOTO win VER|find "Windows Millennium">NUL IF NOT ERRORLEVEL 1 GOTO win VER|find "Windows 2003">NUL IF NOT ERRORLEVEL 1 GOTO NT :NT cls @echo off echo. echo. echo Please close ALL windows except this one echo. echo including the folder you opened to run this tool echo. echo Your desktop and taskbar will disappear when you press a key echo. echo this window will remain open and others may open. echo. echo During this time the bad files will be deleted echo. echo When your desktop returns, echo. echo continue as instructed by your advisor. echo. echo Your desktop background will be reset to blue when you reboot. echo. echo. echo. echo. echo. pause IF EXIST %systemdrive%\LTD.txt del %systemdrive%\LTD.txt IF EXIST %systemdrive%\PSGuard.txt del %systemdrive%\PSGuard.txt cls @echo off IF EXIST %systemdrive%\smitfiles.txt del %systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo smitRem © log file>>%systemdrive%\smitfiles.txt echo version 2.8>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo by noahdfear>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt VER>>%systemdrive%\smitfiles.txt echo. |date |find "current" >>%systemdrive%\smitfiles.txt echo. |time |find "current" >>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>%systemdrive%\smitfiles.txt cls @echo off echo.>>%systemdrive%\smitfiles.txt echo checking for ShudderLTD key>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt regedit.exe /e %systemdrive%\LTD.txt "HKEY_LOCAL_MACHINE\SOFTWARE\SHUDDERLTD" IF EXIST %systemdrive%\LTD.txt echo ShudderLTD key present!>>%systemdrive%\smitfiles.txt IF NOT EXIST %systemdrive%\LTD.txt echo ShudderLTD key not present!>>%systemdrive%\smitfiles.txt IF EXIST %systemdrive%\LTD.txt GOTO LTDFix IF NOT EXIST %systemdrive%\LTD.txt GOTO psgcheck :LTDFix cls @echo off echo.>>%systemdrive%\smitfiles.txt echo Running LTDFix/PSGuard.com fix!>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo checking for PSGuard.com key>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt regedit.exe /e %systemdrive%\PSGuard.txt "HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com" IF EXIST %systemdrive%\PSGuard.txt echo PSGuard.com key present!>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF NOT EXIST %systemdrive%\PSGuard.txt echo PSGuard.com key not present!>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt cls @echo off echo.>>%systemdrive%\smitfiles.txt echo. echo. echo SmitRem © add-on ShudderLTD/PSGuard.com registry Fix echo. echo by Miekiemoes, Atribune and noahdfear echo. echo. echo. echo. pause cls @echo off echo REGEDIT4>>C:\psguardrem.reg echo.>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.FoundCollection]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.FoundCollection.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.FoundObject]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.FoundObject.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.KilledProcessesCollection]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.KilledProcessesCollection.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.KilledProcessInfo]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.KilledProcessInfo.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.License]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.License.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.Options]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.Options.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.Quarantine]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.Quarantine.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.RealTime]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.RealTime.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.RTObject]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.RTObject.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.SafeMode]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.SafeMode.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.Scaner]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.Scaner.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.ScanStatistic]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.ScanStatistic.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.theApp]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.theApp.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.Update]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.Update.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.UpdateInfo]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.UpdateInfo.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.VersionInfo]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.VersionInfo.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\WndLayer.Window]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\WndLayer.Window.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\WndLayer.WindowCollection]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\WndLayer.WindowCollection.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\WndLayer.WindowLayer]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\WndLayer.WindowLayer.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{F880B4F2-75BF-44EC-B7AA-45EC37448027}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{E479197F-49E5-4E60-9FA2-A71D4C7C2BBC}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{E12AAACF-8AF2-4C31-BA94-E3787B44F90E}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{D25F7446-4D36-4203-9EA5-5422B26FA9D0}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{CDD964C2-FB78-4A74-BB1E-1CB1FCB72018}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{CBE4B748-08F9-44DB-8FB1-9AD25979DA35}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{C5B70256-5B08-4056-B84E-C6CE084967F5}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{ACC647EE-991A-4811-B420-F063F50CDDC1}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{8DCA6B3D-1FCA-4500-B210-76119BB5C69E}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{8C2A05C5-780F-4A2E-AE1C-FB8181F860E4}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{82847700-FE61-46A3-B3EE-761A1E312ACA}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{7198F8DA-012C-4DB4-ABD8-923A54C87900}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{67196B3E-55A0-49DE-BA11-66F07DF804DB}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{5E5A79A6-C67B-444E-BE58-BD0ACEFCDA07}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{58E68548-42E2-479D-A9E0-86D9F2EAF02E}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{5206DF89-97FC-41AD-BAE3-993E87053A99}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{4F93062D-7BDA-48BE-AEB6-88AF2B1FE2D4}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{4AA55E8C-2C19-4F3A-91EC-43B6DF937C4F}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{41D7BB0A-64E0-4AB2-BD0B-69EA78E462E8}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{0EA04667-E53B-4E81-8E7C-DE2CA114CBD6}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{3946A33D-BBC6-4792-A383-D855E0F76D91}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{265C2AF8-C94C-4AFF-B2B6-340D3982562C}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{0878F045-B52E-46B3-9724-D3AE69D50067}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{04F3168F-5AFC-4531-B3B4-16CA93720415}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{187A8428-BD94-470D-A178-A2347F940519}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{2865930B-4588-4FF3-8227-6D4F66C92C7A}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{2FE2EDC0-9E62-4F34-8A73-BC66DAE48EF3}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{3A3A8C24-8FF0-4140-9731-54D9483EA70B}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{3A906593-B4BD-48ED-84B0-3249BED65EF9}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{49B72A72-01F5-4AE8-BBD7-DAA67F1E303B}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{6AE3ACA6-1BE3-4443-98DD-EFFCFA793D35}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{9F89E240-06A6-4E1C-BA84-F267DE7DB391}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{79DDF2EF-D881-464B-B2AF-5AF8816A3964}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{813C8E86-4C90-4617-B59E-E130CC068140}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{89133BCE-57D0-4D2B-AFAF-A97B74AD704E}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{8F40CC34-FE77-4618-AA3D-BD2EFACAA8DC}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{9F89E240-06A6-4E1C-BA84-F267DE7DB391}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{B60A0E56-548D-40AE-9383-D752531F653F}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{B67B0756-2528-4996-B4BD-C993614CC0B6}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{BCC51EA9-6340-4EBE-8736-13A752ECB0BE}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{E9719D38-EC55-4C8B-9DF0-080ADE95A9FA}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{F4B3E25A-33B4-4647-9A78-B627DDE211A6}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{08101C3E-6C90-439E-9734-6E4DD1B53B69}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{0BACA3C1-F734-4A5F-970A-15DBF7D3C09C}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{09B90087-4FFA-4A44-BE69-DA117A710F07}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{0D4385DF-F78A-4264-A32C-7DD4A72DE539}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{1449F89C-AD28-427A-97FF-1D5BD812EA43}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{19A0B5C9-65FE-4D3B-8BDD-EFB7FE553C58}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{1C08D3D0-1E04-4DDE-AB0A-75355EA2585E}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{19C99256-D011-47E2-BC64-6322096E20A5}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{20F8B70D-9F16-4DCB-8788-90A0498E46B9}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{2871B7AF-2D4C-478F-BE89-881881C272AB}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{28FEDB90-53C7-4928-994A-CEE782606507}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{2B94CDFD-4A45-4B08-B105-54C709D07B28}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{3A350193-C7F7-4E10-B347-02FF4C3CC4E9}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{2C354A9B-A5DF-41A3-BF40-2D72FEAC14D3}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{4723879B-8F52-4BE7-9994-626AFA539366}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{2C797AA0-978C-4AC2-BBB4-F89D410B614E}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{7B6A3434-8625-4ABF-B79D-09D98C2498C4}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{54007809-0689-4A40-9D8F-94C79D87D931}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{8B6C0168-BAAC-4C7C-911E-0132590F5661}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{557C3787-D066-496E-8CAF-BA47DA7365C1}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{8EC33B7D-9953-4EDB-ACE2-D4C105968601}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{5C083B7E-A083-4B20-A7AD-7C8E29085494}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{A00E2305-7001-4200-BA00-5779F9A3E7D3}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{649D371E-D3E3-4FC0-AC82-E91F73D8E79E}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{B803D266-A08D-4A4C-9604-6D35689ABE09}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{655980F1-13D5-4DA2-9E80-AA56C36876CB}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{A917B2F3-A9BF-477C-A0E3-0382D0376159}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{6AF126A9-B07A-4DE4-883E-28D3ECCD75D8}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{B26B5883-F15F-4283-B3D5-A1728077DE47}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{6B436BDD-8B8B-4A1F-ADD5-E67B30C8F7DD}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{B803D266-A08D-4A4C-9604-6D35689ABE09}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{71BF80FD-7E91-4730-B6E8-8F3E81F5C38B}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{CB9385AB-8541-4B2F-A363-48F64C612993}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{81723C8C-918F-4456-B7E8-A68CF7A10C6D}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{D6A7D177-0B2F-4283-B2E8-B6310A45E606}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{82A10659-A1E5-4732-A839-C910D955C88B}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{D5D6E9B5-30D5-4457-AC8B-399205F50411}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{84844B27-0D53-4C71-AB24-0151B33AB02F}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{D6A7D177-0B2F-4283-B2E8-B6310A45E606}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{A8BCF2B9-ED19-4637-AC77-BF59F131FA1F}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{E0D6C30A-B9A3-4181-8099-3B0D5A2B98AF}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{A9A73A66-B0E0-4FFB-828F-3A55E1FA4271}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{B6049D5D-718F-44C0-B965-06840D27E206}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{F100A342-3AC5-47FF-B5B3-FCDB6FC9F016}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{B817D284-1B82-4793-B1F3-58A06DAB03A1}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{BC077DD0-42B5-451C-B78C-4AC97E4B116B}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{C123DBA0-52DF-4272-BBAA-BFD092D07C2E}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{CB9DD914-68B6-4710-A04E-4745470706CE}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{DE1E317F-716A-4784-BA90-FDA6D6A8FAD5}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{E36DCDBC-57AD-4A1C-B9C6-1161441B51CA}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{E51AC62C-E82E-4E60-97AB-C66C4969AF39}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{EF5750B1-0ABA-45C5-BF12-FB4D1D1150D2}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{F1D9585E-20A6-4689-84C7-C19FE21C9A71}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{F1E1A6B0-6CAC-471B-99C4-4DBADA883BE8}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{F8C9D1A9-B7B7-47CA-8B93-27C5B64D3A47}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\TypeLib\{F61D1CE1-5199-4B57-B59E-C6819EA92F3B}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\TypeLib\{31E956BF-8CA9-4D75-B534-7EBC79770002}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\TypeLib\{6E9E448E-B195-4627-953C-5377FA9BBA36}]>>C:\psguardrem.reg echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PSGuard spyware remover]>>C:\psguardrem.reg echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\P.S.Guard spyware remover]>>C:\psguardrem.reg swreg add HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.comdummy swreg add HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTDdummy swreg save HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTDdummy ShudderLTDdummy.hiv swreg save HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.comdummy PSGuard.comdummy.hiv swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTDdummy /f swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.comdummy /f swreg restore HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTD ShudderLTDdummy.hiv swreg restore HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com PSGuard.comdummy.hiv swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTD /f swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com /f regedit /s C:\psguardrem.reg del ShudderLTDdummy.hiv del PSGuard.comdummy.hiv del /q C:\psguardrem.reg del /q %systemdrive%\LTD.txt del /q %systemdrive%\PSGuard.txt regedit.exe /e %systemdrive%\LTD.txt "HKEY_LOCAL_MACHINE\SOFTWARE\SHUDDERLTD" IF EXIST %systemdrive%\LTD.txt echo ShudderLTD key was NOT successfully removed!>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF NOT EXIST %systemdrive%\LTD.txt echo ShudderLTD key was successfully removed! >>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt regedit.exe /e %systemdrive%\PSGuard.txt "HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com" IF EXIST %systemdrive%\PSGuard.txt echo PSGuard.com key was NOT successfully removed!>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF NOT EXIST %systemdrive%\PSGuard.txt echo if previously present, PSGuard.com key was successfully removed! >>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt del /q %systemdrive%\PSGuard.txt del /q %systemdrive%\LTD.txt GOTO WinHchck sgcheck cls @echo off echo.>>%systemdrive%\smitfiles.txt echo checking for PSGuard.com key>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt regedit.exe /e %systemdrive%\PSGuard.txt "HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com" IF EXIST %systemdrive%\PSGuard.txt echo PSGuard.com key present!>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF NOT EXIST %systemdrive%\PSGuard.txt echo PSGuard.com key not present!>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF EXIST %systemdrive%\PSGuard.txt GOTO psgfix IF NOT EXIST %systemdrive%\PSGuard.txt GOTO WinHchck sgfix cls @echo off echo.>>%systemdrive%\smitfiles.txt echo Running LTDFix/PSGuard.com fix!>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt cls @echo off echo.>>%systemdrive%\smitfiles.txt echo. echo. echo SmitRem © add-on ShudderLTD/PSGuard.com registry Fix echo. echo by Miekiemoes, Atribune and noahdfear echo. echo. echo. echo. pause cls @echo off echo REGEDIT4>>C:\psguardrem.reg echo.