spyaxe piinaa

Discussion in 'Virukset ja haittaohjelmat' started by despvi, Dec 29, 2005.

  1. despvi

    despvi Member

    Joined:
    Dec 29, 2005
    Messages:
    7
    Likes Received:
    0
    Trophy Points:
    11
    Apuva!

    Spyaxe-ohjelma ei jätä rauhaan. Pyydän nöyrimmästi apua (mahd. yksinkertaisesti selitettynä, olen amatööri). HJT-logi tässä:

    Logfile of HijackThis v1.99.1
    Scan saved at 18:13:04, on 29.12.2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Norman\Nvc\BIN\NPFSVICE.EXE
    C:\Norman\bin\ZANDA.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\Norman\Nvc\BIN\NVCSCHED.EXE
    C:\Norman\Nvc\BIN\nipsvc.exe
    C:\Norman\bin\NJEEVES.EXE
    C:\Norman\Nvc\bin\nvcoas.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\nvctrl.exe
    C:\WINDOWS\system32\mssearchnet.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Norman\bin\ZLH.EXE
    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Norman\Nvc\BIN\NIP.EXE
    C:\Norman\Nvc\bin\cclaw.exe
    C:\Norman\Npf\BIN\npfmsg2.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\DOCUME~1\Eero\LOCALS~1\Temp\Tilapäinen kansio 3 hijackthis.zip\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.utu.fi/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.utu.fi/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O2 - BHO: (no name) - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hpEFAF.tmp (file missing)
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll (file missing)
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1121071860546
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe
    O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE
    O23 - Service: Norman Type-R - Unknown owner - C:\Norman\Nvc\BIN\NPFSVICE.EXE
    O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\bin\ZANDA.EXE
    O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe
    O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
     
  2. -kemisti-

    -kemisti- Active member

    Joined:
    Jun 6, 2005
    Messages:
    6,305
    Likes Received:
    0
    Trophy Points:
    96
    Siirrä HjT omaan hakemistoonsa -> c:\hjt\HijackThis.exe

    Fixaa HjT:llä (do a system scan only, merkkaa ja paina fix checked):

    O2 - BHO: (no name) - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hpEFAF.tmp (file missing)
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll (file missing)

    Hae smitrem täältä -> http://noahdfear.geekstogo.com/click counter/click.php?id=1
    Tallenna työpöydälle ja tuplaklikkaa sitä, jolloin se luo smitRem-kansion työpöydälle.

    Käynnistä vikasietotilaan (paina F8 käynnistyksen yhteydessä, kunnes tulee valikko. Valitse valikosta vikasietotila), avaa smitRem-kansio ja tuplaklikkaa RunThis.bat. Seuraa ohjeita. Käynnistä kone uudestaan, lähetä uusi HjT-loki ja c:\smitfiles.txt-tiedoston sisältö.


     
  3. despvi

    despvi Member

    Joined:
    Dec 29, 2005
    Messages:
    7
    Likes Received:
    0
    Trophy Points:
    11
    En ole aivan varma, pääsinkö siihen vikasietotilaan. Konetta käynnistettäessä painoin F8:a ja ruutuun tuli: "Please select boot device: SM-HL-DT-ST DVD-RW GWA-4163B
    PM-SAMSUNG SP1604N
    ESC to boot using defaults"

    Ja aina sen jälkeen kone aukeaa ihan normaalisti. Niin että millaiselta sen vikasietotilan kuuluisi näyttää? Smitrem haettu, eikä se RunThis.bat näytä tekevän mitään. Sen muistio näyttää tältä:

    @echo off

    VER|find "Windows 2000">NUL
    IF NOT ERRORLEVEL 1 GOTO notice

    VER|find "Windows XP">NUL
    IF NOT ERRORLEVEL 1 GOTO notice

    VER|find "Windows 95">NUL
    IF NOT ERRORLEVEL 1 GOTO notice1

    VER|find "Windows 98">NUL
    IF NOT ERRORLEVEL 1 GOTO notice1

    VER|find "Windows Millennium">NUL
    IF NOT ERRORLEVEL 1 GOTO notice1

    VER|find "Windows 2003">NUL
    IF NOT ERRORLEVEL 1 GOTO notice

    echo Unsupported Version
    goto end

    :notice
    color 1F

    cls
    @echo off
    echo.
    echo.
    echo.
    echo ÉÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ»
    echo º º
    echo º Trojan-Spy.HTML.smitfraud.c Killer º
    echo º º
    echo º by noahdfear º
    echo º º
    echo º version 2.8 © º
    echo º º
    echo ÈÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍͼ
    echo.
    echo This tool was tailored to remove smitfraud.c and variants
    echo.
    echo If you do not trust the source, close this window.
    echo.
    echo noahdfear does not assume any liability
    echo.
    echo for damage or loss from running this tool
    echo.
    echo Use at your own risk!!
    echo.
    echo.
    echo.
    echo.
    pause
    cls
    @echo off
    echo.
    echo.
    echo This tool will also clean out the contents of temp folders
    echo.
    echo and the Prefetch folder. It will also run disk cleanup
    echo.
    echo to clear the Temporary Internet Files on this user profile,
    echo.
    echo as well as empty the recycle bin.
    echo.
    echo.
    echo.
    echo.
    pause
    cls

    GOTO menu2

    :notice1
    cls
    @echo off
    echo.
    echo.
    echo.
    echo ÉÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ»
    echo º º
    echo º Trojan-Spy.HTML.smitfraud.c Killer º
    echo º º
    echo º by noahdfear º
    echo º º
    echo º version 2.8 © º
    echo º º
    echo ÈÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍͼ
    echo.
    echo This tool was tailored to remove smitfraud.c and variants
    echo.
    echo If you do not trust the source, close this window.
    echo.
    echo noahdfear does not assume any liability
    echo.
    echo for damage or loss from running this tool
    echo.
    echo Use at your own risk!!
    echo.
    echo Press 1 to continue or E to exit
    echo.
    echo.
    echo.
    echo.
    CHOICE /C:1E /N

    IF errorlevel==2 GOTO done
    IF errorlevel==1 GOTO menu3
    cls

    :menu3
    cls
    @echo off
    echo.
    echo.
    echo This tool will also clean out the contents of temp folders.
    echo.
    echo It will also run disk cleanup to clear the Temporary Internet Files
    echo.
    echo as well as empty the recycle bin
    echo.
    echo.
    echo Press 1 to continue or E to exit
    echo.
    echo.
    echo.
    echo.
    CHOICE /C:1E /N

    IF errorlevel==2 GOTO done
    IF errorlevel==1 GOTO menu2
    cls

    :menu2
    cls
    @echo off

    VER|find "Windows 2000">NUL
    IF NOT ERRORLEVEL 1 GOTO NT

    VER|find "Windows XP">NUL
    IF NOT ERRORLEVEL 1 GOTO NT

    VER|find "Windows 95">NUL
    IF NOT ERRORLEVEL 1 GOTO win

    VER|find "Windows 98">NUL
    IF NOT ERRORLEVEL 1 GOTO win

    VER|find "Windows Millennium">NUL
    IF NOT ERRORLEVEL 1 GOTO win

    VER|find "Windows 2003">NUL
    IF NOT ERRORLEVEL 1 GOTO NT

    :NT

    cls
    @echo off
    echo.
    echo.
    echo Please close ALL windows except this one
    echo.
    echo including the folder you opened to run this tool
    echo.
    echo Your desktop and taskbar will disappear when you press a key
    echo.
    echo this window will remain open and others may open.
    echo.
    echo During this time the bad files will be deleted
    echo.
    echo When your desktop returns,
    echo.
    echo continue as instructed by your advisor.
    echo.
    echo Your desktop background will be reset to blue when you reboot.
    echo.
    echo.
    echo.
    echo.
    echo.
    pause


    IF EXIST %systemdrive%\LTD.txt del %systemdrive%\LTD.txt
    IF EXIST %systemdrive%\PSGuard.txt del %systemdrive%\PSGuard.txt


    cls
    @echo off
    IF EXIST %systemdrive%\smitfiles.txt del %systemdrive%\smitfiles.txt

    echo.>>%systemdrive%\smitfiles.txt
    echo smitRem © log file>>%systemdrive%\smitfiles.txt
    echo version 2.8>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo by noahdfear>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    VER>>%systemdrive%\smitfiles.txt
    echo. |date |find "current" >>%systemdrive%\smitfiles.txt
    echo. |time |find "current" >>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>%systemdrive%\smitfiles.txt
    cls
    @echo off
    echo.>>%systemdrive%\smitfiles.txt
    echo checking for ShudderLTD key>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    regedit.exe /e %systemdrive%\LTD.txt "HKEY_LOCAL_MACHINE\SOFTWARE\SHUDDERLTD"

    IF EXIST %systemdrive%\LTD.txt echo ShudderLTD key present!>>%systemdrive%\smitfiles.txt
    IF NOT EXIST %systemdrive%\LTD.txt echo ShudderLTD key not present!>>%systemdrive%\smitfiles.txt

    IF EXIST %systemdrive%\LTD.txt GOTO LTDFix
    IF NOT EXIST %systemdrive%\LTD.txt GOTO psgcheck

    :LTDFix
    cls
    @echo off
    echo.>>%systemdrive%\smitfiles.txt
    echo Running LTDFix/PSGuard.com fix!>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo checking for PSGuard.com key>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt

    regedit.exe /e %systemdrive%\PSGuard.txt "HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com"