>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.FoundCollection]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.FoundCollection.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.FoundObject]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.FoundObject.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.KilledProcessesCollection]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.KilledProcessesCollection.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.KilledProcessInfo]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.KilledProcessInfo.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.License]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.License.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.Options]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.Options.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.Quarantine]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.Quarantine.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.RealTime]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.RealTime.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.RTObject]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.RTObject.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.SafeMode]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.SafeMode.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.Scaner]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.Scaner.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.ScanStatistic]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.ScanStatistic.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.theApp]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.theApp.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.Update]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.Update.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.UpdateInfo]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.UpdateInfo.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.VersionInfo]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\AVECore.VersionInfo.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\WndLayer.Window]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\WndLayer.Window.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\WndLayer.WindowCollection]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\WndLayer.WindowCollection.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\WndLayer.WindowLayer]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\WndLayer.WindowLayer.1]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{F880B4F2-75BF-44EC-B7AA-45EC37448027}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{E479197F-49E5-4E60-9FA2-A71D4C7C2BBC}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{E12AAACF-8AF2-4C31-BA94-E3787B44F90E}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{D25F7446-4D36-4203-9EA5-5422B26FA9D0}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{CDD964C2-FB78-4A74-BB1E-1CB1FCB72018}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{CBE4B748-08F9-44DB-8FB1-9AD25979DA35}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{C5B70256-5B08-4056-B84E-C6CE084967F5}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{ACC647EE-991A-4811-B420-F063F50CDDC1}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{8DCA6B3D-1FCA-4500-B210-76119BB5C69E}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{8C2A05C5-780F-4A2E-AE1C-FB8181F860E4}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{82847700-FE61-46A3-B3EE-761A1E312ACA}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{7198F8DA-012C-4DB4-ABD8-923A54C87900}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{67196B3E-55A0-49DE-BA11-66F07DF804DB}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{5E5A79A6-C67B-444E-BE58-BD0ACEFCDA07}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{58E68548-42E2-479D-A9E0-86D9F2EAF02E}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{5206DF89-97FC-41AD-BAE3-993E87053A99}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{4F93062D-7BDA-48BE-AEB6-88AF2B1FE2D4}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{4AA55E8C-2C19-4F3A-91EC-43B6DF937C4F}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{41D7BB0A-64E0-4AB2-BD0B-69EA78E462E8}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{0EA04667-E53B-4E81-8E7C-DE2CA114CBD6}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{3946A33D-BBC6-4792-A383-D855E0F76D91}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{265C2AF8-C94C-4AFF-B2B6-340D3982562C}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{0878F045-B52E-46B3-9724-D3AE69D50067}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{04F3168F-5AFC-4531-B3B4-16CA93720415}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{187A8428-BD94-470D-A178-A2347F940519}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{2865930B-4588-4FF3-8227-6D4F66C92C7A}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{2FE2EDC0-9E62-4F34-8A73-BC66DAE48EF3}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{3A3A8C24-8FF0-4140-9731-54D9483EA70B}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{3A906593-B4BD-48ED-84B0-3249BED65EF9}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{49B72A72-01F5-4AE8-BBD7-DAA67F1E303B}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{6AE3ACA6-1BE3-4443-98DD-EFFCFA793D35}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{9F89E240-06A6-4E1C-BA84-F267DE7DB391}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{79DDF2EF-D881-464B-B2AF-5AF8816A3964}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{813C8E86-4C90-4617-B59E-E130CC068140}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{89133BCE-57D0-4D2B-AFAF-A97B74AD704E}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{8F40CC34-FE77-4618-AA3D-BD2EFACAA8DC}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{9F89E240-06A6-4E1C-BA84-F267DE7DB391}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{B60A0E56-548D-40AE-9383-D752531F653F}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{B67B0756-2528-4996-B4BD-C993614CC0B6}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{BCC51EA9-6340-4EBE-8736-13A752ECB0BE}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{E9719D38-EC55-4C8B-9DF0-080ADE95A9FA}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\CLSID\{F4B3E25A-33B4-4647-9A78-B627DDE211A6}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{08101C3E-6C90-439E-9734-6E4DD1B53B69}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{0BACA3C1-F734-4A5F-970A-15DBF7D3C09C}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{09B90087-4FFA-4A44-BE69-DA117A710F07}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{0D4385DF-F78A-4264-A32C-7DD4A72DE539}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{1449F89C-AD28-427A-97FF-1D5BD812EA43}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{19A0B5C9-65FE-4D3B-8BDD-EFB7FE553C58}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{1C08D3D0-1E04-4DDE-AB0A-75355EA2585E}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{19C99256-D011-47E2-BC64-6322096E20A5}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{20F8B70D-9F16-4DCB-8788-90A0498E46B9}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{2871B7AF-2D4C-478F-BE89-881881C272AB}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{28FEDB90-53C7-4928-994A-CEE782606507}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{2B94CDFD-4A45-4B08-B105-54C709D07B28}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{3A350193-C7F7-4E10-B347-02FF4C3CC4E9}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{2C354A9B-A5DF-41A3-BF40-2D72FEAC14D3}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{4723879B-8F52-4BE7-9994-626AFA539366}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{2C797AA0-978C-4AC2-BBB4-F89D410B614E}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{7B6A3434-8625-4ABF-B79D-09D98C2498C4}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{54007809-0689-4A40-9D8F-94C79D87D931}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{8B6C0168-BAAC-4C7C-911E-0132590F5661}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{557C3787-D066-496E-8CAF-BA47DA7365C1}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{8EC33B7D-9953-4EDB-ACE2-D4C105968601}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{5C083B7E-A083-4B20-A7AD-7C8E29085494}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{A00E2305-7001-4200-BA00-5779F9A3E7D3}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{649D371E-D3E3-4FC0-AC82-E91F73D8E79E}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{B803D266-A08D-4A4C-9604-6D35689ABE09}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{655980F1-13D5-4DA2-9E80-AA56C36876CB}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{A917B2F3-A9BF-477C-A0E3-0382D0376159}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{6AF126A9-B07A-4DE4-883E-28D3ECCD75D8}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{B26B5883-F15F-4283-B3D5-A1728077DE47}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{6B436BDD-8B8B-4A1F-ADD5-E67B30C8F7DD}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{B803D266-A08D-4A4C-9604-6D35689ABE09}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{71BF80FD-7E91-4730-B6E8-8F3E81F5C38B}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{CB9385AB-8541-4B2F-A363-48F64C612993}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{81723C8C-918F-4456-B7E8-A68CF7A10C6D}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{D6A7D177-0B2F-4283-B2E8-B6310A45E606}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{82A10659-A1E5-4732-A839-C910D955C88B}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{D5D6E9B5-30D5-4457-AC8B-399205F50411}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{84844B27-0D53-4C71-AB24-0151B33AB02F}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{D6A7D177-0B2F-4283-B2E8-B6310A45E606}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{A8BCF2B9-ED19-4637-AC77-BF59F131FA1F}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{E0D6C30A-B9A3-4181-8099-3B0D5A2B98AF}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{A9A73A66-B0E0-4FFB-828F-3A55E1FA4271}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{B6049D5D-718F-44C0-B965-06840D27E206}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{F100A342-3AC5-47FF-B5B3-FCDB6FC9F016}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{B817D284-1B82-4793-B1F3-58A06DAB03A1}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{BC077DD0-42B5-451C-B78C-4AC97E4B116B}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{C123DBA0-52DF-4272-BBAA-BFD092D07C2E}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{CB9DD914-68B6-4710-A04E-4745470706CE}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{DE1E317F-716A-4784-BA90-FDA6D6A8FAD5}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{E36DCDBC-57AD-4A1C-B9C6-1161441B51CA}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{E51AC62C-E82E-4E60-97AB-C66C4969AF39}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{EF5750B1-0ABA-45C5-BF12-FB4D1D1150D2}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{F1D9585E-20A6-4689-84C7-C19FE21C9A71}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{F1E1A6B0-6CAC-471B-99C4-4DBADA883BE8}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\Interface\{F8C9D1A9-B7B7-47CA-8B93-27C5B64D3A47}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\TypeLib\{F61D1CE1-5199-4B57-B59E-C6819EA92F3B}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\TypeLib\{31E956BF-8CA9-4D75-B534-7EBC79770002}]>>C:\psguardrem.reg echo [-HKEY_CLASSES_ROOT\TypeLib\{6E9E448E-B195-4627-953C-5377FA9BBA36}]>>C:\psguardrem.reg echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PSGuard spyware remover]>>C:\psguardrem.reg echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\P.S.Guard spyware remover]>>C:\psguardrem.reg swreg add HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.comdummy swreg add HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTDdummy swreg save HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTDdummy ShudderLTDdummy.hiv swreg save HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.comdummy PSGuard.comdummy.hiv swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTDdummy /f swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.comdummy /f swreg restore HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTD ShudderLTDdummy.hiv swreg restore HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com PSGuard.comdummy.hiv swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTD /f swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com /f regedit /s C:\psguardrem.reg del ShudderLTDdummy.hiv del PSGuard.comdummy.hiv del /q C:\psguardrem.reg del /q %systemdrive%\PSGuard.txt regedit.exe /e %systemdrive%\PSGuard.txt "HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com" IF EXIST %systemdrive%\PSGuard.txt echo PSGuard.com key was NOT successfully removed!>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF NOT EXIST %systemdrive%\PSGuard.txt echo PSGuard.com key was successfully removed! >>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt del /q %systemdrive%\PSGuard.txt GOTO WinHchck :WinHchck cls @echo off echo.>>%systemdrive%\smitfiles.txt echo checking for WinHound.com key>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt cls @echo off if exist %systemdrive%\WinHound.txt del %systemdrive%\WinHound.txt regedit.exe /e %systemdrive%\WinHound.txt "HKEY_LOCAL_MACHINE\SOFTWARE\WinHound.com" IF EXIST %systemdrive%\WinHound.txt echo WinHound.com key present!>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF NOT EXIST %systemdrive%\WinHound.txt echo WinHound.com key not present!>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF EXIST %systemdrive%\WinHound.txt GOTO WinHfix IF NOT EXIST %systemdrive%\WinHound.txt GOTO smitrem :WinHfix cls @echo off echo.>>%systemdrive%\smitfiles.txt echo Running WinHound.com fix!>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt cls @echo off echo.>>%systemdrive%\smitfiles.txt echo. echo. echo SmitRem © add-on WinHound.com registry Fix echo. echo by Miekiemoes, Atribune and noahdfear echo. echo. echo. echo. pause swreg add HKEY_LOCAL_MACHINE\SOFTWARE\WinHound.comdummy swreg save HKEY_LOCAL_MACHINE\SOFTWARE\WinHound.comdummy WinHound.comdummy.hiv swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\WinHound.comdummy /f swreg restore HKEY_LOCAL_MACHINE\SOFTWARE\WinHound.com WinHound.comdummy.hiv swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\WinHound.com /f del WinHound.comdummy.hiv del /q %systemdrive%\WinHound.txt regedit.exe /e %systemdrive%\WinHound.txt "HKEY_LOCAL_MACHINE\SOFTWARE\WinHound.com" IF EXIST %systemdrive%\WinHound.txt echo WinHound.com key was NOT successfully removed!>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF NOT EXIST %systemdrive%\WinHound.txt echo WinHound.com key was successfully removed! >>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt del /q %systemdrive%\WinHound.txt GOTO smitrem :smitrem @echo off echo. echo If SpyAxe is found and the uninstaller is present, echo. echo the SpyAxe uninstaller will start. echo. echo Allow it to continue. Close any browser window it may cause to open. echo. echo. pause IF EXIST spyaxe.txt del spyaxe.txt echo.>>spyaxe1.txt echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>spyaxe1.txt echo.>>spyaxe1.txt echo SpyAxeFix © by noahdfear>>spyaxe1.txt echo.>>spyaxe1.txt IF EXIST C:\progra~1\spyaxe echo spyaxe directory present>>spyaxe1.txt echo.>>spyaxe1.txt IF EXIST C:\progra~1\spyaxe\uninst.exe echo spyaxe uninstaller present>>spyaxe1.txt IF EXIST C:\progra~1\spyaxe\uninst.exe goto cspyaxe IF NOT EXIST C:\progra~1\spyaxe\uninst.exe goto sys :cspyaxe echo.>>spyaxe1.txt echo Starting spyaxe uninstaller>>spyaxe1.txt start C:\progra~1\spyaxe\uninst.exe goto remove :sys IF EXIST %systemdrive%\progra~1\spyaxe echo spyaxe directory present>>spyaxe1.txt echo.>>spyaxe1.txt IF EXIST %systemdrive%\progra~1\spyaxe\uninst.exe echo spyaxe uninstaller present>>spyaxe1.txt IF EXIST %systemdrive%\progra~1\spyaxe\uninst.exe goto sysspy IF NOT EXIST %systemdrive%\progra~1\spyaxe\uninst.exe echo spyaxe uninstaller NOT present>>spyaxe1.txt IF NOT EXIST %systemdrive%\progra~1\spyaxe\uninst.exe echo spyaxe uninstaller NOT present>>%systemdrive%\smitfiles.txt IF NOT EXIST %systemdrive%\progra~1\spyaxe\uninst.exe del spyaxe1.txt IF NOT EXIST %systemdrive%\progra~1\spyaxe\uninst.exe goto winhound :sysspy echo.>>spyaxe1.txt echo Starting spyaxe uninstaller>>spyaxe1.txt start %systemdrive%\progra~1\spyaxe\uninst.exe echo.>>spyaxe1.txt echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>spyaxe1.txt echo.>>spyaxe1.txt goto remove :remove cls @echo off echo REGEDIT4>>fix.reg echo.>>fix.reg echo [-HKEY_CLASSES_ROOT\CLSID\{E802FFFF-8E58-4d2c-A435-8BEEFB10AB77}]>>fix.reg echo.>>fix.reg echo [-HKEY_CLASSES_ROOT\CLSID\{A2D9D3F0-8C2A-2A1D-A376-1BECFB10AB72}]>>fix.reg echo.>>fix.reg echo [-HKEY_CLASSES_ROOT\CLSID\{A3D21DFF-2E58-4E2A-A435-8CEAF21F0B29}]>>fix.reg echo.>>fix.reg echo [-HKEY_CLASSES_ROOT\CLSID\{C1A8B6A1-2C81-1C3D-A3C6-A1CCDB10B47F}]>>fix.reg echo.>>fix.reg echo [-HKEY_CURRENT_USER\Software\Classes\CLSID\{E802FFFF-8E58-4d2c-A435-8BEEFB10AB77}]>>fix.reg echo.>>fix.reg echo [-HKEY_CURRENT_USER\Software\Classes\CLSID\{A2D9D3F0-8C2A-2A1D-A376-1BECFB10AB72}]>>fix.reg echo.>>fix.reg echo [-HKEY_CURRENT_USER\Software\Classes\CLSID\{A3D21DFF-2E58-4E2A-A435-8CEAF21F0B29}]>>fix.reg echo.>>fix.reg echo [-HKEY_CURRENT_USER\Software\Classes\CLSID\{C1A8B6A1-2C81-1C3D-A3C6-A1CCDB10B47F}]>>fix.reg echo.>>fix.reg echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]>>fix.reg echo "{E802FFFF-8E58-4d2c-A435-8BEEFB10AB77}"=->>fix.reg echo "{A2D9D3F0-8C2A-2A1D-A376-1BECFB10AB72}"=->>fix.reg echo "{A3D21DFF-2E58-4E2A-A435-8CEAF21F0B29}"=->>fix.reg echo "{C1A8B6A1-2C81-1C3D-A3C6-A1CCDB10B47F}"=->>fix.reg echo.>>fix.reg regedit /s fix.reg cls @echo off regedit /a ST.reg HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler echo.>>spyaxe.txt type spyaxe1.txt >>spyaxe.txt echo.>>spyaxe.txt type ST.reg >>spyaxe.txt echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>spyaxe.txt echo.>>spyaxe.txt del /q spyaxe1.txt del /q ST.reg del /q fix.reg echo.>>%systemdrive%\smitfiles.txt type spyaxe.txt>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt del /q spyaxe.txt cls echo. echo. echo If the SpyAxe uninstaller has completed, echo. echo press any key to continue. echo. echo. pause GOTO winhound :winhound @echo off echo. echo If Winhound is found and the uninstaller is present, echo. echo the Winhound uninstaller will start. echo. echo Allow it to continue. echo. echo. pause IF EXIST winhound.txt del winhound.txt echo.>>winhound.txt echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>winhound.txt echo.>>winhound.txt echo WinhoundFix © by noahdfear>>winhound.txt echo.>>winhound.txt IF EXIST C:\progra~1\Winhound echo Winhound directory present>>winhound.txt echo.>>winhound.txt IF EXIST C:\progra~1\Winhound\Uninstall.exe echo Winhound uninstaller present>>winhound.txt IF EXIST C:\progra~1\Winhound\Uninstall.exe goto Winhck IF NOT EXIST C:\progra~1\Winhound\Uninstall.exe goto winh :Winhck echo.>>winhound.txt echo Starting Winhound uninstaller>>winhound.txt start C:\progra~1\Winhound\Uninstall.exe echo.>>winhound.txt echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>winhound.txt echo.>>winhound.txt goto removeh :winh IF EXIST %systemdrive%\progra~1\Winhound echo Winhound directory present>>winhound.txt echo.>>winhound.txt IF EXIST %systemdrive%\progra~1\Winhound\Uninstall.exe echo Winhound uninstaller present>>winhound.txt IF EXIST %systemdrive%\progra~1\Winhound\Uninstall.exe goto winhrem IF NOT EXIST %systemdrive%\progra~1\Winhound\Uninstall.exe echo Winhound uninstaller NOT present>>%systemdrive%\smitfiles.txt IF NOT EXIST %systemdrive%\progra~1\Winhound\Uninstall.exe echo Winhound uninstaller NOT present>>winhound.txt IF NOT EXIST %systemdrive%\progra~1\Winhound\Uninstall.exe del winhound.txt IF NOT EXIST %systemdrive%\progra~1\Winhound\Uninstall.exe goto smitrem1 :winhrem echo.>>winhound.txt echo Starting Winhound uninstaller>>winhound.txt start %systemdrive%\progra~1\Winhound\Uninstall.exe echo.>>winhound.txt echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>winhound.txt echo.>>winhound.txt goto removeh :removeh cls echo. echo. echo If the Winhound uninstaller has completed, echo. echo press any key to continue. echo. echo. pause echo.>>winhound.txt echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>winhound.txt echo.>>winhound.txt echo.>>%systemdrive%\smitfiles.txt type winhound.txt>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt del /q winhound.txt goto smitrem1 :smitrem1 cls @echo off echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo Existing Pre-run Files>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo ~~~ Program Files ~~~>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\Archivos de programa\Winhound" echo Winhound>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\progra~1\Winhound" echo Winhound>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\Archivos de programa\spyaxe" echo SpyAxe>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\progra~1\spyaxe" echo SpyAxe>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\Archivos de programa\SpyTrooper" echo SpyTrooper>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\Archivos de programa\Security Toolbar" echo Security Toolbar>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\progra~1\SpyTrooper" echo SpyTrooper>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\progra~1\Security Toolbar" echo Security Toolbar>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\Archivos de programa\P.S.Guard" echo P.S.Guard>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\Archivos de programa\Security IGuard" echo Security IGuard>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\Archivos de programa\Virtual Maid" echo Virtual Maid>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\Archivos de programa\Search Maid" echo Search Maid>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\Archivos de programa\AntiVirusGold" echo AntiVirusGold>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\Archivos de programa\PSGuard" echo PSGuard>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\Archivos de programa\SpySheriff" echo SpySheriff>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\progra~1\P.S.Guard" echo P.S.Guard>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\progra~1\Security IGuard" echo Security IGuard>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\progra~1\Virtual Maid" echo Virtual Maid>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\progra~1\Search Maid" echo Search Maid>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\progra~1\AntiVirusGold" echo AntiVirusGold>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\progra~1\PSGuard" echo PSGuard>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\progra~1\SpySheriff" echo SpySheriff>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo ~~~ Shortcuts ~~~>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Desktop\WinHound spyware remover.lnk" echo WinHound spyware remover.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Bureaublad\WinHound spyware remover.lnk" echo WinHound spyware remover.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinHound spyware remover.lnk" echo quick launch WinHound spyware remover.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Start Menu\Programs\WinHound spyware remover" echo WinHound spyware remover folder>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Menu Start\Programs\WinHound spyware remover" echo WinHound spyware remover folder>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Desktop\Online Security Guide.url" echo Online Security Guide.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Start Menu\Online Security Guide.url" echo Online Security Guide.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Bureaublad\Online Security Guide.url" echo Online Security Guide.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Menu Start\Online Security Guide.url" echo Online Security Guide.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Desktop\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Desktop\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Start Menu\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Desktop\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Desktop\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Bureaublad\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Bureaublad\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Menu Start\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\SpyTrooper.lnk" echo SpyTrooper.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\SpyTrooper.lnk" echo SpyTrooper.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Menu Start\Programma's\SpyTrooper" echo SpyTrooper folder>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Start Menu\Programs\SpyTrooper" echo SpyTrooper folder>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Bureaublad\Security Troubleshooting.lnk" echo Security Troubleshooting.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Bureaublad\Online Security Center.lnk" echo Online Security Center.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Menu Start\Anti SPAM.url" echo Anti SPAM.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Menu Start\Online Casino.url" echo Online Casino.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Menu Start\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Menu Start\Computer Security.url" echo Computer Security.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Desktop\Security Troubleshooting.lnk" echo Security Troubleshooting.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Desktop\Online Security Center.lnk" echo Online Security Center.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Start Menu\Anti SPAM.url" echo Anti SPAM.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Start Menu\Online Casino.url" echo Online Casino.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Start Menu\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Start Menu\Computer Security.url" echo Computer Security.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Air Tickets.url" echo Air Tickets.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Big Tits.url" echo Big Tits.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Blackjack.url" echo Blackjack.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Britney Spears.url" echo Britney Spears.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Car Insurance.url" echo Car Insurance.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Cheap Cigarettes.url" echo Cheap Cigarettes.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Credit Card.url" echo Credit Card.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Cruises.url" echo Cruises.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Currency Trading.url" echo Currency Trading.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Lesbian Sex.url" echo Lesbian Sex.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\MP3.url" echo MP3.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Online Betting.url" echo Online Betting.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Online Gambling.url" echo Online Gambling.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Oral Sex.url" echo Oral Sex.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Party Poker.url" echo Party Poker.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Pharmacy.url" echo Pharmacy.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Phentermine.url" echo Phentermine.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Pornstars.url" echo job Pornstars.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Remove Spyware.url" echo Remove Spyware.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\viagra.url" echo viagra.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Air Tickets.url" echo Air Tickets.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Big Tits.url" echo Big Tits.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Blackjack.url" echo Blackjack.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Britney Spears.url" echo Britney Spears.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Car Insurance.url" echo Car Insurance.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Cheap Cigarettes.url" echo Cheap Cigarettes.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Credit Card.url" echo Credit Card.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Cruises.url" echo Cruises.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Currency Trading.url" echo Currency Trading.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Lesbian Sex.url" echo Lesbian Sex.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\MP3.url" echo MP3.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Online Betting.url" echo Online Betting.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Online Gambling.url" echo Online Gambling.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Oral Sex.url" echo Oral Sex.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Party Poker.url" echo Party Poker.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Pharmacy.url" echo Pharmacy.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Phentermine.url" echo Phentermine.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Pornstars.url" echo job Pornstars.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Remove Spyware.url" echo Remove Spyware.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\viagra.url" echo viagra.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Start Menu\Programs\PSGuard spyware remover" echo PSGuard spyware remover>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Menu Start\Programma's\PSGuard spyware remover" echo PSGuard spyware remover>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Bureaublad\AntivirusGold.lnk" echo AntivirusGold.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\AntivirusGold.lnk" echo AntivirusGold.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Bureaublad\PSGuard spyware remover.lnk" echo PSGuard spyware remover.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Desktop\PSGuard spyware remover.lnk" echo PSGuard spyware remover.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Bureaublad\Spyware Removal.url" echo Spyware Removal.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Bureaublad\Online Dating.url" echo Online Dating.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Bureaublad\Online Pharmacy.url" echo Online Pharmacy.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Desktop\Spyware Removal.url" echo Spyware Removal.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Desktop\Online Dating.url" echo Online Dating.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Desktop\Online Pharmacy.url" echo Online Pharmacy.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSGuard spyware remover.lnk" echo quick launch PSGuard spyware remover.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSGuard.lnk" echo quick launch PSGuard.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Menu Start\Programma's\SpySheriff" echo SpySheriff>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Bureaublad\SpySheriff.lnk" echo SpySheriff.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Bureaublad\PSGuard.lnk" echo PSGuard.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Application Data\PSGuard.com" echo PSGuard.com>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Start Menu\Programs\SpySheriff" echo SpySheriff>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Application Data\Install.dat" echo Install.dat>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\SpySheriff.lnk" echo SpySheriff.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Desktop\PSGuard.lnk" echo PSGuard.lnk>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo ~~~ Favorites ~~~>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Take It Here - Daily Updated Porn Links.url" echo Take It Here - Daily Updated Porn Links.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Take It Here - Daily Updated Porn Links.url" echo Take It Here - Daily Updated Porn Links.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Favori~1\Free XXX Sites List.url" echo Free XXX Sites List.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Favori~1\Antivirus Test Online.url" echo Antivirus Test Online.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Favori~1\Cheap Viagra.url" echo Cheap Viagra.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Favori~1\Buy Viagra Online.url" echo Buy Viagra Online.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Favori~1\Need Money.url" echo Need Money.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\adult" echo adult>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\cars" echo cars>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\sexual life" echo sexual life>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\shopping" echo shopping>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\anti spam.url" echo anti spam.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\job search.url" echo job search.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\poker.url" echo poker.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\spyware removal.url" echo spyware removal.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Online Gambling.url" echo Online Gambling.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\online dating.url" echo online dating.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Black Jack Online.url" echo Black Jack Online.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Online Pharmacy\Adipex.url" echo Online Pharmacy\Adipex.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Black Jack Online.url" echo Black Jack Online.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Home Loan.url" echo Home Loan.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Network Security.url" echo Network Security.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Online Dating.url" echo Online Dating.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Adipex.url" echo Adipex.