    IF EXIST %systemdrive%\PSGuard.txt echo PSGuard.com key present!>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    IF NOT EXIST %systemdrive%\PSGuard.txt echo PSGuard.com key not present!>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt

    cls
    @echo off
    echo.>>%systemdrive%\smitfiles.txt
    echo.
    echo.
    echo SmitRem © add-on ShudderLTD/PSGuard.com registry Fix
    echo.
    echo by Miekiemoes, Atribune and noahdfear
    echo.
    echo.
    echo.
    echo.
    pause


    cls
    @echo off
    echo REGEDIT4>>C:\psguardrem.reg
    echo.>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.FoundCollection]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.FoundCollection.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.FoundObject]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.FoundObject.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.KilledProcessesCollection]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.KilledProcessesCollection.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.KilledProcessInfo]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.KilledProcessInfo.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.License]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.License.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.Options]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.Options.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.Quarantine]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.Quarantine.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.RealTime]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.RealTime.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.RTObject]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.RTObject.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.SafeMode]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.SafeMode.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.Scaner]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.Scaner.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.ScanStatistic]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.ScanStatistic.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.theApp]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.theApp.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.Update]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.Update.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.UpdateInfo]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.UpdateInfo.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.VersionInfo]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.VersionInfo.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\WndLayer.Window]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\WndLayer.Window.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\WndLayer.WindowCollection]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\WndLayer.WindowCollection.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\WndLayer.WindowLayer]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\WndLayer.WindowLayer.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{F880B4F2-75BF-44EC-B7AA-45EC37448027}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{E479197F-49E5-4E60-9FA2-A71D4C7C2BBC}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{E12AAACF-8AF2-4C31-BA94-E3787B44F90E}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{D25F7446-4D36-4203-9EA5-5422B26FA9D0}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{CDD964C2-FB78-4A74-BB1E-1CB1FCB72018}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{CBE4B748-08F9-44DB-8FB1-9AD25979DA35}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{C5B70256-5B08-4056-B84E-C6CE084967F5}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{ACC647EE-991A-4811-B420-F063F50CDDC1}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{8DCA6B3D-1FCA-4500-B210-76119BB5C69E}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{8C2A05C5-780F-4A2E-AE1C-FB8181F860E4}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{82847700-FE61-46A3-B3EE-761A1E312ACA}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{7198F8DA-012C-4DB4-ABD8-923A54C87900}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{67196B3E-55A0-49DE-BA11-66F07DF804DB}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{5E5A79A6-C67B-444E-BE58-BD0ACEFCDA07}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{58E68548-42E2-479D-A9E0-86D9F2EAF02E}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{5206DF89-97FC-41AD-BAE3-993E87053A99}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{4F93062D-7BDA-48BE-AEB6-88AF2B1FE2D4}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{4AA55E8C-2C19-4F3A-91EC-43B6DF937C4F}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{41D7BB0A-64E0-4AB2-BD0B-69EA78E462E8}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{0EA04667-E53B-4E81-8E7C-DE2CA114CBD6}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{3946A33D-BBC6-4792-A383-D855E0F76D91}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{265C2AF8-C94C-4AFF-B2B6-340D3982562C}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{0878F045-B52E-46B3-9724-D3AE69D50067}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{04F3168F-5AFC-4531-B3B4-16CA93720415}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{187A8428-BD94-470D-A178-A2347F940519}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{2865930B-4588-4FF3-8227-6D4F66C92C7A}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{2FE2EDC0-9E62-4F34-8A73-BC66DAE48EF3}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{3A3A8C24-8FF0-4140-9731-54D9483EA70B}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{3A906593-B4BD-48ED-84B0-3249BED65EF9}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{49B72A72-01F5-4AE8-BBD7-DAA67F1E303B}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{6AE3ACA6-1BE3-4443-98DD-EFFCFA793D35}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{9F89E240-06A6-4E1C-BA84-F267DE7DB391}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{79DDF2EF-D881-464B-B2AF-5AF8816A3964}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{813C8E86-4C90-4617-B59E-E130CC068140}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{89133BCE-57D0-4D2B-AFAF-A97B74AD704E}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{8F40CC34-FE77-4618-AA3D-BD2EFACAA8DC}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{9F89E240-06A6-4E1C-BA84-F267DE7DB391}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{B60A0E56-548D-40AE-9383-D752531F653F}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{B67B0756-2528-4996-B4BD-C993614CC0B6}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{BCC51EA9-6340-4EBE-8736-13A752ECB0BE}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{E9719D38-EC55-4C8B-9DF0-080ADE95A9FA}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{F4B3E25A-33B4-4647-9A78-B627DDE211A6}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{08101C3E-6C90-439E-9734-6E4DD1B53B69}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{0BACA3C1-F734-4A5F-970A-15DBF7D3C09C}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{09B90087-4FFA-4A44-BE69-DA117A710F07}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{0D4385DF-F78A-4264-A32C-7DD4A72DE539}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{1449F89C-AD28-427A-97FF-1D5BD812EA43}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{19A0B5C9-65FE-4D3B-8BDD-EFB7FE553C58}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{1C08D3D0-1E04-4DDE-AB0A-75355EA2585E}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{19C99256-D011-47E2-BC64-6322096E20A5}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{20F8B70D-9F16-4DCB-8788-90A0498E46B9}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{2871B7AF-2D4C-478F-BE89-881881C272AB}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{28FEDB90-53C7-4928-994A-CEE782606507}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{2B94CDFD-4A45-4B08-B105-54C709D07B28}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{3A350193-C7F7-4E10-B347-02FF4C3CC4E9}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{2C354A9B-A5DF-41A3-BF40-2D72FEAC14D3}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{4723879B-8F52-4BE7-9994-626AFA539366}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{2C797AA0-978C-4AC2-BBB4-F89D410B614E}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{7B6A3434-8625-4ABF-B79D-09D98C2498C4}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{54007809-0689-4A40-9D8F-94C79D87D931}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{8B6C0168-BAAC-4C7C-911E-0132590F5661}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{557C3787-D066-496E-8CAF-BA47DA7365C1}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{8EC33B7D-9953-4EDB-ACE2-D4C105968601}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{5C083B7E-A083-4B20-A7AD-7C8E29085494}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{A00E2305-7001-4200-BA00-5779F9A3E7D3}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{649D371E-D3E3-4FC0-AC82-E91F73D8E79E}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{B803D266-A08D-4A4C-9604-6D35689ABE09}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{655980F1-13D5-4DA2-9E80-AA56C36876CB}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{A917B2F3-A9BF-477C-A0E3-0382D0376159}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{6AF126A9-B07A-4DE4-883E-28D3ECCD75D8}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{B26B5883-F15F-4283-B3D5-A1728077DE47}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{6B436BDD-8B8B-4A1F-ADD5-E67B30C8F7DD}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{B803D266-A08D-4A4C-9604-6D35689ABE09}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{71BF80FD-7E91-4730-B6E8-8F3E81F5C38B}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{CB9385AB-8541-4B2F-A363-48F64C612993}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{81723C8C-918F-4456-B7E8-A68CF7A10C6D}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{D6A7D177-0B2F-4283-B2E8-B6310A45E606}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{82A10659-A1E5-4732-A839-C910D955C88B}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{D5D6E9B5-30D5-4457-AC8B-399205F50411}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{84844B27-0D53-4C71-AB24-0151B33AB02F}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{D6A7D177-0B2F-4283-B2E8-B6310A45E606}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{A8BCF2B9-ED19-4637-AC77-BF59F131FA1F}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{E0D6C30A-B9A3-4181-8099-3B0D5A2B98AF}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{A9A73A66-B0E0-4FFB-828F-3A55E1FA4271}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{B6049D5D-718F-44C0-B965-06840D27E206}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{F100A342-3AC5-47FF-B5B3-FCDB6FC9F016}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{B817D284-1B82-4793-B1F3-58A06DAB03A1}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{BC077DD0-42B5-451C-B78C-4AC97E4B116B}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{C123DBA0-52DF-4272-BBAA-BFD092D07C2E}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{CB9DD914-68B6-4710-A04E-4745470706CE}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{DE1E317F-716A-4784-BA90-FDA6D6A8FAD5}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{E36DCDBC-57AD-4A1C-B9C6-1161441B51CA}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{E51AC62C-E82E-4E60-97AB-C66C4969AF39}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{EF5750B1-0ABA-45C5-BF12-FB4D1D1150D2}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{F1D9585E-20A6-4689-84C7-C19FE21C9A71}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{F1E1A6B0-6CAC-471B-99C4-4DBADA883BE8}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{F8C9D1A9-B7B7-47CA-8B93-27C5B64D3A47}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\TypeLib\{F61D1CE1-5199-4B57-B59E-C6819EA92F3B}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\TypeLib\{31E956BF-8CA9-4D75-B534-7EBC79770002}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\TypeLib\{6E9E448E-B195-4627-953C-5377FA9BBA36}]>>C:\psguardrem.reg
    echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PSGuard spyware remover]>>C:\psguardrem.reg
    echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\P.S.Guard spyware remover]>>C:\psguardrem.reg

    swreg add HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.comdummy
    swreg add HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTDdummy
    swreg save HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTDdummy ShudderLTDdummy.hiv
    swreg save HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.comdummy PSGuard.comdummy.hiv
    swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTDdummy /f
    swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.comdummy /f
    swreg restore HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTD ShudderLTDdummy.hiv
    swreg restore HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com PSGuard.comdummy.hiv
    swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTD /f
    swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com /f

    regedit /s C:\psguardrem.reg

    del ShudderLTDdummy.hiv
    del PSGuard.comdummy.hiv

    del /q C:\psguardrem.reg
    del /q %systemdrive%\LTD.txt
    del /q %systemdrive%\PSGuard.txt

    regedit.exe /e %systemdrive%\LTD.txt "HKEY_LOCAL_MACHINE\SOFTWARE\SHUDDERLTD"