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Alprazolam.url" echo Alprazolam.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Carisoprodol.url" echo Carisoprodol.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Diazepam.url" echo Diazepam.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Hydrocodone.url" echo Hydrocodone.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Lortab.url" echo Lortab.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Online Pharmacy.url" echo Online Pharmacy.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Prozac.url" echo Prozac.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Valium.url" echo Valium.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Vicodin.url" echo Vicodin.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Xanax.url" echo Xanax.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Remove Spyware.url" echo Remove Spyware.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Spam Filters.url" echo Spam Filters.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Take It Here - Free * TGP.url" echo Take It Here - Free * TGP.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Web Detective.url" echo Web Detective.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Online Gambling" echo Online Gambling folder>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Online Pharmacy" echo Online Pharmacy folder>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo ~~~ system32 folder ~~~>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\wbeconm.dll" echo wbeconm.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\_plastilin_" echo _plastilin_>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\atmtd.dll" echo atmtd.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\atmtd.dll._" echo atmtd.dll._>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Defpia32.dll" echo Defpia32.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\fhpd.dll" echo fhpd.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Kdfdlh32.dll" echo Kdfdlh32.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\klja.dll" echo klja.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\ll.exe" echo ll.exe>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Mhpcja32.dll" echo Mhpcja32.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Nbfgemln.exe" echo Nbfgemln.exe>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\ongi.dll" echo ongi.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\perflibs__" echo perflibs__>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\svcp.csv" echo svcp.csv>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\sywsvcs.exe" echo sywsvcs.exe>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\windesktop.dll" echo windesktop.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\windesktop.exe" echo windesktop.exe>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\wins32.dll" echo wins32.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\winselect.exe" echo winselect.exe>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\winsub.xml" echo winsub.xml>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\zlbw.dll" echo zlbw.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\ioctrl.dll" echo ioctrl.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\svchosts.dll" echo svchosts.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\ff.tmp" echo ff.tmp>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\oleext32.dll" echo oleext32.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\1024" echo 1024 dir>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\svchop.exe" echo svchop.exe>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\shdochop.dll" echo shdochop.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\zlbw.dll" echo zlbw.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\msvol.tlb" echo msvol.tlb>>%systemdrive%\smitfiles.txt IF EXIST "%systemroot%\system32\ld****.tmp" echo ld****.tmp>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\mssearchnet.exe" echo mssearchnet.exe>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\ncompat.tlb" echo ncompat.tlb>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\nvctrl.exe" echo nvctrl.exe>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\mscornet.exe" echo mscornet.exe>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\gunist.exe" echo gunist.exe>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\param32.dll" echo param32.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\pop_up.dll" echo pop_up.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\searchdll.dll" echo searchdll.dll>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\thn.dll echo thn.dll>>%systemdrive%\smitfiles.txt IF EXIST "%systemroot%\system32\__delete_on_reboot__intel32.exe" echo __delete_on_reboot__intel32.exe>>%systemdrive%\smitfiles.txt IF EXIST "%systemroot%\system32\__delete_on_reboot__OLEADM.dll" echo __delete_on_reboot__OLEADM.dll>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\intell32.exe echo intell32.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\oleext.dll echo oleext.dll>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\wppp.html echo wppp.html>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\svcnt.exe echo svcnt.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\oleadm.dll echo oleadm.dll>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\intel32.exe echo intel32.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\hhk.dll.tcf echo hhk.dll.tcf>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\perfcii.ini echo perfcii.ini>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\oleadm32.dll echo oleadm32.dll>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\wp.bmp echo wp.bmp>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\hookdump.exe echo hookdump.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\winnook.exe echo winnook.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\wldr.dll echo wldr.dll>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\helper.exe echo helper.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\intmonp.exe echo intmonp.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\msmsgs.exe echo msmsgs.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\ole32vbs.exe echo ole32vbs.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\msole32.exe echo msole32.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\hp***.tmp echo hp***.tmp>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\shnlog.exe echo shnlog.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\intmon.exe echo intmon.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\hhk.dll echo hhk.dll>>%systemdrive%\smitfiles.txt IF EXIST "%systemroot%\system32\__delete_on_reboot__intmon.exe" echo __delete_on_reboot__intmon.exe>>%systemdrive%\smitfiles.txt IF EXIST "%systemroot%\system32\Log Files" echo Log Files>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\logfiles echo logfiles>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo ~~~ Icons in System32 ~~~>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\ts.ico" echo ts.ico>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\ot.ico" echo ot.ico>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\ptainfo1.ico" echo ptainfo1>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\ptainfo2.ico" echo ptainfo2>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Air Tickets.ico" echo Air Tickets>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Big Tits.ico" echo Big Tits>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Blackjack.ico" echo Blackjack>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Britney Spears.ico" echo Britney Spears>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Car Insurance.ico" echo Car Insurance>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Cheap Cigarettes.ico" echo Cheap Cigarettes>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Credit Card.ico" echo Credit Card>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Cruises.ico" echo Cruises>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Currency Trading.ico" echo Currency Trading>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Lesbian Sex.ico" echo Lesbian Sex>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\MP3.ico" echo MP3>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Online Betting.ico" echo Online Betting>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Online Gambling.ico" echo Online Gambling>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Oral Sex.ico" echo Oral Sex>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Party Poker.ico" echo Party Poker>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Pharmacy.ico" echo Pharmacy>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Phentermine.ico" echo Phentermine>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Pornstars.ico" echo Pornstars>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Remove Spyware.ico" echo Remove Spyware>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\viagra.ico" echo viagra>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo ~~~ Windows directory ~~~>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\RGF2ZQ echo RGF2ZQ folder>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\warnhp.html echo warnhp.html>>%systemdrive%\smitfiles.txt IF EXIST "%systemroot%\Application Data\Shudder Global Limited" echo Application Data\Shudder Global Limited>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\wp.bmp echo wp.bmp>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\uninstIU.exe echo uninstIU.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\zloader3.exe echo zloader3.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\desktop.html echo desktop.html>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\screen.html echo screen.html>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\sites.ini echo sites.ini>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\popuper.exe echo popuper.exe>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo ~~~ Drive root ~~~>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF EXIST %systemdrive%\bsw.exe echo bsw.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemdrive%\wp.exe echo wp.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemdrive%\wp.bmp echo wp.bmp>>%systemdrive%\smitfiles.txt IF EXIST %systemdrive%\bsw.bmp echo bsw.bmp>>%systemdrive%\smitfiles.txt IF EXIST %systemdrive%\winstall.exe echo winstall.exe>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo ~~~ Miscellaneous Files/folders ~~~>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\application data\shudder global limited" echo shudder global limited>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt cls @echo off if exist %systemdrive%\replace.cmd del replace.cmd copy replace.cmd %systemdrive%\replace.cmd cls @echo off if exist %systemdrive%\delfiles.cmd del delfiles.cmd copy delfiles.cmd %systemdrive%\delfiles.cmd cls @echo off echo.>>%systemdrive%\smitfiles.txt process -k explorer.exe>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo Starting registry repairs>>%systemdrive%\smitfiles.txt cls @echo off echo REGEDIT4>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{e0103cd4-d1ce-411a-b75b-4fec072867f4}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e0103cd4-d1ce-411a-b75b-4fec072867f4}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e0103cd4-d1ce-411a-b75b-4fec072867f4}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]>>C:\smitfrau.reg echo "{A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F}"=->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CURRENT_USER\Software\Classes\CLSID\{A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CMDSERVICE]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MCHINJDRV]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdService]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mchInjDrv]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MCHINJDRV]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mchInjDrv]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]>>C:\smitfrau.reg echo "windesktop" =->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]>>C:\smitfrau.reg echo "windesktop" =->>C:\smitfrau.reg echo "WinHound" =->>C:\smitfrau.reg echo "sp" =->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchAssistant Uninstall]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinHound spyware remover]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_LOCAL_MACHINE\SOFTWARE\Policies]>>C:\smitfrau.reg echo "{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}" =->>C:\smitfrau.reg echo "{645FF040-5081-101B-9F08-00AA002F954E}" =->>C:\smitfrau.reg echo "{6BF52A52-394A-11D3-B153-00C04F79FAA6}" =->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced]>>C:\smitfrau.reg echo "SeparateProcess" =dword:00000000>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3E01D51F-E9BD-4902-A0DE-2F4AA5A03092}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\New Windows]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DownloadManager]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\text/html]>>C:\smitfrau.reg echo "{348722EC-7332-496E-B944-FF60A9456D46}" =->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\text/plain]>>C:\smitfrau.reg echo "{348722EC-7332-496E-B944-FF60A9456D46}" =->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]>>C:\smitfrau.reg echo "NoActiveDesktopChanges"=dword:00000000>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{736B5468-BDAD-41BE-92D0-22AE2DDF7BCB}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{1ca480cd-c0e5-4548-874e-b85b17905b3a}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1ca480cd-c0e5-4548-874e-b85b17905b3a}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1ca480cd-c0e5-4548-874e-b85b17905b3a}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objecta\{724510c3-f3c8-4fb7-879a-d99f29008a2f}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{724510C3-F3C8-4FB7-879A-D99F29008A2F}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]>>C:\smitfrau.reg echo "SpyAxe"=->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{724510c3-f3c8-4fb7-879a-d99f29008a2f}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{724510c3-f3c8-4fb7-879a-d99f29008a2f}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]>>C:\smitfrau.reg echo "Display Inline Images"=->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{736B5468-BDAD-41BE-92D0-22AE2DDF7BCB}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{736B5468-BDAD-41BE-92D0-22AE2DDF7BCB}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]>>C:\smitfrau.reg echo "{736B5468-BDAD-41BE-92D0-22AE2DDF7BCB}"=->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{3e9b951e-6f72-431b-82cf-4a9fbf2f53bc}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3e9b951e-6f72-431b-82cf-4a9fbf2f53bc}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7288c0bd-7f2f-4229-a0c4-3c90a6e2a881}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7caf96a2-c556-460a-988e-76fc7895d284}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\clsid\{e9ccf15d-4c68-4b5a-9e9a-8e12e4bd39bd}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{736B5468-BDAD-41BE-92D0-22AE2DDF7BCB}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\clsid\{057e242f-2947-4e0a-8e61-a11345d97ea6}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CURRENT_USER\Software\SNO2]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CURRENT_USER\Software\SpyTrooper]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e9ccf15d-4c68-4b5a-9e9a-8e12e4bd39bd}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]>>C:\smitfrau.reg echo "{736b5468-bdad-41be-92d0-22ae2ddf7bcb}"=->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpyTrooper]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]>>C:\smitfrau.reg echo "FH"=->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]>>C:\smitfrau.reg echo "SpyTrooper"=->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\uuid]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Classes\HP]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Classes\HP.1]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{15DC7116-E58E-4395-A45A-A1C99B17C030}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{17E02586-A91D-4A9D-A74E-187B05DFFE6F}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{1BD98DFD-2DA9-4C54-85D7-BE03A0F9C487}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{1C94EA51-3800-4F08-B5DC-A5B67823FFEA}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{20D1AF34-6E19-42D8-AF9F-BDFBE45C2454}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{21E132C9-1F98-4151-BDAD-7D9B49C60A8E}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{23F7AD29-F51A-4BA1-BE70-143B1CB25BD1}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{2C59D5EC-6B91-4896-BD6F-5F121D87A7F8}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{2F34E0E0-F0BB-477F-AFB8-509262FA0AD1}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{35ED274E-3F42-4A78-BBDC-3B7D73E85578}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{3D74D140-F780-4AE3-8D6D-F8DC39107213}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{49443D6E-CE4E-47A9-8DEB-F5774CE14984}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{52034AD2-914C-4634-B375-9299631E5525}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{7702C521-76AE-42C0-A181-3B5A96C2EEF7}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{7ADDA344-1D36-4446-9F4B-B2351FB19EFD}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{7D98221E-AF8F-4D29-8BB1-1DFABC288173}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{9746B450-6064-4EC8-9480-72A289AA2237}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{C5A40FCE-0A0F-40CA-985E-661C28B5B431}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{C7F22879-7151-4C71-8C50-9557AFDA66C6}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{CA5E7959-60B5-47B7-80AC-1606309733F3}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{CEABF027-6CDC-4D47-ADF6-AC5D065826A6}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{E0AA0493-C410-4CBD-B1DB-1723374FA8E0}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{E5D78BD8-3874-4AA0-9D45-CFB79382C484}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\NVideoCodek.Chl]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{77B2F8DE-CB3F-4B6B-839B-807DD1ADBA1C}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{081669BA-EFC4-48C2-A8F4-874052D02553}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{145E6FB1-1256-44ED-A336-8BBA43373BE6}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{1D27320E-2DA2-41E2-A103-B5FD9D6A798B}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B599C57E-113A-4488-A5E9-BC552C4F1152}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{D56A1203-1452-EBA1-7294-EE3377770000}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{C7EDAB2E-D7F9-11D8-BA48-C79B0C409D70}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Classes\Interface\{C7EDAB2E-D7F9-11D8-BA48-C79B0C409D70}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Classes\Typelib\{C7EDAB2E-D7F9-11D8-BA48-C79B0C409D70}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Classes\Serch_hook.transURL]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Classes\Serch_hook.transURL.1]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database\Distribution Units\{11120607-1001-1111-1000-110199901123}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\{081669BA-EFC4-48C2-A8F4-874052D02553}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Internet Connection Update and HomeP KB234087]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\{081669BA-EFC4-48C2-A8F4-874052D02553}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{081669BA-EFC4-48C2-A8F4-874052D02553}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]>>C:\smitfrau.reg echo "{D56A1203-1452-EBA1-7294-EE3377770000}"=->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]>>C:\smitfrau.reg echo "{C7EDAB2E-D7F9-11D8-BA48-C79B0C409D70}"=->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\{E7C9AF76-A50A-423A-A5CA-88DB1A24CEAE}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PSGUARD SPYWARE REMOVER]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]>>C:\smitfrau.reg echo "P.S.Guard"=->>C:\smitfrau.reg echo "Fast Start"=->>C:\smitfrau.reg echo "AntivirusGold"=->>C:\smitfrau.reg echo "PSGuard spyware remover"=->>C:\smitfrau.reg echo "intell32.exe"=->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Update]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager]>>C:\smitfrau.reg echo "AllowProtectedRenames"="0">>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SOFTWARE\AdwareDelete]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Desktop]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]>>C:\smitfrau.reg echo "SNInstall"=->>C:\smitfrau.reg echo "Windows installer"=->>C:\smitfrau.reg echo "SpySheriff"=->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]>>C:\smitfrau.reg echo "ForceActiveDesktopOn"=->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]>>C:\smitfrau.reg echo "Wallpaper"=->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]>>C:\smitfrau.reg echo "DisableTaskMgr"=dword:00000000>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\LocalUser\Software\Microsoft\Windows\CurrentVersion\Policies\System]>>C:\smitfrau.reg echo "DisableTaskMgr"=dword:00000000>>C:\smitfrau.reg echo "**del.DisableTaskMgr"=" ">>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]>>C:\smitfrau.reg echo "DisableTaskMgr"=dword:00000000>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]>>C:\smitfrau.reg echo "DisableCAD"=dword:00000000>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{357A87ED-3E5D-437d-B334-DEB7EB4982A3}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]>>C:\smitfrau.reg echo "WindowsFZ"=->>C:\smitfrau.reg echo "PSGuard"=->>C:\smitfrau.reg echo "intel32.exe"=->>C:\smitfrau.reg echo "RegSvr32"=->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]>>C:\smitfrau.reg echo "Intel system tool"=->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SOFTWARE\AntivirusGold]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]>>C:\smitfrau.reg echo "Use Search Asst"=->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]>>C:\smitfrau.reg echo "NoDispAppearancePage"=->>C:\smitfrau.reg echo "Wallpaper"=->>C:\smitfrau.reg echo "WallpaperStyle"=->>C:\smitfrau.reg echo "NoDispBackgroundPage"=->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]>>C:\smitfrau.reg echo "NoActiveDesktopChanges"=->>C:\smitfrau.reg echo "NoActiveDesktop"=->>C:\smitfrau.reg echo "NoSaveSettings"=->>C:\smitfrau.reg echo "ClassicShell"=->>C:\smitfrau.reg echo "NoThemesTab"=->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]>>C:\smitfrau.reg echo "wininet.dll"=->>C:\smitfrau.reg echo "kernel32.dll"=->>C:\smitfrau.reg echo "nvctrl.exe"=->>C:\smitfrau.reg echo "notepad.exe"=->>C:\smitfrau.reg echo "notepad2.exe"=->>C:\smitfrau.reg echo "winlogon.exe"=->>C:\smitfrau.reg echo "paint.exe"=->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_CURRENT_USER\Control Panel\Desktop]>>C:\smitfrau.reg echo "Wallpaper"=->>C:\smitfrau.reg echo "WallpaperStyle"=->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_CURRENT_USER\Control Panel\Colors]>>C:\smitfrau.reg echo "Background"="0 78 152">>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop]>>C:\smitfrau.reg echo "NoChangingWallPaper"=->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{893fad3a-931e-4e53-b515-b1426d63799b}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3bf1f86f-b1a8-489b-8d8b-43781d51411f}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]>>C:\smitfrau.reg echo "SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm">>C:\smitfrau.reg echo "CustomizeSearch"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm">>C:\smitfrau.reg echo "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch">>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]>>C:\smitfrau.reg echo "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch">>C:\smitfrau.reg echo "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch">>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main]>>C:\smitfrau.reg echo "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch">>C:\smitfrau.reg echo "Search Bar"="Search Bar"="http://search.msn.com/intl/searchpane/en-au/prov2.htm">>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\main]>>C:\smitfrau.reg echo "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch">>C:\smitfrau.reg echo "Search Bar"="http://search.msn.com/spbasic.htm">>C:\smitfrau.reg echo "Use Custom Search URL"=dword:00000000>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]>>C:\smitfrau.reg echo ""="http://home.microsoft.com/access/autosearch.asp?p=%s">>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\VMHomepage]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\CLSID\VMHomepage.1]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\Interface\{1E1B2878-88FF-11D2-8D96-D7ACAC95951F}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\TypeLib\{1E1B286C-88FF-11D2-8D96-D7ACAC95951F}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\VMHomepage]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_CLASSES_ROOT\VMHomepage.1]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objecta]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\HTTP\Parameters\S]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\HTTP\Parameters\S]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\r]>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]>>C:\smitfrau.reg echo "NoActiveDesktopChanges"=hex:00000000>>C:\smitfrau.reg echo "NoActiveDesktop"=dword:00000000>>C:\smitfrau.reg echo "NoSaveSettings"=dword:00000000>>C:\smitfrau.reg echo "ClassicShell"=dword:00000000>>C:\smitfrau.reg echo "NoThemesTab"=dword:00000000>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]>>C:\smitfrau.reg echo "NoDispAppearancePage"=dword:00000000>>C:\smitfrau.reg echo "NoColorChoice"=dword:00000000>>C:\smitfrau.reg echo "NoSizeChoice"=dword:00000000>>C:\smitfrau.reg echo "NoDispBackgroundPage"=dword:00000000>>C:\smitfrau.reg echo "NoDispScrSavPage"=dword:00000000>>C:\smitfrau.reg echo "NoDispCPL"=dword:00000000>>C:\smitfrau.reg echo "NoVisualStyleChoice"=dword:00000000>>C:\smitfrau.reg echo "NoDispSettingsPage"=dword:00000000>>C:\smitfrau.reg echo "NoDispScrSavPage"=dword:00000000>>C:\smitfrau.reg echo "NoVisualStyleChoice"=dword:00000000>>C:\smitfrau.reg echo "NoSizeChoice"=dword:00000000>>C:\smitfrau.reg echo "SetVisualStyle"=->>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop]>>C:\smitfrau.reg echo "NoChangingWallPaper"=dword:00000000>>C:\smitfrau.reg echo "NoAddingComponents"=dword:00000000>>C:\smitfrau.reg echo "NoComponents"=dword:00000000>>C:\smitfrau.reg echo "NoDeletingComponents"=dword:00000000>>C:\smitfrau.reg echo "NoEditingComponents"=dword:00000000>>C:\smitfrau.reg echo "NoCloseDragDropBands"=dword:00000000>>C:\smitfrau.reg echo "NoMovingBands"=dword:00000000>>C:\smitfrau.reg echo "NoHTMLWallPaper"=dword:00000000>>C:\smitfrau.reg echo.>>C:\smitfrau.reg echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ThemeManager]>>C:\smitfrau.reg echo "ThemeActive"="1" echo "DllName"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\>>C:\smitfrau.reg echo 74,00,25,00,5c,00,72,00,65,00,73,00,6f,00,75,00,72,00,63,00,65,00,73,00,5c,\>>C:\smitfrau.reg echo 00,54,00,68,00,65,00,6d,00,65,00,73,00,5c,00,6c,00,75,00,6e,00,61,00,5c,00,\>>C:\smitfrau.reg echo 6c,00,75,00,6e,00,61,00,2e,00,6d,00,73,00,73,00,74,00,79,00,6c,00,65,00,73,\>>C:\smitfrau.reg echo 00,00,00>>C:\smitfrau.reg cls @echo off regedit.exe /s C:\smitfrau.reg echo.>>%systemdrive%\smitfiles.txt echo Deleting files>>%systemdrive%\smitfiles.txt cls @echo off attrib -h -r -s "%AllUsersProfile%\Desktop\WinHound spyware remover.lnk" attrib -h -r -s "%AllUsersProfile%\Bureaublad\WinHound spyware remover.lnk" attrib -h -r -s "%AllUsersProfile%\Start Menu\WinHound spyware remover\*.*" attrib -h -r -s "%AllUsersProfile%\Menu Start\WinHound spyware remover\*.*" del /q "%AllUsersProfile%\Desktop\WinHound spyware remover.lnk" del /q "%AllUsersProfile%\Bureaublad\WinHound spyware remover.lnk" del /q "%AllUsersProfile%\Start Menu\WinHound spyware remover\*.*" del /q "%AllUsersProfile%\Menu Start\WinHound spyware remover\*.*" rmdir /q /s "%AllUsersProfile%\Start Menu\Programs\WinHound spyware remover" rmdir /q /s "%AllUsersProfile%\Menu Start\Programs\WinHound spyware remover" attrib -h -r -s "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinHound spyware remover.lnk" del /q "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinHound spyware remover.lnk" attrib -r -h "%systemdrive%\Archivos de programa\Winhound\Trash\*.*" del /q "%systemdrive%\Archivos de programa\Winhound\Trash\*.*" rmdir "%systemdrive%\Archivos de programa\Winhound\Trash" attrib -r -h %systemdrive%\progra~1\Winhound\Trash\*.* del /q %systemdrive%\progra~1\Winhound\Trash\*.* rmdir %systemdrive%\progra~1\Winhound\Trash\ attrib -r -h "%systemdrive%\Archivos de programa\Winhound\*.*" del /q "%systemdrive%\Archivos de programa\Winhound\*.*" rmdir "%systemdrive%\Archivos de programa\Winhound" attrib -r -h %systemdrive%\progra~1\Winhound\*.* del /q %systemdrive%\progra~1\Winhound\*.* rmdir %systemdrive%\progra~1\Winhound attrib -h -r -s "%AllUsersProfile%\Desktop\WinHound spyware remover.lnk" attrib -h -r -s "%AllUsersProfile%\Bureaublad\WinHound spyware remover.lnk" attrib -h -r -s "%AllUsersProfile%\Start Menu\WinHound spyware remover\*.*" attrib -h -r -s "%AllUsersProfile%\Menu Start\WinHound spyware remover\*.*" del /q "%AllUsersProfile%\Desktop\WinHound spyware remover.lnk" del /q "%AllUsersProfile%\Bureaublad\WinHound spyware remover.lnk" del /q "%AllUsersProfile%\Start Menu\WinHound spyware remover\*.*" del /q "%AllUsersProfile%\Menu Start\WinHound spyware remover\*.*" rmdir /q /s "%AllUsersProfile%\Start Menu\Programs\WinHound spyware remover" rmdir /q /s "%AllUsersProfile%\Menu Start\Programs\WinHound spyware remover" attrib -h -r -s "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinHound spyware remover.lnk" del /q "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinHound spyware remover.lnk" attrib -h -r -s "%AllUsersProfile%\Desktop\Online Security Center.url" attrib -h -r -s "%AllUsersProfile%\Start Menu\Security Troubleshooting.url" attrib -h -r -s "%AllUsersProfile%\Bureaublad\Online Security Center.url" attrib -h -r -s "%AllUsersProfile%\Menu Start\Security Troubleshooting.url" del /q "%AllUsersProfile%\Desktop\Online Security Center.url" del /q "%AllUsersProfile%\Start Menu\Security Troubleshooting.url" del /q "%AllUsersProfile%\Bureaublad\Online Security Center.url" del /q "%AllUsersProfile%\Menu Start\Security Troubleshooting.url" attrib -h -r -s "%AllUsersProfile%\Desktop\Security Troubleshooting.url" attrib -h -r -s "%AllUsersProfile%\Desktop\Online Security Center.url" attrib -h -r -s "%AllUsersProfile%\Start Menu\Security Troubleshooting.url" attrib -h -r -s "%userprofile%\Desktop\Security Troubleshooting.url" attrib -h -r -s "%userprofile%\Desktop\Online Security Center.url" attrib -h -r -s "%userprofile%\Favori~1\Take It Here - Daily Updated Porn Links.url" del /q "%AllUsersProfile%\Desktop\Security Troubleshooting.url" del /q "%AllUsersProfile%\Desktop\Online Security Center.url" del /q "%AllUsersProfile%\Start Menu\Security Troubleshooting.url" del /q "%userprofile%\Desktop\Security Troubleshooting.url" del /q "%userprofile%\Desktop\Online Security Center.url" del /q "%userprofile%\Favori~1\Take It Here - Daily Updated Porn Links.url" attrib -h -r -s "%AllUsersProfile%\Bureaublad\Security Troubleshooting.url" attrib -h -r -s "%AllUsersProfile%\Bureaublad\Online Security Center.url" attrib -h -r -s "%AllUsersProfile%\Menu Start\Security Troubleshooting.url" attrib -h -r -s "%userprofile%\Bureaublad\Security Troubleshooting.url" attrib -h -r -s "%userprofile%\Bureaublad\Online Security Center.url" attrib -h -r -s "%userprofile%\Favori~1\Take It Here - Daily Updated Porn Links.url" del /q "%AllUsersProfile%\Bureaublad\Security Troubleshooting.url" del /q "%AllUsersProfile%\Bureaublad\Online Security Center.url" del /q "%AllUsersProfile%\Menu Start\Security Troubleshooting.url" del /q "%userprofile%\Bureaublad\Security Troubleshooting.url" del /q "%userprofile%\Bureaublad\Online Security Center.url" del /q "%userprofile%\Favori~1\Take It Here - Daily Updated Porn Links.url" attrib -r -h "%systemdrive%\Archivos de programa\spyaxe\*.*" del /q "%systemdrive%\Archivos de programa\spyaxe\*.*" rmdir "%systemdrive%\Archivos de programa\spyaxe" attrib -r -h %systemdrive%\progra~1\spyaxe\*.* del /q %systemdrive%\progra~1\spyaxe\*.* rmdir %systemdrive%\progra~1\spyaxe attrib -h -r -s "%systemdrive%\Archivos de programa\SpyTrooper\*.*" del /q "%systemdrive%\Archivos de programa\SpyTrooper\*.*" rmdir /q /s "%systemdrive%\Archivos de programa\SpyTrooper" attrib -h -r -s "%systemdrive%\Archivos de programa\Security Toolbar\*.*" del /q "%systemdrive%\Archivos de programa\Security Toolbar\*.*" rmdir /q /s "%systemdrive%\Archivos de programa\Security Toolbar" attrib -h -r -s "%systemdrive%\progra~1\SpyTrooper\*.*" del /q "%systemdrive%\progra~1\SpyTrooper\*.*" rmdir /q /s "%systemdrive%\progra~1\SpyTrooper" attrib -h -r -s "%systemdrive%\progra~1\Security Toolbar\*.*" del /q "%systemdrive%\progra~1\Security Toolbar\*.*" rmdir /q /s "%systemdrive%\progra~1\Security Toolbar" attrib -r -h -s "%userprofile%\Bureaublad\SpyTrooper.lnk" attrib -r -h -s "%UserProfile%\Desktop\SpyTrooper.lnk" del /q "%userprofile%\Bureaublad\SpyTrooper.lnk" del /q "%UserProfile%\Desktop\SpyTrooper.lnk" attrib -h -r -s "%userprofile%\Menu Start\Programma's\SpyTrooper\*.*" del /q "%userprofile%\Menu Start\Programma's\SpyTrooper\*.*" rmdir /q /s "%userprofile%\Menu Start\Programma's\SpyTrooper" attrib -h -r -s "%userprofile%\Start Menu\Programs\SpyTrooper\*.*" del /q "%userprofile%\Start Menu\Programs\SpyTrooper\*.