    IF EXIST %systemdrive%\LTD.txt echo ShudderLTD key was NOT successfully removed!>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    IF NOT EXIST %systemdrive%\LTD.txt echo ShudderLTD key was successfully removed! :)>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt

    regedit.exe /e %systemdrive%\PSGuard.txt "HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com"

    IF EXIST %systemdrive%\PSGuard.txt echo PSGuard.com key was NOT successfully removed!>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    IF NOT EXIST %systemdrive%\PSGuard.txt echo if previously present, PSGuard.com key was successfully removed! :)>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt

    del /q %systemdrive%\PSGuard.txt
    del /q %systemdrive%\LTD.txt

    GOTO WinHchck

    :psgcheck
    cls
    @echo off
    echo.>>%systemdrive%\smitfiles.txt
    echo checking for PSGuard.com key>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt

    regedit.exe /e %systemdrive%\PSGuard.txt "HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com"

    IF EXIST %systemdrive%\PSGuard.txt echo PSGuard.com key present!>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    IF NOT EXIST %systemdrive%\PSGuard.txt echo PSGuard.com key not present!>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt

    IF EXIST %systemdrive%\PSGuard.txt GOTO psgfix
    IF NOT EXIST %systemdrive%\PSGuard.txt GOTO WinHchck

    :psgfix
    cls
    @echo off
    echo.>>%systemdrive%\smitfiles.txt
    echo Running LTDFix/PSGuard.com fix!>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    cls
    @echo off
    echo.>>%systemdrive%\smitfiles.txt
    echo.
    echo.
    echo SmitRem © add-on ShudderLTD/PSGuard.com registry Fix
    echo.
    echo by Miekiemoes, Atribune and noahdfear
    echo.
    echo.
    echo.
    echo.
    pause

    cls
    @echo off
    echo REGEDIT4>>C:\psguardrem.reg
    echo.>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.FoundCollection]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.FoundCollection.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.FoundObject]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.FoundObject.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.KilledProcessesCollection]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.KilledProcessesCollection.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.KilledProcessInfo]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.KilledProcessInfo.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.License]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.License.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.Options]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.Options.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.Quarantine]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.Quarantine.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.RealTime]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.RealTime.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.RTObject]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.RTObject.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.SafeMode]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.SafeMode.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.Scaner]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.Scaner.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.ScanStatistic]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.ScanStatistic.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.theApp]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.theApp.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.Update]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.Update.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.UpdateInfo]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.UpdateInfo.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.VersionInfo]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\AVECore.VersionInfo.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\WndLayer.Window]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\WndLayer.Window.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\WndLayer.WindowCollection]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\WndLayer.WindowCollection.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\WndLayer.WindowLayer]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\WndLayer.WindowLayer.1]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{F880B4F2-75BF-44EC-B7AA-45EC37448027}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{E479197F-49E5-4E60-9FA2-A71D4C7C2BBC}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{E12AAACF-8AF2-4C31-BA94-E3787B44F90E}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{D25F7446-4D36-4203-9EA5-5422B26FA9D0}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{CDD964C2-FB78-4A74-BB1E-1CB1FCB72018}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{CBE4B748-08F9-44DB-8FB1-9AD25979DA35}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{C5B70256-5B08-4056-B84E-C6CE084967F5}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{ACC647EE-991A-4811-B420-F063F50CDDC1}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{8DCA6B3D-1FCA-4500-B210-76119BB5C69E}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{8C2A05C5-780F-4A2E-AE1C-FB8181F860E4}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{82847700-FE61-46A3-B3EE-761A1E312ACA}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{7198F8DA-012C-4DB4-ABD8-923A54C87900}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{67196B3E-55A0-49DE-BA11-66F07DF804DB}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{5E5A79A6-C67B-444E-BE58-BD0ACEFCDA07}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{58E68548-42E2-479D-A9E0-86D9F2EAF02E}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{5206DF89-97FC-41AD-BAE3-993E87053A99}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{4F93062D-7BDA-48BE-AEB6-88AF2B1FE2D4}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{4AA55E8C-2C19-4F3A-91EC-43B6DF937C4F}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{41D7BB0A-64E0-4AB2-BD0B-69EA78E462E8}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{0EA04667-E53B-4E81-8E7C-DE2CA114CBD6}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{3946A33D-BBC6-4792-A383-D855E0F76D91}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{265C2AF8-C94C-4AFF-B2B6-340D3982562C}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{0878F045-B52E-46B3-9724-D3AE69D50067}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{04F3168F-5AFC-4531-B3B4-16CA93720415}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{187A8428-BD94-470D-A178-A2347F940519}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{2865930B-4588-4FF3-8227-6D4F66C92C7A}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{2FE2EDC0-9E62-4F34-8A73-BC66DAE48EF3}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{3A3A8C24-8FF0-4140-9731-54D9483EA70B}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{3A906593-B4BD-48ED-84B0-3249BED65EF9}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{49B72A72-01F5-4AE8-BBD7-DAA67F1E303B}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{6AE3ACA6-1BE3-4443-98DD-EFFCFA793D35}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{9F89E240-06A6-4E1C-BA84-F267DE7DB391}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{79DDF2EF-D881-464B-B2AF-5AF8816A3964}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{813C8E86-4C90-4617-B59E-E130CC068140}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{89133BCE-57D0-4D2B-AFAF-A97B74AD704E}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{8F40CC34-FE77-4618-AA3D-BD2EFACAA8DC}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{9F89E240-06A6-4E1C-BA84-F267DE7DB391}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{B60A0E56-548D-40AE-9383-D752531F653F}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{B67B0756-2528-4996-B4BD-C993614CC0B6}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{BCC51EA9-6340-4EBE-8736-13A752ECB0BE}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{E9719D38-EC55-4C8B-9DF0-080ADE95A9FA}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{F4B3E25A-33B4-4647-9A78-B627DDE211A6}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{08101C3E-6C90-439E-9734-6E4DD1B53B69}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{0BACA3C1-F734-4A5F-970A-15DBF7D3C09C}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{09B90087-4FFA-4A44-BE69-DA117A710F07}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{0D4385DF-F78A-4264-A32C-7DD4A72DE539}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{1449F89C-AD28-427A-97FF-1D5BD812EA43}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{19A0B5C9-65FE-4D3B-8BDD-EFB7FE553C58}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{1C08D3D0-1E04-4DDE-AB0A-75355EA2585E}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{19C99256-D011-47E2-BC64-6322096E20A5}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{20F8B70D-9F16-4DCB-8788-90A0498E46B9}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{2871B7AF-2D4C-478F-BE89-881881C272AB}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{28FEDB90-53C7-4928-994A-CEE782606507}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{2B94CDFD-4A45-4B08-B105-54C709D07B28}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{3A350193-C7F7-4E10-B347-02FF4C3CC4E9}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{2C354A9B-A5DF-41A3-BF40-2D72FEAC14D3}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{4723879B-8F52-4BE7-9994-626AFA539366}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{2C797AA0-978C-4AC2-BBB4-F89D410B614E}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{7B6A3434-8625-4ABF-B79D-09D98C2498C4}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{54007809-0689-4A40-9D8F-94C79D87D931}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{8B6C0168-BAAC-4C7C-911E-0132590F5661}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{557C3787-D066-496E-8CAF-BA47DA7365C1}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{8EC33B7D-9953-4EDB-ACE2-D4C105968601}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{5C083B7E-A083-4B20-A7AD-7C8E29085494}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{A00E2305-7001-4200-BA00-5779F9A3E7D3}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{649D371E-D3E3-4FC0-AC82-E91F73D8E79E}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{B803D266-A08D-4A4C-9604-6D35689ABE09}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{655980F1-13D5-4DA2-9E80-AA56C36876CB}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{A917B2F3-A9BF-477C-A0E3-0382D0376159}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{6AF126A9-B07A-4DE4-883E-28D3ECCD75D8}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{B26B5883-F15F-4283-B3D5-A1728077DE47}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{6B436BDD-8B8B-4A1F-ADD5-E67B30C8F7DD}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{B803D266-A08D-4A4C-9604-6D35689ABE09}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{71BF80FD-7E91-4730-B6E8-8F3E81F5C38B}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{CB9385AB-8541-4B2F-A363-48F64C612993}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{81723C8C-918F-4456-B7E8-A68CF7A10C6D}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{D6A7D177-0B2F-4283-B2E8-B6310A45E606}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{82A10659-A1E5-4732-A839-C910D955C88B}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{D5D6E9B5-30D5-4457-AC8B-399205F50411}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{84844B27-0D53-4C71-AB24-0151B33AB02F}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{D6A7D177-0B2F-4283-B2E8-B6310A45E606}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{A8BCF2B9-ED19-4637-AC77-BF59F131FA1F}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{E0D6C30A-B9A3-4181-8099-3B0D5A2B98AF}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{A9A73A66-B0E0-4FFB-828F-3A55E1FA4271}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{B6049D5D-718F-44C0-B965-06840D27E206}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{F100A342-3AC5-47FF-B5B3-FCDB6FC9F016}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{B817D284-1B82-4793-B1F3-58A06DAB03A1}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{BC077DD0-42B5-451C-B78C-4AC97E4B116B}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{C123DBA0-52DF-4272-BBAA-BFD092D07C2E}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{CB9DD914-68B6-4710-A04E-4745470706CE}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{DE1E317F-716A-4784-BA90-FDA6D6A8FAD5}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{E36DCDBC-57AD-4A1C-B9C6-1161441B51CA}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{E51AC62C-E82E-4E60-97AB-C66C4969AF39}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{EF5750B1-0ABA-45C5-BF12-FB4D1D1150D2}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{F1D9585E-20A6-4689-84C7-C19FE21C9A71}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{F1E1A6B0-6CAC-471B-99C4-4DBADA883BE8}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{F8C9D1A9-B7B7-47CA-8B93-27C5B64D3A47}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\TypeLib\{F61D1CE1-5199-4B57-B59E-C6819EA92F3B}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\TypeLib\{31E956BF-8CA9-4D75-B534-7EBC79770002}]>>C:\psguardrem.reg
    echo [-HKEY_CLASSES_ROOT\TypeLib\{6E9E448E-B195-4627-953C-5377FA9BBA36}]>>C:\psguardrem.reg
    echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PSGuard spyware remover]>>C:\psguardrem.reg
    echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\P.S.Guard spyware remover]>>C:\psguardrem.reg