*" rmdir /q /s "%userprofile%\Start Menu\Programs\SpyTrooper" attrib -r -h -s "%UserProfile%\Favori~1\Free XXX Sites List.url" del /q "%userprofile%\Favori~1\Free XXX Sites List.url" attrib -r -h -s "%UserProfile%\Favori~1\Antivirus Test Online.url" del /q "%UserProfile%\Favori~1\Antivirus Test Online.url" attrib -h -r -s "%AllUsersProfile%\Favori~1\Cheap Viagra.url" attrib -h -r -s "%AllUsersProfile%\Favori~1\Buy Viagra Online.url" attrib -h -r -s "%AllUsersProfile%\Start Menu\Anti SPAM.url" attrib -h -r -s "%AllUsersProfile%\Start Menu\Online Casino.url" attrib -h -r -s "%AllUsersProfile%\Start Menu\Online Security Center.url" attrib -h -r -s "%AllUsersProfile%\Start Menu\Computer Security.url" del /q "%AllUsersProfile%\Favori~1\Cheap Viagra.url" del /q "%AllUsersProfile%\Favori~1\Buy Viagra Online.url" del /q "%AllUsersProfile%\Start Menu\Anti SPAM.url" del /q "%AllUsersProfile%\Start Menu\Online Casino.url" del /q "%AllUsersProfile%\Start Menu\Online Security Center.url" del /q "%AllUsersProfile%\Start Menu\Computer Security.url" attrib -h -r -s "%AllUsersProfile%\Desktop\Security Troubleshooting.lnk" attrib -h -r -s "%AllUsersProfile%\Desktop\Online Security Center.lnk" del /q "%AllUsersProfile%\Desktop\Security Troubleshooting.lnk" del /q "%AllUsersProfile%\Desktop\Online Security Center.lnk" attrib -h -r -s "%AllUsersProfile%\Menu Start\Anti SPAM.url" attrib -h -r -s "%AllUsersProfile%\Menu Start\Online Casino.url" attrib -h -r -s "%AllUsersProfile%\Menu Start\Online Security Center.url" attrib -h -r -s "%AllUsersProfile%\Menu Start\Computer Security.url" del /q "%AllUsersProfile%\Menu Start\Anti SPAM.url" del /q "%AllUsersProfile%\Menu Start\Online Casino.url" del /q "%AllUsersProfile%\Menu Start\Online Security Center.url" del /q "%AllUsersProfile%\Menu Start\Computer Security.url" attrib -h -r -s "%AllUsersProfile%\Bureaublad\Security Troubleshooting.lnk" attrib -h -r -s "%AllUsersProfile%\Bureaublad\Online Security Center.lnk" del /q "%AllUsersProfile%\Bureaublad\Security Troubleshooting.lnk" del /q "%AllUsersProfile%\Bureaublad\Online Security Center.lnk" attrib -h -r -s "%systemroot%\Application Data\Shudder Global Limited\*.*" del /q "%systemroot%\Application Data\Shudder Global Limited\*.*" rmdir /q /s "%systemroot%\Application Data\Shudder Global Limited" attrib -h -r -s "%userprofile%\application data\shudder global limited\*.*" del /q "%userprofile%\application data\shudder global limited\*.*" rmdir /q /s "%userprofile%\application data\shudder global limited" attrib -r -h -s "%userprofile%\Bureaublad\Air Tickets.url" attrib -r -h -s "%userprofile%\Bureaublad\Big Tits.url" attrib -r -h -s "%userprofile%\Bureaublad\Blackjack.url" attrib -r -h -s "%userprofile%\Bureaublad\Britney Spears.url" attrib -r -h -s "%userprofile%\Bureaublad\Car Insurance.url" attrib -r -h -s "%userprofile%\Bureaublad\Cheap Cigarettes.url" attrib -r -h -s "%userprofile%\Bureaublad\Credit Card.url" attrib -r -h -s "%userprofile%\Bureaublad\Cruises.url" attrib -r -h -s "%userprofile%\Bureaublad\Currency Trading.url" attrib -r -h -s "%userprofile%\Bureaublad\Lesbian Sex.url" attrib -r -h -s "%userprofile%\Bureaublad\MP3.url" attrib -r -h -s "%userprofile%\Bureaublad\Online Betting.url" attrib -r -h -s "%userprofile%\Bureaublad\Online Gambling.url" attrib -r -h -s "%userprofile%\Bureaublad\Oral Sex.url" attrib -r -h -s "%userprofile%\Bureaublad\Party Poker.url" attrib -r -h -s "%userprofile%\Bureaublad\Pharmacy.url" attrib -r -h -s "%userprofile%\Bureaublad\Phentermine.url" attrib -r -h -s "%userprofile%\Bureaublad\Pornstars.url" attrib -r -h -s "%userprofile%\Bureaublad\Remove Spyware.url" attrib -r -h -s "%userprofile%\Bureaublad\viagra.url" attrib -r -h -s "%UserProfile%\Desktop\Air Tickets.url" attrib -r -h -s "%UserProfile%\Desktop\Big Tits.url" attrib -r -h -s "%UserProfile%\Desktop\Blackjack.url" attrib -r -h -s "%UserProfile%\Desktop\Britney Spears.url" attrib -r -h -s "%UserProfile%\Desktop\Car Insurance.url" attrib -r -h -s "%UserProfile%\Desktop\Cheap Cigarettes.url" attrib -r -h -s "%UserProfile%\Desktop\Credit Card.url" attrib -r -h -s "%UserProfile%\Desktop\Cruises.url" attrib -r -h -s "%UserProfile%\Desktop\Currency Trading.url" attrib -r -h -s "%UserProfile%\Desktop\Lesbian Sex.url" attrib -r -h -s "%UserProfile%\Desktop\MP3.url" attrib -r -h -s "%UserProfile%\Desktop\Online Betting.url" attrib -r -h -s "%UserProfile%\Desktop\Online Gambling.url" attrib -r -h -s "%UserProfile%\Desktop\Oral Sex.url" attrib -r -h -s "%UserProfile%\Desktop\Party Poker.url" attrib -r -h -s "%UserProfile%\Desktop\Pharmacy.url" attrib -r -h -s "%UserProfile%\Desktop\Phentermine.url" attrib -r -h -s "%UserProfile%\Desktop\Pornstars.url" attrib -r -h -s "%UserProfile%\Desktop\Remove Spyware.url" attrib -r -h -s "%UserProfile%\Desktop\viagra.url" attrib -r -h -s "%UserProfile%\Favori~1\Need Money.url" del /q "%userprofile%\Bureaublad\Air Tickets.url" del /q "%userprofile%\Bureaublad\Big Tits.url" del /q "%userprofile%\Bureaublad\Blackjack.url" del /q "%userprofile%\Bureaublad\Britney Spears.url" del /q "%userprofile%\Bureaublad\Car Insurance.url" del /q "%userprofile%\Bureaublad\Cheap Cigarettes.url" del /q "%userprofile%\Bureaublad\Credit Card.url" del /q "%userprofile%\Bureaublad\Cruises.url" del /q "%userprofile%\Bureaublad\Currency Trading.url" del /q "%userprofile%\Bureaublad\Lesbian Sex.url" del /q "%userprofile%\Bureaublad\MP3.url" del /q "%userprofile%\Bureaublad\Online Betting.url" del /q "%userprofile%\Bureaublad\Online Gambling.url" del /q "%userprofile%\Bureaublad\Oral Sex.url" del /q "%userprofile%\Bureaublad\Party Poker.url" del /q "%userprofile%\Bureaublad\Pharmacy.url" del /q "%userprofile%\Bureaublad\Phentermine.url" del /q "%userprofile%\Bureaublad\Pornstars.url" del /q "%userprofile%\Bureaublad\Remove Spyware.url" del /q "%userprofile%\Bureaublad\viagra.url" del /q "%UserProfile%\Desktop\Air Tickets.url" del /q "%UserProfile%\Desktop\Big Tits.url" del /q "%UserProfile%\Desktop\Blackjack.url" del /q "%UserProfile%\Desktop\Britney Spears.url" del /q "%UserProfile%\Desktop\Car Insurance.url" del /q "%UserProfile%\Desktop\Cheap Cigarettes.url" del /q "%UserProfile%\Desktop\Credit Card.url" del /q "%UserProfile%\Desktop\Cruises.url" del /q "%UserProfile%\Desktop\Currency Trading.url" del /q "%UserProfile%\Desktop\Lesbian Sex.url" del /q "%UserProfile%\Desktop\MP3.url" del /q "%UserProfile%\Desktop\Online Betting.url" del /q "%UserProfile%\Desktop\Online Gambling.url" del /q "%UserProfile%\Desktop\Oral Sex.url" del /q "%UserProfile%\Desktop\Party Poker.url" del /q "%UserProfile%\Desktop\Pharmacy.url" del /q "%UserProfile%\Desktop\Phentermine.url" del /q "%UserProfile%\Desktop\Pornstars.url" del /q "%UserProfile%\Desktop\Remove Spyware.url" del /q "%UserProfile%\Desktop\viagra.url" del /q "%UserProfile%\Favori~1\Need Money.url" attrib -h -r -s "%AllUsersProfile%\Start Menu\Programs\PSGuard spyware remover\*.*" del /q "%AllUsersProfile%\Start Menu\Programs\PSGuard spyware remover\*.*" rmdir /q /s "%AllUsersProfile%\Start Menu\Programs\PSGuard spyware remover" attrib -h -r -s "%AllUsersProfile%\Start Menu\Programs\PSGuard spyware remover\*.*" del /q "%AllUsersProfile%\Start Menu\Programs\PSGuard spyware remover\*.*" rmdir /q /s "%AllUsersProfile%\Start Menu\Programs\PSGuard spyware remover" attrib -h -r -s "%UserProfile%\Bureaublad\AntivirusGold.lnk" del /q "%UserProfile%\Bureaublad\AntivirusGold.lnk" attrib -h -r -s "%UserProfile%\Desktop\AntivirusGold.lnk" del /q "%UserProfile%\Desktop\AntivirusGold.lnk" attrib -h -r -s "%AllUsersProfile%\Bureaublad\PSGuard spyware remover.lnk" del /q "%AllUsersProfile%\Bureaublad\PSGuard spyware remover.lnk" attrib -h -r -s "%AllUsersProfile%\Desktop\PSGuard spyware remover.lnk" del /q "%AllUsersProfile%\Desktop\PSGuard spyware remover.lnk" attrib -h -r -s "%userprofile%\Favori~1\adult\*.*" attrib -h -r -s "%userprofile%\Favori~1\cars\*.*" attrib -h -r -s "%userprofile%\Favori~1\sexual life\*.*" attrib -h -r -s "%userprofile%\Favori~1\shopping\*.*" attrib -h -r -s "%userprofile%\Favori~1\anti spam.url" attrib -h -r -s "%userprofile%\Favori~1\job search.url" attrib -h -r -s "%userprofile%\Favori~1\poker.url" attrib -h -r -s "%userprofile%\Favori~1\spyware removal.url" del /q "%userprofile%\Favori~1\adult\*.*" del /q "%userprofile%\Favori~1\cars\*.*" del /q "%userprofile%\Favori~1\sexual life\*.*" del /q "%userprofile%\Favori~1\shopping\*.*" rmdir "%userprofile%\Favori~1\adult" rmdir "%userprofile%\Favori~1\cars" rmdir "%userprofile%\Favori~1\sexual life" rmdir "%userprofile%\Favori~1\shopping" del /q "%userprofile%\Favori~1\anti spam.url" del /q "%userprofile%\Favori~1\job search.url" del /q "%userprofile%\Favori~1\poker.url" del /q "%userprofile%\Favori~1\spyware removal.url" attrib -h -r -s "%userprofile%\Favori~1\Online Gambling\*.*" attrib -h -r -s "%userprofile%\Favori~1\online dating.url" attrib -h -r -s "%userprofile%\Favori~1\Black Jack Online.url" attrib -h -r -s "%userprofile%\Favori~1\Black Jack Online.url" attrib -h -r -s "%userprofile%\Favori~1\Home Loan.url" attrib -h -r -s "%userprofile%\Favori~1\Network Security.url" attrib -h -r -s "%userprofile%\Favori~1\Online Dating.url" attrib -h -r -s "%userprofile%\Favori~1\Online Gambling.url" attrib -h -r -s "%userprofile%\Favori~1\Online Pharmacy\*.*" attrib -h -r -s "%userprofile%\Favori~1\Online Pharmacy.url" attrib -h -r -s "%userprofile%\Favori~1\Remove Spyware.url" attrib -h -r -s "%userprofile%\Favori~1\Spam Filters.url" attrib -h -r -s "%userprofile%\Favori~1\Take It Here - Free * TGP.url" attrib -h -r -s "%userprofile%\Favori~1\Web Detective.url" del /q "%userprofile%\Favori~1\Online Gambling\*.*" del /q "%userprofile%\Favori~1\online dating.url" del /q "%userprofile%\Favori~1\Black Jack Online.url" del /q "%userprofile%\Favori~1\Black Jack Online.url" del /q "%userprofile%\Favori~1\Home Loan.url" del /q "%userprofile%\Favori~1\Network Security.url" del /q "%userprofile%\Favori~1\Online Dating.url" del /q "%userprofile%\Favori~1\Online Gambling.url" del /q "%userprofile%\Favori~1\Online Pharmacy\*.*" del /q "%userprofile%\Favori~1\Online Pharmacy.url" del /q "%userprofile%\Favori~1\Remove Spyware.url" del /q "%userprofile%\Favori~1\Spam Filters.url" del /q "%userprofile%\Favori~1\Take It Here - Free * TGP.url" del /q "%userprofile%\Favori~1\Web Detective.url" rmdir /q /s "%userprofile%\Favori~1\Online Gambling" rmdir /q /s "%userprofile%\Favori~1\Online Pharmacy" rmdir /q /s "%userprofile%\Favori~1\Online Gambling" rmdir /q /s "%userprofile%\Favori~1\Online Pharmacy" attrib -h -r -s "%systemdrive%\Archivos de programa\P.S.Guard\*.*" del /q "%systemdrive%\Archivos de programa\P.S.Guard\*.*" rmdir /q /s "%systemdrive%\Archivos de programa\P.S.Guard" attrib -h -r -s "%systemdrive%\progra~1\P.S.Guard\*.*" del /q "%systemdrive%\progra~1\P.S.Guard\*.*" rmdir /q /s "%systemdrive%\progra~1\P.S.Guard" attrib -h -r -s "%systemdrive%\Archivos de programa\Security IGuard\*.*" attrib -h -r -s "%systemdrive%\Archivos de programa\Virtual Maid\*.*" attrib -h -r -s "%systemdrive%\Archivos de programa\Search Maid\*.*" attrib -h -r -s "%systemdrive%\Archivos de programa\AntiVirusGold\*.*" attrib -h -r -s "%systemdrive%\Archivos de programa\PSGuard\*.*" attrib -h -r -s "%systemdrive%\Archivos de programa\SpySheriff\*.*" del /q "%systemdrive%\Archivos de programa\Security IGuard\*.*" del /q "%systemdrive%\Archivos de programa\Virtual Maid\*.*" del /q "%systemdrive%\Archivos de programa\Search Maid\*.*" del /q "%systemdrive%\Archivos de programa\AntiVirusGold\*.*" del /q "%systemdrive%\Archivos de programa\PSGuard\*.*" del /q "%systemdrive%\Archivos de programa\SpySheriff\*.*" rmdir /q /s "%systemdrive%\Archivos de programa\Security IGuard" rmdir /q /s "%systemdrive%\Archivos de programa\Virtual Maid" rmdir /q /s "%systemdrive%\Archivos de programa\Search Maid" rmdir /q /s "%systemdrive%\Archivos de programa\AntiVirusGold" rmdir /q /s "%systemdrive%\Archivos de programa\PSGuard" rmdir /q /s "%systemdrive%\Archivos de programa\SpySheriff" attrib -h -r -s "%allusersprofile%\Bureaublad\Spyware Removal.url" attrib -h -r -s "%allusersprofile%\Bureaublad\Online Dating.url" attrib -h -r -s "%allusersprofile%\Bureaublad\Online Pharmacy.url" del /q "%allusersprofile%\Bureaublad\Spyware Removal.url" del /q "%allusersprofile%\Bureaublad\Online Dating.url" del /q "%allusersprofile%\Bureaublad\Online Pharmacy.url" attrib -h -r -s "%allusersprofile%\Desktop\Spyware Removal.url" attrib -h -r -s "%allusersprofile%\Desktop\Online Dating.url" attrib -h -r -s "%allusersprofile%\Desktop\Online Pharmacy.url" del /q "%allusersprofile%\Desktop\Spyware Removal.url" del /q "%allusersprofile%\Desktop\Online Dating.url" del /q "%allusersprofile%\Desktop\Online Pharmacy.url" attrib -h -r -s "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSGuard spyware remover.lnk" del /q "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSGuard spyware remover.lnk" attrib -h -r -s "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSGuard.lnk" del /q "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSGuard.lnk" attrib -h -r -s "%userprofile%\Menu Start\Programma's\SpySheriff\*.*" del /q "%userprofile%\Menu Start\Programma's\SpySheriff\*.*" rmdir /q /s "%userprofile%\Menu Start\Programma's\SpySheriff" attrib -h -r -s "%UserProfile%\Bureaublad\SpySheriff.lnk" del /q "%UserProfile%\Bureaublad\SpySheriff.lnk" attrib -h -r -s "%AllUsersProfile%\Bureaublad\PSGuard.lnk" del /q "%AllUsersProfile%\Bureaublad\PSGuard.lnk" attrib -h -r -s "%userprofile%\Application Data\PSGuard.com\*.*" del /q "%userprofile%\Application Data\PSGuard.com\*.*" rmdir /q /s "%userprofile%\Application Data\PSGuard.com" attrib -h -r -s "%userprofile%\Start Menu\Programs\SpySheriff\*.*" del /q /s "%userprofile%\Start Menu\Programs\SpySheriff\*.*" rmdir /q /s "%userprofile%\Start Menu\Programs\SpySheriff" attrib -h -r -s "%userprofile%\Application Data\Install.dat" del /q "%userprofile%\Application Data\Install.dat" attrib -h -r -s "%UserProfile%\Desktop\SpySheriff.lnk" del /q "%UserProfile%\Desktop\SpySheriff.lnk" attrib -h -r -s "%AllUsersProfile%\Desktop\PSGuard.lnk" del /q ""%AllUsersProfile%\Desktop\PSGuard.lnk" attrib -h -r -s "%systemdrive%\progra~1\Security IGuard\*.*" attrib -h -r -s "%systemdrive%\progra~1\Virtual Maid\*.*" attrib -h -r -s "%systemdrive%\progra~1\Search Maid\*.*" attrib -h -r -s "%systemdrive%\progra~1\AntiVirusGold\*.*" attrib -h -r -s "%systemdrive%\progra~1\PSGuard\*.*" attrib -h -r -s "%systemdrive%\progra~1\SpySheriff\*.*" del /q "%systemdrive%\progra~1\Security IGuard\*.*" del /q "%systemdrive%\progra~1\Virtual Maid\*.*" del /q "%systemdrive%\progra~1\Search Maid\*.*" del /q "%systemdrive%\progra~1\AntiVirusGold\*.*" del /q "%systemdrive%\progra~1\PSGuard\*.*" del /q "%systemdrive%\progra~1\SpySheriff\*.*" rmdir /q /s "%systemdrive%\progra~1\Security IGuard" rmdir /q /s "%systemdrive%\progra~1\Virtual Maid" rmdir /q /s "%systemdrive%\progra~1\Search Maid" rmdir /q /s "%systemdrive%\progra~1\AntiVirusGold" rmdir /q /s "%systemdrive%\progra~1\PSGuard" rmdir /q /s "%systemdrive%\progra~1\SpySheriff" attrib -h -r -s %temp%\*.* del /q %temp%\*.* rmdir /q /s %temp% mkdir %temp% cls @echo off cd %systemroot%\system32 cls @echo off attrib -r -h -s wbeconm.dll del /q wbeconm.dll attrib -r -h -s "_plastilin_" attrib -r -h -s "atmtd.dll" attrib -r -h -s "atmtd.dll._" attrib -r -h -s "Defpia32.dll" attrib -r -h -s "fhpd.dll" attrib -r -h -s "Kdfdlh32.dll" attrib -r -h -s "klja.dll" attrib -r -h -s "ll.exe" attrib -r -h -s "Mhpcja32.dll" attrib -r -h -s "Nbfgemln.exe" attrib -r -h -s "ongi.dll" attrib -r -h -s "perflibs__" attrib -r -h -s "svcp.csv" attrib -r -h -s "sywsvcs.exe" attrib -r -h -s "windesktop.dll" attrib -r -h -s "windesktop.exe" attrib -r -h -s "wins32.dll" attrib -r -h -s "winselect.exe" attrib -r -h -s "winsub.xml" attrib -r -h -s "zlbw.dll" del /q "_plastilin_" del /q "atmtd.dll" del /q "atmtd.dll._" del /q "Defpia32.dll" del /q "fhpd.dll" del /q "Kdfdlh32.dll" del /q "klja.dll" del /q "ll.exe" del /q "Mhpcja32.dll" del /q "Nbfgemln.exe" del /q "ongi.dll" del /q "perflibs__" del /q "svcp.csv" del /q "sywsvcs.exe" del /q "windesktop.dll" del /q "windesktop.exe" del /q "wins32.dll" del /q "winselect.exe" del /q "winsub.xml" del /q "zlbw.dll" attrib -r -h -s ioctrl.dll del /q ioctrl.dll attrib -r -h -s svchosts.dll del /q svchosts.dll attrib -r -h -s oleext32.dll del /q oleext32.dll attrib -r -h -s ff.tmp del /q ff.tmp attrib -h -r -s 1024\*.* del /q 1024\*.* del /q 1024\*.* rmdir /q /s 1024 attrib -r -h -s svchop.exe attrib -r -h -s shdochop.dll attrib -h -r -s ts.ico attrib -h -r -s ot.ico attrib -r -h -s ptainfo1.ico attrib -r -h -s ptainfo2.ico attrib -r -h -s zlbw.dll attrib -r -h -s msvol.tlb attrib -r -h -s ld****.tmp attrib -r -h -s mssearchnet.exe attrib -r -h -s ncompat.tlb attrib -r -h -s nvctrl.exe attrib -r -h -s mscornet.exe attrib -r -h -s gunist.exe attrib -r -h -s param32.dll attrib -r -h -s pop_up.dll attrib -r -h -s MP3.ico attrib -r -h -s Pharmacy.ico attrib -r -h -s viagra.ico attrib -r -h -s "searchdll.dll" attrib -r -h -s "Air Tickets.ico" attrib -r -h -s "Big Tits.ico" attrib -r -h -s "Blackjack.ico" attrib -r -h -s "Britney Spears.ico" attrib -r -h -s "Car Insurance.ico" attrib -r -h -s "Cheap Cigarettes.ico" attrib -r -h -s "Credit Card.ico" attrib -r -h -s Cruises.ico attrib -r -h -s "Currency Trading.ico" attrib -r -h -s "Lesbian Sex.ico" attrib -r -h -s "Online Betting.ico" attrib -r -h -s "Online Gambling.ico" attrib -r -h -s "Oral Sex.ico" attrib -r -h -s "Party Poker.ico" attrib -r -h -s "Phentermine.ico" attrib -r -h -s "Pornstars.ico" attrib -r -h -s "Remove Spyware.ico" del /q svchop.exe del /q shdochop.dll del /q ts.ico del /q ot.ico del /q ptainfo1.ico del /q ptainfo2.ico del /q zlbw.dll del /q msvol.tlb del /q ld****.tmp del /q mssearchnet.exe del /q ncompat.tlb del /q nvctrl.exe del /q mscornet.exe del /q gunist.exe del /q param32.dll del /q pop_up.dll del /q MP3.ico del /q Pharmacy.ico del /q viagra.ico del /q "searchdll.dll" del /q "Air Tickets.ico" del /q "Big Tits.ico" del /q "Blackjack.ico" del /q "Britney Spears.ico" del /q "Car Insurance.ico" del /q "Cheap Cigarettes.ico" del /q "Credit Card.ico" del /q Cruises.ico del /q "Currency Trading.ico" del /q "Lesbian Sex.ico" del /q "Online Betting.ico" del /q "Online Gambling.ico" del /q "Oral Sex.ico" del /q "Party Poker.ico" del /q "Phentermine.ico" del /q "Pornstars.ico" del /q "Remove Spyware.ico" attrib -h -r -s thn.dll del /q thn.dll attrib -h -r -s "__delete_on_reboot__intel32.exe" del /q "__delete_on_reboot__intel32.exe" attrib -h -r -s "__delete_on_reboot__OLEADM.dll" del /q "__delete_on_reboot__OLEADM.dll" attrib -h -r -s intell32.exe del /q intell32.exe attrib -h -r -s oleext.dll del /q oleext.dll attrib -h -r -s oleadm.dll del /q oleadm.dll attrib -h -r -s wppp.html del /q wppp.html attrib -h -r -s svcnt.exe del /q svcnt.exe attrib -h -r -s intel32.exe del /q intel32.exe attrib -h -r -s hhk.dll.tcf del /q hhk.dll.tcf attrib -h -r -s perfcii.ini del /q perfcii.ini attrib -h -r -s oleadm32.dll del /q oleadm32.dll attrib -h -r -s wp.bmp del /q wp.bmp attrib -h -r -s hookdump.exe del /q hookdump.exe attrib -h -r -s winnook.exe del /q winnook.exe attrib -h -r -s wldr.dll del /q wldr.dll attrib -h -r -s helper.exe del /q helper.exe attrib -h -r -s intmonp.exe del /q intmonp.exe attrib -h -r -s msmsgs.exe del /q msmsgs.exe attrib -h -r -s ole32vbs.exe del /q ole32vbs.exe attrib -h -r -s msole32.exe del /q msole32.exe attrib -h -r -s hp***.tmp del /q hp***.tmp attrib -h -r -s shnlog.exe del /q shnlog.exe attrib -h -r -s intmon.exe del /q intmon.exe attrib -h -r -s hhk.dll del /q hhk.dll attrib -h -r -s "__delete_on_reboot__intmon.exe" del /q "__delete_on_reboot__intmon.exe" attrib -h -r -s "Log Files\*.*" attrib -h -r -s logfiles\*.* del /q "Log Files\*.*" del /q logfiles\*.* rmdir /q /s "Log Files" rmdir /q /s logfiles cls @echo off cd %systemroot% cls @echo off attrib -r -h %systemroot%\RGF2ZQ\*.* del /q %systemroot%\RGF2ZQ\*.* rmdir %systemroot%\RGF2ZQ attrib -h -r -s warnhp.html del /q warnhp.html attrib -h -r -s wp.bmp del /q wp.bmp attrib -h -r -s uninstIU.exe del /q uninstIU.exe attrib -h -r -s zloader3.exe del /q zloader3.exe attrib -h -r -s desktop.html del /q desktop.html attrib -h -r -s screen.html del /q screen.html attrib -h -r -s sites.ini del /q sites.ini attrib -h -r -s popuper.exe del /q popuper.exe attrib -h -r -s prefetch\*.* del /q prefetch\*.* del /q /s prefetch attrib -h -r -s temp\*.* del /q temp\*.* rmdir /q /s temp mkdir temp cls @echo off cd %systemroot%\system32\config\system~1\Local Settings cls @echo off attrib -h -r -s temp\*.* del /q temp\*.* rmdir /q /s temp mkdir temp cls @echo off cd %systemroot%\system32\config\system~1\Local Settings\Tempor~1 cls @echo off attrib -h -r -s "Content.IE5\*.*" del /q "Content.IE5\*.*" rmdir /q /s "Content.IE5" mkdir "Content.IE5" cls @echo off cd \ cls @echo off IF EXIST \temp attrib -h -r -s \temp\*.* IF EXIST \temp del /q temp\*.* attrib -h -r -s bsw.exe del /q bsw.exe attrib -h -r -s wp.exe del /q wp.exe attrib -h -r -s wp.bmp del /q wp.bmp attrib -h -r -s bsw.bmp del /q bsw.bmp attrib -h -r -s winstall.exe del /q winstall.exe cd %systemroot%\system32 IF EXIST wininet.dll GOTO test IF NOT EXIST wininet.dll GOTO missing :missing del /q %systemdrive%\delfiles.cmd cls @echo off echo.>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo Remaining Post-run Files>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo ~~~ Program Files ~~~>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\Archivos de programa\Winhound" echo Winhound>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\progra~1\Winhound" echo Winhound>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\Archivos de programa\spyaxe" echo SpyAxe>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\progra~1\spyaxe" echo SpyAxe>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\Archivos de programa\SpyTrooper" echo SpyTrooper>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\Archivos de programa\Security Toolbar" echo Security Toolbar>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\progra~1\SpyTrooper" echo SpyTrooper>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\progra~1\Security Toolbar" echo Security Toolbar>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\Archivos de programa\P.S.Guard" echo P.S.Guard>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\Archivos de programa\Security IGuard" echo Security IGuard>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\Archivos de programa\Virtual Maid" echo Virtual Maid>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\Archivos de programa\Search Maid" echo Search Maid>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\Archivos de programa\AntiVirusGold" echo AntiVirusGold>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\Archivos de programa\PSGuard" echo PSGuard>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\Archivos de programa\SpySheriff" echo SpySheriff>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\progra~1\P.S.Guard" echo P.S.Guard>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\progra~1\Security IGuard" echo Security IGuard>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\progra~1\Virtual Maid" echo Virtual Maid>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\progra~1\Search Maid" echo Search Maid>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\progra~1\AntiVirusGold" echo AntiVirusGold>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\progra~1\PSGuard echo" PSGuard>>%systemdrive%\smitfiles.txt IF EXIST "%systemdrive%\progra~1\SpySheriff" echo SpySheriff>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo ~~~ Shortcuts ~~~>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Desktop\WinHound spyware remover.lnk" echo WinHound spyware remover.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Bureaublad\WinHound spyware remover.lnk" echo WinHound spyware remover.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinHound spyware remover.lnk" echo quick launch WinHound spyware remover.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Start Menu\Programs\WinHound spyware remover" echo WinHound spyware remover folder>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Menu Start\Programs\WinHound spyware remover" echo WinHound spyware remover folder>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Desktop\Online Security Guide.url" echo Online Security Guide.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Start Menu\Online Security Guide.url" echo Online Security Guide.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Bureaublad\Online Security Guide.url" echo Online Security Guide.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Menu Start\Online Security Guide.url" echo Online Security Guide.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Desktop\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Desktop\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Start Menu\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Desktop\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Desktop\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Bureaublad\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Bureaublad\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Menu Start\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\SpyTrooper.lnk" echo SpyTrooper.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\SpyTrooper.lnk" echo SpyTrooper.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Menu Start\Programma's\SpyTrooper" echo SpyTrooper folder>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Start Menu\Programs\SpyTrooper" echo SpyTrooper folder>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Favori~1\Cheap Viagra.url" echo Cheap Viagra.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Favori~1\Buy Viagra Online.url" echo Buy Viagra Online.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Start Menu\Anti SPAM.url" echo Anti SPAM.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Start Menu\Online Casino.url" echo Online Casino.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Start Menu\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Start Menu\Computer Security.url" echo Computer Security.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Desktop\Security Troubleshooting.lnk" echo Security Troubleshooting.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Desktop\Online Security Center.lnk" echo Online Security Center.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\favorieten\Cheap Viagra.url" echo Cheap Viagra.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\favorieten\Buy Viagra Online.url" echo Buy Viagra Online.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Menu Start\Anti SPAM.url" echo Anti SPAM.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Menu Start\Online Casino.url" echo Online Casino.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Menu Start\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Menu Start\Computer Security.url" echo Computer Security.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Bureaublad\Security Troubleshooting.lnk" echo Security Troubleshooting.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Bureaublad\Online Security Center.lnk" echo Online Security Center.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Air Tickets.url" echo Air Tickets.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Big Tits.url" echo Big Tits.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Blackjack.url" echo Blackjack.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Britney Spears.url" echo Britney Spears.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Car Insurance.url" echo Car Insurance.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Cheap Cigarettes.url" echo Cheap Cigarettes.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Credit Card.url" echo Credit Card.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Cruises.url" echo Cruises.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Currency Trading.url" echo Currency Trading.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Lesbian Sex.url" echo Lesbian Sex.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\MP3.url" echo MP3.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Online Betting.url" echo Online Betting.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Online Gambling.url" echo Online Gambling.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Oral Sex.url" echo Oral Sex.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Party Poker.url" echo Party Poker.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Pharmacy.url" echo Pharmacy.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Phentermine.url" echo Phentermine.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Pornstars.url" echo job Pornstars.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\Remove Spyware.url" echo Remove Spyware.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Bureaublad\viagra.url" echo viagra.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Air Tickets.url" echo Air Tickets.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Big Tits.url" echo Big Tits.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Blackjack.url" echo Blackjack.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Britney Spears.url" echo Britney Spears.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Car Insurance.url" echo Car Insurance.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Cheap Cigarettes.url" echo Cheap Cigarettes.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Credit Card.url" echo Credit Card.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Cruises.url" echo Cruises.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Currency Trading.url" echo Currency Trading.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Lesbian Sex.url" echo Lesbian Sex.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\MP3.url" echo MP3.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Online Betting.url" echo Online Betting.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Online Gambling.url" echo Online Gambling.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Oral Sex.url" echo Oral Sex.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Party Poker.url" echo Party Poker.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Pharmacy.url" echo Pharmacy.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Phentermine.url" echo Phentermine.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Pornstars.url" echo job Pornstars.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\Remove Spyware.url" echo Remove Spyware.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\viagra.url" echo viagra.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Start Menu\Programs\PSGuard spyware remover" echo PSGuard spyware remover>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Menu Start\Programma's\PSGuard spyware remover" echo PSGuard spyware remover>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Bureaublad\AntivirusGold.lnk" echo AntivirusGold.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\AntivirusGold.lnk" echo AntivirusGold.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Bureaublad\PSGuard spyware remover.lnk" echo PSGuard spyware remover.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Desktop\PSGuard spyware remover.lnk" echo PSGuard spyware remover.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Bureaublad\Spyware Removal.url" echo Spyware Removal.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Bureaublad\Online Dating.url" echo Online Dating.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Bureaublad\Online Pharmacy.url" echo Online Pharmacy.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Desktop\Spyware Removal.url" echo Spyware Removal.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Desktop\Online Dating.url" echo Online Dating.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Desktop\Online Pharmacy.url" echo Online Pharmacy.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSGuard spyware remover.lnk" echo quick launch PSGuard spyware remover.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSGuard.lnk" echo quick launch PSGuard.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Menu Start\Programma's\SpySheriff" echo SpySheriff>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Bureaublad\SpySheriff.lnk" echo SpySheriff.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Bureaublad\PSGuard.lnk" echo PSGuard.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Application Data\PSGuard.com" echo PSGuard.com>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Start Menu\Programs\SpySheriff" echo SpySheriff>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Application Data\Install.dat" echo Install.dat>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Desktop\SpySheriff.lnk" echo SpySheriff.lnk>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Desktop\PSGuard.lnk" echo PSGuard.lnk>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo ~~~ Favorites ~~~>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Take It Here - Daily Updated Porn Links.url" echo Take It Here - Daily Updated Porn Links.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Take It Here - Daily Updated Porn Links.url" echo Take It Here - Daily Updated Porn Links.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Favori~1\Free XXX Sites List.url" echo Free XXX Sites List.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Favori~1\Antivirus Test Online.url" echo Antivirus Test Online.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Favori~1\Cheap Viagra.url" echo Cheap Viagra.url>>%systemdrive%\smitfiles.txt IF EXIST "%AllUsersProfile%\Favori~1\Buy Viagra Online.url" echo Buy Viagra Online.url>>%systemdrive%\smitfiles.txt IF EXIST "%UserProfile%\Favori~1\Need Money.url" echo Need Money.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\adult" echo adult>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\cars" echo cars>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\sexual life" echo sexual life>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\shopping" echo shopping>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\anti spam.url" echo anti spam.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\job search.url" echo job search.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\poker.url" echo poker.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\spyware removal.url" echo spyware removal.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Online Gambling.url" echo Online Gambling.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\online dating.url" echo online dating.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Black Jack Online.url" echo Black Jack Online.