    swreg add HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.comdummy
    swreg add HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTDdummy
    swreg save HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTDdummy ShudderLTDdummy.hiv
    swreg save HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.comdummy PSGuard.comdummy.hiv
    swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTDdummy /f
    swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.comdummy /f
    swreg restore HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTD ShudderLTDdummy.hiv
    swreg restore HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com PSGuard.comdummy.hiv
    swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTD /f
    swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com /f

    regedit /s C:\psguardrem.reg

    del ShudderLTDdummy.hiv
    del PSGuard.comdummy.hiv

    del /q C:\psguardrem.reg
    del /q %systemdrive%\PSGuard.txt

    regedit.exe /e %systemdrive%\PSGuard.txt "HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com"

    IF EXIST %systemdrive%\PSGuard.txt echo PSGuard.com key was NOT successfully removed!>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    IF NOT EXIST %systemdrive%\PSGuard.txt echo PSGuard.com key was successfully removed! :)>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt

    del /q %systemdrive%\PSGuard.txt

    GOTO WinHchck

    :WinHchck
    cls
    @echo off
    echo.>>%systemdrive%\smitfiles.txt
    echo checking for WinHound.com key>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt

    cls
    @echo off
    if exist %systemdrive%\WinHound.txt del %systemdrive%\WinHound.txt

    regedit.exe /e %systemdrive%\WinHound.txt "HKEY_LOCAL_MACHINE\SOFTWARE\WinHound.com"

    IF EXIST %systemdrive%\WinHound.txt echo WinHound.com key present!>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    IF NOT EXIST %systemdrive%\WinHound.txt echo WinHound.com key not present!>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt

    IF EXIST %systemdrive%\WinHound.txt GOTO WinHfix
    IF NOT EXIST %systemdrive%\WinHound.txt GOTO smitrem

    :WinHfix
    cls
    @echo off
    echo.>>%systemdrive%\smitfiles.txt
    echo Running WinHound.com fix!>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    cls
    @echo off
    echo.>>%systemdrive%\smitfiles.txt
    echo.
    echo.
    echo SmitRem © add-on WinHound.com registry Fix
    echo.
    echo by Miekiemoes, Atribune and noahdfear
    echo.
    echo.
    echo.
    echo.
    pause

    swreg add HKEY_LOCAL_MACHINE\SOFTWARE\WinHound.comdummy
    swreg save HKEY_LOCAL_MACHINE\SOFTWARE\WinHound.comdummy WinHound.comdummy.hiv
    swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\WinHound.comdummy /f
    swreg restore HKEY_LOCAL_MACHINE\SOFTWARE\WinHound.com WinHound.comdummy.hiv
    swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\WinHound.com /f
    del WinHound.comdummy.hiv

    del /q %systemdrive%\WinHound.txt

    regedit.exe /e %systemdrive%\WinHound.txt "HKEY_LOCAL_MACHINE\SOFTWARE\WinHound.com"

    IF EXIST %systemdrive%\WinHound.txt echo WinHound.com key was NOT successfully removed!>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    IF NOT EXIST %systemdrive%\WinHound.txt echo WinHound.com key was successfully removed! :)>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt

    del /q %systemdrive%\WinHound.txt

    GOTO smitrem

    :smitrem
    @echo off
    echo.
    echo If SpyAxe is found and the uninstaller is present,
    echo.
    echo the SpyAxe uninstaller will start.
    echo.
    echo Allow it to continue. Close any browser window it may cause to open.
    echo.
    echo.
    pause

    IF EXIST spyaxe.txt del spyaxe.txt
    echo.>>spyaxe1.txt
    echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>spyaxe1.txt
    echo.>>spyaxe1.txt
    echo SpyAxeFix © by noahdfear>>spyaxe1.txt
    echo.>>spyaxe1.txt
    IF EXIST C:\progra~1\spyaxe echo spyaxe directory present>>spyaxe1.txt
    echo.>>spyaxe1.txt
    IF EXIST C:\progra~1\spyaxe\uninst.exe echo spyaxe uninstaller present>>spyaxe1.txt
    IF EXIST C:\progra~1\spyaxe\uninst.exe goto cspyaxe
    IF NOT EXIST C:\progra~1\spyaxe\uninst.exe goto sys
    :cspyaxe
    echo.>>spyaxe1.txt
    echo Starting spyaxe uninstaller>>spyaxe1.txt
    start C:\progra~1\spyaxe\uninst.exe
    goto remove
    :sys
    IF EXIST %systemdrive%\progra~1\spyaxe echo spyaxe directory present>>spyaxe1.txt
    echo.>>spyaxe1.txt
    IF EXIST %systemdrive%\progra~1\spyaxe\uninst.exe echo spyaxe uninstaller present>>spyaxe1.txt
    IF EXIST %systemdrive%\progra~1\spyaxe\uninst.exe goto sysspy
    IF NOT EXIST %systemdrive%\progra~1\spyaxe\uninst.exe echo spyaxe uninstaller NOT present>>spyaxe1.txt
    IF NOT EXIST %systemdrive%\progra~1\spyaxe\uninst.exe echo spyaxe uninstaller NOT present>>%systemdrive%\smitfiles.txt
    IF NOT EXIST %systemdrive%\progra~1\spyaxe\uninst.exe del spyaxe1.txt
    IF NOT EXIST %systemdrive%\progra~1\spyaxe\uninst.exe goto winhound
    :sysspy
    echo.>>spyaxe1.txt
    echo Starting spyaxe uninstaller>>spyaxe1.txt
    start %systemdrive%\progra~1\spyaxe\uninst.exe
    echo.>>spyaxe1.txt
    echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>spyaxe1.txt
    echo.>>spyaxe1.txt
    goto remove
    :remove
    cls
    @echo off
    echo REGEDIT4>>fix.reg
    echo.>>fix.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{E802FFFF-8E58-4d2c-A435-8BEEFB10AB77}]>>fix.reg
    echo.>>fix.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{A2D9D3F0-8C2A-2A1D-A376-1BECFB10AB72}]>>fix.reg
    echo.>>fix.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{A3D21DFF-2E58-4E2A-A435-8CEAF21F0B29}]>>fix.reg
    echo.>>fix.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{C1A8B6A1-2C81-1C3D-A3C6-A1CCDB10B47F}]>>fix.reg
    echo.>>fix.reg
    echo [-HKEY_CURRENT_USER\Software\Classes\CLSID\{E802FFFF-8E58-4d2c-A435-8BEEFB10AB77}]>>fix.reg
    echo.>>fix.reg
    echo [-HKEY_CURRENT_USER\Software\Classes\CLSID\{A2D9D3F0-8C2A-2A1D-A376-1BECFB10AB72}]>>fix.reg
    echo.>>fix.reg
    echo [-HKEY_CURRENT_USER\Software\Classes\CLSID\{A3D21DFF-2E58-4E2A-A435-8CEAF21F0B29}]>>fix.reg
    echo.>>fix.reg
    echo [-HKEY_CURRENT_USER\Software\Classes\CLSID\{C1A8B6A1-2C81-1C3D-A3C6-A1CCDB10B47F}]>>fix.reg
    echo.>>fix.reg
    echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]>>fix.reg
    echo "{E802FFFF-8E58-4d2c-A435-8BEEFB10AB77}"=->>fix.reg
    echo "{A2D9D3F0-8C2A-2A1D-A376-1BECFB10AB72}"=->>fix.reg
    echo "{A3D21DFF-2E58-4E2A-A435-8CEAF21F0B29}"=->>fix.reg
    echo "{C1A8B6A1-2C81-1C3D-A3C6-A1CCDB10B47F}"=->>fix.reg
    echo.>>fix.reg
    regedit /s fix.reg
    cls
    @echo off
    regedit /a ST.reg HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
    echo.>>spyaxe.txt
    type spyaxe1.txt >>spyaxe.txt
    echo.>>spyaxe.txt
    type ST.reg >>spyaxe.txt
    echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>spyaxe.txt
    echo.>>spyaxe.txt
    del /q spyaxe1.txt
    del /q ST.reg
    del /q fix.reg
    echo.>>%systemdrive%\smitfiles.txt
    type spyaxe.txt>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    del /q spyaxe.txt

    cls
    echo.
    echo.
    echo If the SpyAxe uninstaller has completed,
    echo.
    echo press any key to continue.
    echo.
    echo.
    pause

    GOTO winhound

    :winhound
    @echo off
    echo.
    echo If Winhound is found and the uninstaller is present,
    echo.
    echo the Winhound uninstaller will start.
    echo.
    echo Allow it to continue.
    echo.
    echo.
    pause

    IF EXIST winhound.txt del winhound.txt
    echo.>>winhound.txt
    echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>winhound.txt
    echo.>>winhound.txt
    echo WinhoundFix © by noahdfear>>winhound.txt
    echo.>>winhound.txt
    IF EXIST C:\progra~1\Winhound echo Winhound directory present>>winhound.txt
    echo.>>winhound.txt
    IF EXIST C:\progra~1\Winhound\Uninstall.exe echo Winhound uninstaller present>>winhound.txt
    IF EXIST C:\progra~1\Winhound\Uninstall.exe goto Winhck
    IF NOT EXIST C:\progra~1\Winhound\Uninstall.exe goto winh
    :Winhck
    echo.>>winhound.txt
    echo Starting Winhound uninstaller>>winhound.txt
    start C:\progra~1\Winhound\Uninstall.exe
    echo.>>winhound.txt
    echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>winhound.txt
    echo.>>winhound.txt
    goto removeh
    :winh
    IF EXIST %systemdrive%\progra~1\Winhound echo Winhound directory present>>winhound.txt
    echo.>>winhound.txt
    IF EXIST %systemdrive%\progra~1\Winhound\Uninstall.exe echo Winhound uninstaller present>>winhound.txt
    IF EXIST %systemdrive%\progra~1\Winhound\Uninstall.exe goto winhrem
    IF NOT EXIST %systemdrive%\progra~1\Winhound\Uninstall.exe echo Winhound uninstaller NOT present>>%systemdrive%\smitfiles.txt
    IF NOT EXIST %systemdrive%\progra~1\Winhound\Uninstall.exe echo Winhound uninstaller NOT present>>winhound.txt
    IF NOT EXIST %systemdrive%\progra~1\Winhound\Uninstall.exe del winhound.txt
    IF NOT EXIST %systemdrive%\progra~1\Winhound\Uninstall.exe goto smitrem1
    :winhrem
    echo.>>winhound.txt
    echo Starting Winhound uninstaller>>winhound.txt
    start %systemdrive%\progra~1\Winhound\Uninstall.exe
    echo.>>winhound.txt
    echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>winhound.txt
    echo.>>winhound.txt
    goto removeh
    :removeh
    cls
    echo.
    echo.
    echo If the Winhound uninstaller has completed,
    echo.
    echo press any key to continue.
    echo.
    echo.
    pause

    echo.>>winhound.txt
    echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>winhound.txt
    echo.>>winhound.txt
    echo.>>%systemdrive%\smitfiles.txt
    type winhound.txt>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    del /q winhound.txt

    goto smitrem1

    :smitrem1
    cls
    @echo off
    echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo Existing Pre-run Files>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo ~~~ Program Files ~~~>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\Archivos de programa\Winhound" echo Winhound>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\progra~1\Winhound" echo Winhound>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\Archivos de programa\spyaxe" echo SpyAxe>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\progra~1\spyaxe" echo SpyAxe>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\Archivos de programa\SpyTrooper" echo SpyTrooper>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\Archivos de programa\Security Toolbar" echo Security Toolbar>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\progra~1\SpyTrooper" echo SpyTrooper>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\progra~1\Security Toolbar" echo Security Toolbar>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\Archivos de programa\P.S.Guard" echo P.S.Guard>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\Archivos de programa\Security IGuard" echo Security IGuard>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\Archivos de programa\Virtual Maid" echo Virtual Maid>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\Archivos de programa\Search Maid" echo Search Maid>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\Archivos de programa\AntiVirusGold" echo AntiVirusGold>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\Archivos de programa\PSGuard" echo PSGuard>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\Archivos de programa\SpySheriff" echo SpySheriff>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\progra~1\P.S.Guard" echo P.S.Guard>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\progra~1\Security IGuard" echo Security IGuard>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\progra~1\Virtual Maid" echo Virtual Maid>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\progra~1\Search Maid" echo Search Maid>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\progra~1\AntiVirusGold" echo AntiVirusGold>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\progra~1\PSGuard" echo PSGuard>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\progra~1\SpySheriff" echo SpySheriff>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo ~~~ Shortcuts ~~~>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Desktop\WinHound spyware remover.lnk" echo WinHound spyware remover.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Bureaublad\WinHound spyware remover.lnk" echo WinHound spyware remover.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinHound spyware remover.lnk" echo quick launch WinHound spyware remover.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Start Menu\Programs\WinHound spyware remover" echo WinHound spyware remover folder>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Menu Start\Programs\WinHound spyware remover" echo WinHound spyware remover folder>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Desktop\Online Security Guide.url" echo Online Security Guide.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Start Menu\Online Security Guide.url" echo Online Security Guide.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Bureaublad\Online Security Guide.url" echo Online Security Guide.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Menu Start\Online Security Guide.url" echo Online Security Guide.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Desktop\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Desktop\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Start Menu\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Desktop\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Desktop\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Bureaublad\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Bureaublad\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Menu Start\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\SpyTrooper.lnk" echo SpyTrooper.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\SpyTrooper.lnk" echo SpyTrooper.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Menu Start\Programma's\SpyTrooper" echo SpyTrooper folder>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Start Menu\Programs\SpyTrooper" echo SpyTrooper folder>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Bureaublad\Security Troubleshooting.lnk" echo Security Troubleshooting.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Bureaublad\Online Security Center.lnk" echo Online Security Center.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Menu Start\Anti SPAM.url" echo Anti SPAM.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Menu Start\Online Casino.url" echo Online Casino.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Menu Start\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Menu Start\Computer Security.url" echo Computer Security.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Desktop\Security Troubleshooting.lnk" echo Security Troubleshooting.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Desktop\Online Security Center.lnk" echo Online Security Center.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Start Menu\Anti SPAM.url" echo Anti SPAM.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Start Menu\Online Casino.url" echo Online Casino.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Start Menu\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Start Menu\Computer Security.url" echo Computer Security.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Air Tickets.url" echo Air Tickets.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Big Tits.url" echo Big Tits.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Blackjack.url" echo Blackjack.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Britney Spears.url" echo Britney Spears.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Car Insurance.url" echo Car Insurance.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Cheap Cigarettes.url" echo Cheap Cigarettes.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Credit Card.url" echo Credit Card.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Cruises.url" echo Cruises.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Currency Trading.url" echo Currency Trading.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Lesbian Sex.url" echo Lesbian Sex.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\MP3.url" echo MP3.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Online Betting.url" echo Online Betting.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Online Gambling.url" echo Online Gambling.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Oral Sex.url" echo Oral Sex.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Party Poker.url" echo Party Poker.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Pharmacy.url" echo Pharmacy.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Phentermine.url" echo Phentermine.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Pornstars.url" echo job Pornstars.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Remove Spyware.url" echo Remove Spyware.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\viagra.url" echo viagra.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Air Tickets.url" echo Air Tickets.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Big Tits.url" echo Big Tits.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Blackjack.url" echo Blackjack.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Britney Spears.url" echo Britney Spears.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Car Insurance.url" echo Car Insurance.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Cheap Cigarettes.url" echo Cheap Cigarettes.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Credit Card.url" echo Credit Card.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Cruises.url" echo Cruises.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Currency Trading.url" echo Currency Trading.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Lesbian Sex.url" echo Lesbian Sex.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\MP3.url" echo MP3.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Online Betting.url" echo Online Betting.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Online Gambling.url" echo Online Gambling.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Oral Sex.url" echo Oral Sex.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Party Poker.url" echo Party Poker.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Pharmacy.url" echo Pharmacy.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Phentermine.url" echo Phentermine.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Pornstars.url" echo job Pornstars.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Remove Spyware.url" echo Remove Spyware.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\viagra.url" echo viagra.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Start Menu\Programs\PSGuard spyware remover" echo PSGuard spyware remover>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Menu Start\Programma's\PSGuard spyware remover" echo PSGuard spyware remover>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Bureaublad\AntivirusGold.lnk" echo AntivirusGold.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\AntivirusGold.lnk" echo AntivirusGold.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Bureaublad\PSGuard spyware remover.lnk" echo PSGuard spyware remover.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Desktop\PSGuard spyware remover.lnk" echo PSGuard spyware remover.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Bureaublad\Spyware Removal.url" echo Spyware Removal.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Bureaublad\Online Dating.url" echo Online Dating.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Bureaublad\Online Pharmacy.url" echo Online Pharmacy.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Desktop\Spyware Removal.url" echo Spyware Removal.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Desktop\Online Dating.url" echo Online Dating.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Desktop\Online Pharmacy.url" echo Online Pharmacy.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSGuard spyware remover.lnk" echo quick launch PSGuard spyware remover.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSGuard.lnk" echo quick launch PSGuard.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Menu Start\Programma's\SpySheriff" echo SpySheriff>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Bureaublad\SpySheriff.lnk" echo SpySheriff.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Bureaublad\PSGuard.lnk" echo PSGuard.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Application Data\PSGuard.com" echo PSGuard.com>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Start Menu\Programs\SpySheriff" echo SpySheriff>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Application Data\Install.dat" echo Install.dat>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\SpySheriff.lnk" echo SpySheriff.