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Online Pharmacy\Adipex.url" echo Online Pharmacy\Adipex.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Black Jack Online.url" echo Black Jack Online.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Home Loan.url" echo Home Loan.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Network Security.url" echo Network Security.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Online Dating.url" echo Online Dating.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Adipex.url" echo Adipex.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Alprazolam.url" echo Alprazolam.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Carisoprodol.url" echo Carisoprodol.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Diazepam.url" echo Diazepam.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Hydrocodone.url" echo Hydrocodone.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Lortab.url" echo Lortab.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Online Pharmacy.url" echo Online Pharmacy.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Prozac.url" echo Prozac.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Valium.url" echo Valium.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Vicodin.url" echo Vicodin.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Xanax.url" echo Xanax.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Remove Spyware.url" echo Remove Spyware.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Spam Filters.url" echo Spam Filters.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Take It Here - Free * TGP.url" echo Take It Here - Free * TGP.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Web Detective.url" echo Web Detective.url>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Online Gambling" echo Online Gambling folder>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\Favori~1\Online Pharmacy" echo Online Pharmacy folder>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo ~~~ system32 folder ~~~>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\wbeconm.dll" echo wbeconm.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\_plastilin_" echo _plastilin_>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\atmtd.dll" echo atmtd.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\atmtd.dll._" echo atmtd.dll._>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Defpia32.dll" echo Defpia32.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\fhpd.dll" echo fhpd.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Kdfdlh32.dll" echo Kdfdlh32.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\klja.dll" echo klja.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\ll.exe" echo ll.exe>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Mhpcja32.dll" echo Mhpcja32.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Nbfgemln.exe" echo Nbfgemln.exe>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\ongi.dll" echo ongi.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\perflibs__" echo perflibs__>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\svcp.csv" echo svcp.csv>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\sywsvcs.exe" echo sywsvcs.exe>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\windesktop.dll" echo windesktop.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\windesktop.exe" echo windesktop.exe>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\wins32.dll" echo wins32.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\winselect.exe" echo winselect.exe>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\winsub.xml" echo winsub.xml>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\zlbw.dll" echo zlbw.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\ioctrl.dll" echo ioctrl.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\svchosts.dll" echo svchosts.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\ff.tmp" echo ff.tmp>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\oleext32.dll" echo oleext32.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\1024" echo 1024 dir>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\svchop.exe" echo svchop.exe>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\shdochop.dll" echo shdochop.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\zlbw.dll" echo zlbw.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\msvol.tlb" echo msvol.tlb>>%systemdrive%\smitfiles.txt IF EXIST "%systemroot%\system32\ld****.tmp" echo ld****.tmp>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\mssearchnet.exe" echo mssearchnet.exe>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\ncompat.tlb" echo ncompat.tlb>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\nvctrl.exe" echo nvctrl.exe>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\mscornet.exe" echo mscornet.exe>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\gunist.exe" echo gunist.exe>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\param32.dll" echo param32.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\pop_up.dll" echo pop_up.dll>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\searchdll.dll" echo searchdll.dll>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\thn.dll echo thn.dll>>%systemdrive%\smitfiles.txt IF EXIST "%systemroot%\system32\__delete_on_reboot__intel32.exe" echo __delete_on_reboot__intel32.exe>>%systemdrive%\smitfiles.txt IF EXIST "%systemroot%\system32\__delete_on_reboot__OLEADM.dll" echo __delete_on_reboot__OLEADM.dll>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\intell32.exe echo intell32.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\oleext.dll echo oleext.dll>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\wppp.html echo wppp.html>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\svcnt.exe echo svcnt.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\oleadm.dll echo oleadm.dll>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\intel32.exe echo intel32.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\hhk.dll.tcf echo hhk.dll.tcf>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\perfcii.ini echo perfcii.ini>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\oleadm32.dll echo oleadm32.dll>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\wp.bmp echo wp.bmp>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\hookdump.exe echo hookdump.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\winnook.exe echo winnook.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\wldr.dll echo wldr.dll>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\helper.exe echo helper.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\intmonp.exe echo intmonp.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\msmsgs.exe echo msmsgs.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\ole32vbs.exe echo ole32vbs.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\msole32.exe echo msole32.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\hp***.tmp echo hp***.tmp>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\shnlog.exe echo shnlog.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\intmon.exe echo intmon.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\hhk.dll echo hhk.dll>>%systemdrive%\smitfiles.txt IF EXIST "%systemroot%\system32\__delete_on_reboot__intmon.exe" echo __delete_on_reboot__intmon.exe>>%systemdrive%\smitfiles.txt IF EXIST "%systemroot%\system32\Log Files" echo Log Files>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\system32\logfiles echo logfiles>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo ~~~ Icons in System32 ~~~>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\ts.ico" echo ts.ico>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\ot.ico" echo ot.ico>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\ptainfo1.ico" echo ptainfo1>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\ptainfo2.ico" echo ptainfo2>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Air Tickets.ico" echo Air Tickets>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Big Tits.ico" echo Big Tits>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Blackjack.ico" echo Blackjack>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Britney Spears.ico" echo Britney Spears>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Car Insurance.ico" echo Car Insurance>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Cheap Cigarettes.ico" echo Cheap Cigarettes>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Credit Card.ico" echo Credit Card>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Cruises.ico" echo Cruises>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Currency Trading.ico" echo Currency Trading>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Lesbian Sex.ico" echo Lesbian Sex>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\MP3.ico" echo MP3>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Online Betting.ico" echo Online Betting>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Online Gambling.ico" echo Online Gambling>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Oral Sex.ico" echo Oral Sex>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Party Poker.ico" echo Party Poker>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Pharmacy.ico" echo Pharmacy>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Phentermine.ico" echo Phentermine>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Pornstars.ico" echo Pornstars>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\Remove Spyware.ico" echo Remove Spyware>>%systemdrive%\smitfiles.txt IF EXIST "%Systemroot%\system32\viagra.ico" echo viagra>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo ~~~ Windows directory ~~~>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\RGF2ZQ echo RGF2ZQ folder>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\warnhp.html echo warnhp.html>>%systemdrive%\smitfiles.txt IF EXIST "%systemroot%\Application Data\Shudder Global Limited" echo Application Data\Shudder Global Limited>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\wp.bmp echo wp.bmp>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\uninstIU.exe echo uninstIU.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\zloader3.exe echo zloader3.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\desktop.html echo desktop.html>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\screen.html echo screen.html>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\sites.ini echo sites.ini>>%systemdrive%\smitfiles.txt IF EXIST %systemroot%\popuper.exe echo popuper.exe>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo ~~~ Drive root ~~~>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF EXIST %systemdrive%\bsw.exe echo bsw.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemdrive%\wp.exe echo wp.exe>>%systemdrive%\smitfiles.txt IF EXIST %systemdrive%\wp.bmp echo wp.bmp>>%systemdrive%\smitfiles.txt IF EXIST %systemdrive%\bsw.bmp echo bsw.bmp>>%systemdrive%\smitfiles.txt IF EXIST %systemdrive%\winstall.exe echo winstall.exe>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo ~~~ Miscellaneous Files/folders ~~~>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF EXIST "%userprofile%\application data\shudder global limited" echo shudder global limited>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt IF EXIST %systemdrive%\winstall.exe echo winstall.exe>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo ~~~ Wininet.dll ~~~>>%systemdrive%\smitfiles.txt echo.>>%systemdrive%\smitfiles.txt echo wininet.dll is missing!!>>%systemdrive%\smitfiles.txt GOTO finish :test cls Eli mitä teen väärin?
Sun koneessa F8 tuo esiin boot menun eikä sitä valikkoa. Tee näin: * Sulje kaikki ohjelmat. * Klikkaa käynnistä -> suorita -> msconfig ja OK * Valitse BOOT.INI-välilehti, merkkaa "/SAFEBOOT"-valinta, ja sitten klikkaa OK ja käynnistä kone uudelleen sitä pyydettäessä * Tietokone käynnistyy vikasietotilaan * Tee vikasietotilassa pyydetyt toimenpiteet(eli aja se RunThis.bat smitrem-kansiosta ohjeiden mukaan). * Kun olet valmis, mene uudelleen msconfigiin kuten edellä ja ota valinta pois BOOT.INI-välilehdeltä "/SAFEBOOT"-kohdasta ja paina OK, jolloin koneesi käynnistyy normaalisti. EDIT: Ja editoi toi edellinen viesti vähän pienemmäks Lähetä uusi HjT-loki ja c:\smitfiles.txt-tiedoston sisältö
Nyt alkaa näyttää valoisammalta! hjt-loki tässä: Logfile of HijackThis v1.99.1 Scan saved at 13:09:35, on 30.12.2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Norman\Nvc\BIN\NPFSVICE.EXE C:\Norman\bin\ZANDA.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\wdfmgr.exe C:\Norman\Nvc\BIN\NVCSCHED.EXE C:\Norman\Nvc\BIN\nipsvc.exe C:\Norman\bin\NJEEVES.EXE C:\Norman\Nvc\bin\nvcoas.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Norman\bin\ZLH.EXE C:\Program Files\Microsoft AntiSpyware\gcasServ.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Norman\Nvc\BIN\NIP.EXE C:\Norman\Nvc\bin\cclaw.exe C:\Norman\Npf\BIN\npfmsg2.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\WINDOWS\system32\wuauclt.exe C:\hjt\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.utu.fi/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.utu.fi/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1121071860546 O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O18 - Filter: text/html - (no CLSID) - (no file) O18 - Filter: text/plain - (no CLSID) - (no file) O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE O23 - Service: Norman Type-R - Unknown owner - C:\Norman\Nvc\BIN\NPFSVICE.EXE O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\bin\ZANDA.EXE O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe ja smitfiles.txt tässä: smitRem © log file version 2.8 by noahdfear Microsoft Windows XP [versio 5.1.2600] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ checking for ShudderLTD key ShudderLTD key not present! checking for PSGuard.com key PSGuard.com key not present! checking for WinHound.com key WinHound.com key not present! ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ SpyAxeFix © by noahdfear spyaxe directory present spyaxe uninstaller present Starting spyaxe uninstaller REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" "{A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F}"="Security Update" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Winhound uninstaller NOT present ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Existing Pre-run Files ~~~ Program Files ~~~ SpyAxe ~~~ Shortcuts ~~~ ~~~ Favorites ~~~ ~~~ system32 folder ~~~ wbeconm.dll 1024 dir msvol.tlb ld****.tmp mssearchnet.exe ncompat.tlb nvctrl.exe hp***.tmp ~~~ Icons in System32 ~~~ ts.ico ot.ico ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~ Miscellaneous Files/folders ~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03 Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org Killing PID 728 'explorer.exe' Starting registry repairs Deleting files Remaining Post-run Files ~~~ Program Files ~~~ SpyAxe ~~~ Shortcuts ~~~ ~~~ Favorites ~~~ ~~~ system32 folder ~~~ ~~~ Icons in System32 ~~~ ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~ Miscellaneous Files/folders ~~~ ~~~ Wininet.dll ~~~ CLEAN! Uskaltaako tässä nyt jo riemuita (ja nöyrimmästi kiittää auttajaansa)?
Aika hyvä Poista tämä hakemisto, jos on. C:\Program Files\==>SpyAxe<== Ja fixaa nämä rivit HjT:llä: O18 - Filter: text/html - (no CLSID) - (no file) O18 - Filter: text/plain - (no CLSID) - (no file) Muuten on kunnossa.
Kyseiset rivit fixattu, SpyAxe-hakemistoja ei löytynyt, kaikki kunnossa! Tuhannesti kiitoksia avusta!
Onhan tämä nyt sitten varmasti puhdas? Aloin epäillä, kun Normanin tarkistus kertoi löytäneensä (ja siirtäneensä karanteeniin) tiedostoja, joissa oli troijalainen nimeltään W32/Zlob.GC Logfile of HijackThis v1.99.1 Scan saved at 17:35:00, on 30.12.2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Norman\Nvc\BIN\NPFSVICE.EXE C:\Norman\bin\ZANDA.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\wdfmgr.exe C:\Norman\bin\NJEEVES.EXE C:\Norman\Nvc\BIN\nipsvc.exe C:\Norman\Nvc\BIN\NVCSCHED.EXE C:\Norman\Nvc\bin\nvcoas.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Norman\bin\ZLH.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Norman\Nvc\bin\cclaw.exe C:\Norman\Nvc\BIN\NIP.EXE C:\Norman\Npf\BIN\npfmsg2.exe C:\WINDOWS\system32\wuauclt.exe C:\hjt\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.utu.fi/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.utu.fi/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1121071860546 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O18 - Filter: text/html - (no CLSID) - (no file) O18 - Filter: text/plain - (no CLSID) - (no file) O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE O23 - Service: Norman Type-R - Unknown owner - C:\Norman\Nvc\BIN\NPFSVICE.EXE O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\bin\ZANDA.EXE O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Tyhjennä se Normanin karanteeni vikasietotilassa. Norman on "säilönyt" noita spyaxen pöpöjä sinne. Ja fixaa nämä (vikasietotilassa, jos eivät muuten lähde): O18 - Filter: text/html - (no CLSID) - (no file) O18 - Filter: text/plain - (no CLSID) - (no file)