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Desktop\PSGuard.lnk" echo PSGuard.lnk>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo ~~~ Favorites ~~~>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Take It Here - Daily Updated Porn Links.url" echo Take It Here - Daily Updated Porn Links.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Take It Here - Daily Updated Porn Links.url" echo Take It Here - Daily Updated Porn Links.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Favori~1\Free XXX Sites List.url" echo Free XXX Sites List.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Favori~1\Antivirus Test Online.url" echo Antivirus Test Online.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Favori~1\Cheap Viagra.url" echo Cheap Viagra.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Favori~1\Buy Viagra Online.url" echo Buy Viagra Online.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Favori~1\Need Money.url" echo Need Money.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\adult" echo adult>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\cars" echo cars>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\sexual life" echo sexual life>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\shopping" echo shopping>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\anti spam.url" echo anti spam.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\job search.url" echo job search.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\poker.url" echo poker.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\spyware removal.url" echo spyware removal.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Online Gambling.url" echo Online Gambling.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\online dating.url" echo online dating.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Black Jack Online.url" echo Black Jack Online.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Online Pharmacy\Adipex.url" echo Online Pharmacy\Adipex.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Black Jack Online.url" echo Black Jack Online.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Home Loan.url" echo Home Loan.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Network Security.url" echo Network Security.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Online Dating.url" echo Online Dating.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Adipex.url" echo Adipex.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Alprazolam.url" echo Alprazolam.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Carisoprodol.url" echo Carisoprodol.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Diazepam.url" echo Diazepam.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Hydrocodone.url" echo Hydrocodone.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Lortab.url" echo Lortab.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Online Pharmacy.url" echo Online Pharmacy.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Prozac.url" echo Prozac.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Valium.url" echo Valium.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Vicodin.url" echo Vicodin.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Xanax.url" echo Xanax.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Remove Spyware.url" echo Remove Spyware.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Spam Filters.url" echo Spam Filters.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Take It Here - Free * TGP.url" echo Take It Here - Free * TGP.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Web Detective.url" echo Web Detective.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Online Gambling" echo Online Gambling folder>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Online Pharmacy" echo Online Pharmacy folder>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo ~~~ system32 folder ~~~>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\wbeconm.dll" echo wbeconm.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\_plastilin_" echo _plastilin_>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\atmtd.dll" echo atmtd.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\atmtd.dll._" echo atmtd.dll._>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Defpia32.dll" echo Defpia32.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\fhpd.dll" echo fhpd.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Kdfdlh32.dll" echo Kdfdlh32.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\klja.dll" echo klja.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\ll.exe" echo ll.exe>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Mhpcja32.dll" echo Mhpcja32.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Nbfgemln.exe" echo Nbfgemln.exe>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\ongi.dll" echo ongi.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\perflibs__" echo perflibs__>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\svcp.csv" echo svcp.csv>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\sywsvcs.exe" echo sywsvcs.exe>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\windesktop.dll" echo windesktop.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\windesktop.exe" echo windesktop.exe>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\wins32.dll" echo wins32.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\winselect.exe" echo winselect.exe>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\winsub.xml" echo winsub.xml>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\zlbw.dll" echo zlbw.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\ioctrl.dll" echo ioctrl.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\svchosts.dll" echo svchosts.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\ff.tmp" echo ff.tmp>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\oleext32.dll" echo oleext32.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\1024" echo 1024 dir>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\svchop.exe" echo svchop.exe>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\shdochop.dll" echo shdochop.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\zlbw.dll" echo zlbw.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\msvol.tlb" echo msvol.tlb>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemroot%\system32\ld****.tmp" echo ld****.tmp>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\mssearchnet.exe" echo mssearchnet.exe>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\ncompat.tlb" echo ncompat.tlb>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\nvctrl.exe" echo nvctrl.exe>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\mscornet.exe" echo mscornet.exe>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\gunist.exe" echo gunist.exe>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\param32.dll" echo param32.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\pop_up.dll" echo pop_up.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\searchdll.dll" echo searchdll.dll>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\thn.dll echo thn.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemroot%\system32\__delete_on_reboot__intel32.exe" echo __delete_on_reboot__intel32.exe>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemroot%\system32\__delete_on_reboot__OLEADM.dll" echo __delete_on_reboot__OLEADM.dll>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\intell32.exe echo intell32.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\oleext.dll echo oleext.dll>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\wppp.html echo wppp.html>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\svcnt.exe echo svcnt.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\oleadm.dll echo oleadm.dll>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\intel32.exe echo intel32.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\hhk.dll.tcf echo hhk.dll.tcf>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\perfcii.ini echo perfcii.ini>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\oleadm32.dll echo oleadm32.dll>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\wp.bmp echo wp.bmp>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\hookdump.exe echo hookdump.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\winnook.exe echo winnook.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\wldr.dll echo wldr.dll>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\helper.exe echo helper.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\intmonp.exe echo intmonp.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\msmsgs.exe echo msmsgs.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\ole32vbs.exe echo ole32vbs.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\msole32.exe echo msole32.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\hp***.tmp echo hp***.tmp>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\shnlog.exe echo shnlog.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\intmon.exe echo intmon.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\hhk.dll echo hhk.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemroot%\system32\__delete_on_reboot__intmon.exe" echo __delete_on_reboot__intmon.exe>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemroot%\system32\Log Files" echo Log Files>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\logfiles echo logfiles>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo ~~~ Icons in System32 ~~~>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\ts.ico" echo ts.ico>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\ot.ico" echo ot.ico>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\ptainfo1.ico" echo ptainfo1>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\ptainfo2.ico" echo ptainfo2>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Air Tickets.ico" echo Air Tickets>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Big Tits.ico" echo Big Tits>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Blackjack.ico" echo Blackjack>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Britney Spears.ico" echo Britney Spears>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Car Insurance.ico" echo Car Insurance>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Cheap Cigarettes.ico" echo Cheap Cigarettes>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Credit Card.ico" echo Credit Card>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Cruises.ico" echo Cruises>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Currency Trading.ico" echo Currency Trading>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Lesbian Sex.ico" echo Lesbian Sex>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\MP3.ico" echo MP3>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Online Betting.ico" echo Online Betting>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Online Gambling.ico" echo Online Gambling>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Oral Sex.ico" echo Oral Sex>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Party Poker.ico" echo Party Poker>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Pharmacy.ico" echo Pharmacy>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Phentermine.ico" echo Phentermine>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Pornstars.ico" echo Pornstars>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Remove Spyware.ico" echo Remove Spyware>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\viagra.ico" echo viagra>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo ~~~ Windows directory ~~~>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\RGF2ZQ echo RGF2ZQ folder>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\warnhp.html echo warnhp.html>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemroot%\Application Data\Shudder Global Limited" echo Application Data\Shudder Global Limited>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\wp.bmp echo wp.bmp>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\uninstIU.exe echo uninstIU.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\zloader3.exe echo zloader3.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\desktop.html echo desktop.html>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\screen.html echo screen.html>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\sites.ini echo sites.ini>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\popuper.exe echo popuper.exe>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo ~~~ Drive root ~~~>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    IF EXIST %systemdrive%\bsw.exe echo bsw.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemdrive%\wp.exe echo wp.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemdrive%\wp.bmp echo wp.bmp>>%systemdrive%\smitfiles.txt
    IF EXIST %systemdrive%\bsw.bmp echo bsw.bmp>>%systemdrive%\smitfiles.txt
    IF EXIST %systemdrive%\winstall.exe echo winstall.exe>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo ~~~ Miscellaneous Files/folders ~~~>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\application data\shudder global limited" echo shudder global limited>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt

    cls
    @echo off
    if exist %systemdrive%\replace.cmd del replace.cmd
    copy replace.cmd %systemdrive%\replace.cmd

    cls
    @echo off
    if exist %systemdrive%\delfiles.cmd del delfiles.cmd
    copy delfiles.cmd %systemdrive%\delfiles.cmd

    cls
    @echo off
    echo.>>%systemdrive%\smitfiles.txt
    process -k explorer.exe>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo Starting registry repairs>>%systemdrive%\smitfiles.txt

    cls
    @echo off
    echo REGEDIT4>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{e0103cd4-d1ce-411a-b75b-4fec072867f4}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e0103cd4-d1ce-411a-b75b-4fec072867f4}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e0103cd4-d1ce-411a-b75b-4fec072867f4}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]>>C:\smitfrau.reg
    echo "{A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F}"=->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CURRENT_USER\Software\Classes\CLSID\{A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CMDSERVICE]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MCHINJDRV]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdService]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mchInjDrv]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MCHINJDRV]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mchInjDrv]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]>>C:\smitfrau.reg
    echo "windesktop" =->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]>>C:\smitfrau.reg
    echo "windesktop" =->>C:\smitfrau.reg
    echo "WinHound" =->>C:\smitfrau.reg
    echo "sp" =->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchAssistant Uninstall]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinHound spyware remover]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_LOCAL_MACHINE\SOFTWARE\Policies]>>C:\smitfrau.reg
    echo "{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}" =->>C:\smitfrau.reg
    echo "{645FF040-5081-101B-9F08-00AA002F954E}" =->>C:\smitfrau.reg
    echo "{6BF52A52-394A-11D3-B153-00C04F79FAA6}" =->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced]>>C:\smitfrau.reg
    echo "SeparateProcess" =dword:00000000>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3E01D51F-E9BD-4902-A0DE-2F4AA5A03092}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\New Windows]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DownloadManager]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\text/html]>>C:\smitfrau.reg
    echo "{348722EC-7332-496E-B944-FF60A9456D46}" =->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\text/plain]>>C:\smitfrau.reg
    echo "{348722EC-7332-496E-B944-FF60A9456D46}" =->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]>>C:\smitfrau.reg
    echo "NoActiveDesktopChanges"=dword:00000000>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{736B5468-BDAD-41BE-92D0-22AE2DDF7BCB}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{1ca480cd-c0e5-4548-874e-b85b17905b3a}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1ca480cd-c0e5-4548-874e-b85b17905b3a}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1ca480cd-c0e5-4548-874e-b85b17905b3a}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objecta\{724510c3-f3c8-4fb7-879a-d99f29008a2f}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{724510C3-F3C8-4FB7-879A-D99F29008A2F}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]>>C:\smitfrau.reg
    echo "SpyAxe"=->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{724510c3-f3c8-4fb7-879a-d99f29008a2f}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{724510c3-f3c8-4fb7-879a-d99f29008a2f}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]>>C:\smitfrau.reg
    echo "Display Inline Images"=->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{736B5468-BDAD-41BE-92D0-22AE2DDF7BCB}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{736B5468-BDAD-41BE-92D0-22AE2DDF7BCB}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]>>C:\smitfrau.reg
    echo "{736B5468-BDAD-41BE-92D0-22AE2DDF7BCB}"=->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{3e9b951e-6f72-431b-82cf-4a9fbf2f53bc}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3e9b951e-6f72-431b-82cf-4a9fbf2f53bc}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7288c0bd-7f2f-4229-a0c4-3c90a6e2a881}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7caf96a2-c556-460a-988e-76fc7895d284}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\clsid\{e9ccf15d-4c68-4b5a-9e9a-8e12e4bd39bd}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{736B5468-BDAD-41BE-92D0-22AE2DDF7BCB}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\clsid\{057e242f-2947-4e0a-8e61-a11345d97ea6}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CURRENT_USER\Software\SNO2]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CURRENT_USER\Software\SpyTrooper]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e9ccf15d-4c68-4b5a-9e9a-8e12e4bd39bd}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]>>C:\smitfrau.reg
    echo "{736b5468-bdad-41be-92d0-22ae2ddf7bcb}"=->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpyTrooper]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]>>C:\smitfrau.reg
    echo "FH"=->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]>>C:\smitfrau.reg
    echo "SpyTrooper"=->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\uuid]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Classes\HP]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Classes\HP.1]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{15DC7116-E58E-4395-A45A-A1C99B17C030}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{17E02586-A91D-4A9D-A74E-187B05DFFE6F}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{1BD98DFD-2DA9-4C54-85D7-BE03A0F9C487}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{1C94EA51-3800-4F08-B5DC-A5B67823FFEA}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{20D1AF34-6E19-42D8-AF9F-BDFBE45C2454}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{21E132C9-1F98-4151-BDAD-7D9B49C60A8E}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{23F7AD29-F51A-4BA1-BE70-143B1CB25BD1}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{2C59D5EC-6B91-4896-BD6F-5F121D87A7F8}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{2F34E0E0-F0BB-477F-AFB8-509262FA0AD1}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{35ED274E-3F42-4A78-BBDC-3B7D73E85578}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{3D74D140-F780-4AE3-8D6D-F8DC39107213}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{49443D6E-CE4E-47A9-8DEB-F5774CE14984}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{52034AD2-914C-4634-B375-9299631E5525}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{7702C521-76AE-42C0-A181-3B5A96C2EEF7}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{7ADDA344-1D36-4446-9F4B-B2351FB19EFD}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{7D98221E-AF8F-4D29-8BB1-1DFABC288173}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{9746B450-6064-4EC8-9480-72A289AA2237}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{C5A40FCE-0A0F-40CA-985E-661C28B5B431}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{C7F22879-7151-4C71-8C50-9557AFDA66C6}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{CA5E7959-60B5-47B7-80AC-1606309733F3}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{CEABF027-6CDC-4D47-ADF6-AC5D065826A6}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{E0AA0493-C410-4CBD-B1DB-1723374FA8E0}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{E5D78BD8-3874-4AA0-9D45-CFB79382C484}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\NVideoCodek.Chl]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{77B2F8DE-CB3F-4B6B-839B-807DD1ADBA1C}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{081669BA-EFC4-48C2-A8F4-874052D02553}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{145E6FB1-1256-44ED-A336-8BBA43373BE6}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{1D27320E-2DA2-41E2-A103-B5FD9D6A798B}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B599C57E-113A-4488-A5E9-BC552C4F1152}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{D56A1203-1452-EBA1-7294-EE3377770000}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{C7EDAB2E-D7F9-11D8-BA48-C79B0C409D70}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Classes\Interface\{C7EDAB2E-D7F9-11D8-BA48-C79B0C409D70}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Classes\Typelib\{C7EDAB2E-D7F9-11D8-BA48-C79B0C409D70}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Classes\Serch_hook.transURL]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Classes\Serch_hook.transURL.1]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database\Distribution Units\{11120607-1001-1111-1000-110199901123}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\{081669BA-EFC4-48C2-A8F4-874052D02553}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Internet Connection Update and HomeP KB234087]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\{081669BA-EFC4-48C2-A8F4-874052D02553}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{081669BA-EFC4-48C2-A8F4-874052D02553}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]>>C:\smitfrau.reg
    echo "{D56A1203-1452-EBA1-7294-EE3377770000}"=->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]>>C:\smitfrau.reg
    echo "{C7EDAB2E-D7F9-11D8-BA48-C79B0C409D70}"=->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\{E7C9AF76-A50A-423A-A5CA-88DB1A24CEAE}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PSGUARD SPYWARE REMOVER]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]>>C:\smitfrau.reg
    echo "P.S.Guard"=->>C:\smitfrau.reg
    echo "Fast Start"=->>C:\smitfrau.reg
    echo "AntivirusGold"=->>C:\smitfrau.reg
    echo "PSGuard spyware remover"=->>C:\smitfrau.reg
    echo "intell32.exe"=->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Update]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager]>>C:\smitfrau.reg
    echo "AllowProtectedRenames"="0">>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SOFTWARE\AdwareDelete]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Desktop]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]>>C:\smitfrau.reg
    echo "SNInstall"=->>C:\smitfrau.reg
    echo "Windows installer"=->>C:\smitfrau.reg
    echo "SpySheriff"=->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]>>C:\smitfrau.reg
    echo "ForceActiveDesktopOn"=->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]>>C:\smitfrau.reg
    echo "Wallpaper"=->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]>>C:\smitfrau.reg
    echo "DisableTaskMgr"=dword:00000000>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\LocalUser\Software\Microsoft\Windows\CurrentVersion\Policies\System]>>C:\smitfrau.reg
    echo "DisableTaskMgr"=dword:00000000>>C:\smitfrau.reg
    echo "**del.DisableTaskMgr"=" ">>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]>>C:\smitfrau.reg
    echo "DisableTaskMgr"=dword:00000000>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]>>C:\smitfrau.reg
    echo "DisableCAD"=dword:00000000>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{357A87ED-3E5D-437d-B334-DEB7EB4982A3}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]>>C:\smitfrau.reg
    echo "WindowsFZ"=->>C:\smitfrau.reg
    echo "PSGuard"=->>C:\smitfrau.reg
    echo "intel32.exe"=->>C:\smitfrau.reg
    echo "RegSvr32"=->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]>>C:\smitfrau.reg
    echo "Intel system tool"=->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SOFTWARE\AntivirusGold]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]>>C:\smitfrau.reg
    echo "Use Search Asst"=->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]>>C:\smitfrau.reg
    echo "NoDispAppearancePage"=->>C:\smitfrau.reg
    echo "Wallpaper"=->>C:\smitfrau.reg
    echo "WallpaperStyle"=->>C:\smitfrau.reg
    echo "NoDispBackgroundPage"=->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]>>C:\smitfrau.reg
    echo "NoActiveDesktopChanges"=->>C:\smitfrau.reg
    echo "NoActiveDesktop"=->>C:\smitfrau.reg
    echo "NoSaveSettings"=->>C:\smitfrau.reg
    echo "ClassicShell"=->>C:\smitfrau.reg
    echo "NoThemesTab"=->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]>>C:\smitfrau.reg
    echo "wininet.dll"=->>C:\smitfrau.reg
    echo "kernel32.dll"=->>C:\smitfrau.reg
    echo "nvctrl.exe"=->>C:\smitfrau.reg
    echo "notepad.exe"=->>C:\smitfrau.reg
    echo "notepad2.exe"=->>C:\smitfrau.reg
    echo "winlogon.exe"=->>C:\smitfrau.reg
    echo "paint.exe"=->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_CURRENT_USER\Control Panel\Desktop]>>C:\smitfrau.reg
    echo "Wallpaper"=->>C:\smitfrau.reg
    echo "WallpaperStyle"=->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_CURRENT_USER\Control Panel\Colors]>>C:\smitfrau.reg
    echo "Background"="0 78 152">>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop]>>C:\smitfrau.reg
    echo "NoChangingWallPaper"=->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{893fad3a-931e-4e53-b515-b1426d63799b}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3bf1f86f-b1a8-489b-8d8b-43781d51411f}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]>>C:\smitfrau.reg
    echo "SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm">>C:\smitfrau.reg
    echo "CustomizeSearch"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm">>C:\smitfrau.reg
    echo "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch">>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]>>C:\smitfrau.reg
    echo "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch">>C:\smitfrau.reg
    echo "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch">>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main]>>C:\smitfrau.reg
    echo "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch">>C:\smitfrau.reg
    echo "Search Bar"="Search Bar"="http://search.msn.com/intl/searchpane/en-au/prov2.htm">>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\main]>>C:\smitfrau.reg
    echo "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch">>C:\smitfrau.reg
    echo "Search Bar"="http://search.msn.com/spbasic.htm">>C:\smitfrau.reg
    echo "Use Custom Search URL"=dword:00000000>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]>>C:\smitfrau.reg
    echo ""="http://home.microsoft.com/access/autosearch.asp?p=%s">>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\VMHomepage]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\CLSID\VMHomepage.1]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\Interface\{1E1B2878-88FF-11D2-8D96-D7ACAC95951F}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\TypeLib\{1E1B286C-88FF-11D2-8D96-D7ACAC95951F}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\VMHomepage]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_CLASSES_ROOT\VMHomepage.1]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objecta]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\HTTP\Parameters\S]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\HTTP\Parameters\S]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\r]>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]>>C:\smitfrau.reg
    echo "NoActiveDesktopChanges"=hex:00000000>>C:\smitfrau.reg
    echo "NoActiveDesktop"=dword:00000000>>C:\smitfrau.reg
    echo "NoSaveSettings"=dword:00000000>>C:\smitfrau.reg
    echo "ClassicShell"=dword:00000000>>C:\smitfrau.reg
    echo "NoThemesTab"=dword:00000000>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]>>C:\smitfrau.reg
    echo "NoDispAppearancePage"=dword:00000000>>C:\smitfrau.reg
    echo "NoColorChoice"=dword:00000000>>C:\smitfrau.reg
    echo "NoSizeChoice"=dword:00000000>>C:\smitfrau.reg
    echo "NoDispBackgroundPage"=dword:00000000>>C:\smitfrau.reg
    echo "NoDispScrSavPage"=dword:00000000>>C:\smitfrau.reg
    echo "NoDispCPL"=dword:00000000>>C:\smitfrau.reg
    echo "NoVisualStyleChoice"=dword:00000000>>C:\smitfrau.reg
    echo "NoDispSettingsPage"=dword:00000000>>C:\smitfrau.reg
    echo "NoDispScrSavPage"=dword:00000000>>C:\smitfrau.reg
    echo "NoVisualStyleChoice"=dword:00000000>>C:\smitfrau.reg
    echo "NoSizeChoice"=dword:00000000>>C:\smitfrau.reg
    echo "SetVisualStyle"=->>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop]>>C:\smitfrau.reg
    echo "NoChangingWallPaper"=dword:00000000>>C:\smitfrau.reg
    echo "NoAddingComponents"=dword:00000000>>C:\smitfrau.reg
    echo "NoComponents"=dword:00000000>>C:\smitfrau.reg
    echo "NoDeletingComponents"=dword:00000000>>C:\smitfrau.reg
    echo "NoEditingComponents"=dword:00000000>>C:\smitfrau.reg
    echo "NoCloseDragDropBands"=dword:00000000>>C:\smitfrau.reg
    echo "NoMovingBands"=dword:00000000>>C:\smitfrau.reg
    echo "NoHTMLWallPaper"=dword:00000000>>C:\smitfrau.reg
    echo.>>C:\smitfrau.reg
    echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ThemeManager]>>C:\smitfrau.reg
    echo "ThemeActive"="1"
    echo "DllName"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\>>C:\smitfrau.reg
    echo 74,00,25,00,5c,00,72,00,65,00,73,00,6f,00,75,00,72,00,63,00,65,00,73,00,5c,\>>C:\smitfrau.reg
    echo 00,54,00,68,00,65,00,6d,00,65,00,73,00,5c,00,6c,00,75,00,6e,00,61,00,5c,00,\>>C:\smitfrau.reg
    echo 6c,00,75,00,6e,00,61,00,2e,00,6d,00,73,00,73,00,74,00,79,00,6c,00,65,00,73,\>>C:\smitfrau.reg
    echo 00,00,00>>C:\smitfrau.reg

    cls
    @echo off
    regedit.exe /s C:\smitfrau.reg

    echo.>>%systemdrive%\smitfiles.txt
    echo Deleting files>>%systemdrive%\smitfiles.txt

    cls
    @echo off

    attrib -h -r -s "%AllUsersProfile%\Desktop\WinHound spyware remover.lnk"
    attrib -h -r -s "%AllUsersProfile%\Bureaublad\WinHound spyware remover.lnk"
    attrib -h -r -s "%AllUsersProfile%\Start Menu\WinHound spyware remover\*.*"
    attrib -h -r -s "%AllUsersProfile%\Menu Start\WinHound spyware remover\*.*"

    del /q "%AllUsersProfile%\Desktop\WinHound spyware remover.lnk"
    del /q "%AllUsersProfile%\Bureaublad\WinHound spyware remover.lnk"
    del /q "%AllUsersProfile%\Start Menu\WinHound spyware remover\*.*"
    del /q "%AllUsersProfile%\Menu Start\WinHound spyware remover\*.*"
    rmdir /q /s "%AllUsersProfile%\Start Menu\Programs\WinHound spyware remover"
    rmdir /q /s "%AllUsersProfile%\Menu Start\Programs\WinHound spyware remover"

    attrib -h -r -s "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinHound spyware remover.lnk"
    del /q "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinHound spyware remover.lnk"

    attrib -r -h "%systemdrive%\Archivos de programa\Winhound\Trash\*.*"
    del /q "%systemdrive%\Archivos de programa\Winhound\Trash\*.*"
    rmdir "%systemdrive%\Archivos de programa\Winhound\Trash"
    attrib -r -h %systemdrive%\progra~1\Winhound\Trash\*.*
    del /q %systemdrive%\progra~1\Winhound\Trash\*.*
    rmdir %systemdrive%\progra~1\Winhound\Trash\
    attrib -r -h "%systemdrive%\Archivos de programa\Winhound\*.*"
    del /q "%systemdrive%\Archivos de programa\Winhound\*.*"
    rmdir "%systemdrive%\Archivos de programa\Winhound"
    attrib -r -h %systemdrive%\progra~1\Winhound\*.*
    del /q %systemdrive%\progra~1\Winhound\*.*
    rmdir %systemdrive%\progra~1\Winhound

    attrib -h -r -s "%AllUsersProfile%\Desktop\WinHound spyware remover.lnk"
    attrib -h -r -s "%AllUsersProfile%\Bureaublad\WinHound spyware remover.lnk"
    attrib -h -r -s "%AllUsersProfile%\Start Menu\WinHound spyware remover\*.*"
    attrib -h -r -s "%AllUsersProfile%\Menu Start\WinHound spyware remover\*.*"

    del /q "%AllUsersProfile%\Desktop\WinHound spyware remover.lnk"
    del /q "%AllUsersProfile%\Bureaublad\WinHound spyware remover.lnk"
    del /q "%AllUsersProfile%\Start Menu\WinHound spyware remover\*.*"
    del /q "%AllUsersProfile%\Menu Start\WinHound spyware remover\*.*"
    rmdir /q /s "%AllUsersProfile%\Start Menu\Programs\WinHound spyware remover"
    rmdir /q /s "%AllUsersProfile%\Menu Start\Programs\WinHound spyware remover"

    attrib -h -r -s "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinHound spyware remover.lnk"
    del /q "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinHound spyware remover.lnk"

    attrib -h -r -s "%AllUsersProfile%\Desktop\Online Security Center.url"
    attrib -h -r -s "%AllUsersProfile%\Start Menu\Security Troubleshooting.url"
    attrib -h -r -s "%AllUsersProfile%\Bureaublad\Online Security Center.url"
    attrib -h -r -s "%AllUsersProfile%\Menu Start\Security Troubleshooting.url"

    del /q "%AllUsersProfile%\Desktop\Online Security Center.url"
    del /q "%AllUsersProfile%\Start Menu\Security Troubleshooting.url"
    del /q "%AllUsersProfile%\Bureaublad\Online Security Center.url"
    del /q "%AllUsersProfile%\Menu Start\Security Troubleshooting.url"

    attrib -h -r -s "%AllUsersProfile%\Desktop\Security Troubleshooting.url"
    attrib -h -r -s "%AllUsersProfile%\Desktop\Online Security Center.url"
    attrib -h -r -s "%AllUsersProfile%\Start Menu\Security Troubleshooting.url"
    attrib -h -r -s "%userprofile%\Desktop\Security Troubleshooting.url"
    attrib -h -r -s "%userprofile%\Desktop\Online Security Center.url"
    attrib -h -r -s "%userprofile%\Favori~1\Take It Here - Daily Updated Porn Links.url"

    del /q "%AllUsersProfile%\Desktop\Security Troubleshooting.url"
    del /q "%AllUsersProfile%\Desktop\Online Security Center.url"
    del /q "%AllUsersProfile%\Start Menu\Security Troubleshooting.url"
    del /q "%userprofile%\Desktop\Security Troubleshooting.url"
    del /q "%userprofile%\Desktop\Online Security Center.url"
    del /q "%userprofile%\Favori~1\Take It Here - Daily Updated Porn Links.url"

    attrib -h -r -s "%AllUsersProfile%\Bureaublad\Security Troubleshooting.url"
    attrib -h -r -s "%AllUsersProfile%\Bureaublad\Online Security Center.url"
    attrib -h -r -s "%AllUsersProfile%\Menu Start\Security Troubleshooting.url"
    attrib -h -r -s "%userprofile%\Bureaublad\Security Troubleshooting.url"
    attrib -h -r -s "%userprofile%\Bureaublad\Online Security Center.url"
    attrib -h -r -s "%userprofile%\Favori~1\Take It Here - Daily Updated Porn Links.url"

    del /q "%AllUsersProfile%\Bureaublad\Security Troubleshooting.url"
    del /q "%AllUsersProfile%\Bureaublad\Online Security Center.url"
    del /q "%AllUsersProfile%\Menu Start\Security Troubleshooting.url"
    del /q "%userprofile%\Bureaublad\Security Troubleshooting.url"
    del /q "%userprofile%\Bureaublad\Online Security Center.url"
    del /q "%userprofile%\Favori~1\Take It Here - Daily Updated Porn Links.url"

    attrib -r -h "%systemdrive%\Archivos de programa\spyaxe\*.*"
    del /q "%systemdrive%\Archivos de programa\spyaxe\*.*"
    rmdir "%systemdrive%\Archivos de programa\spyaxe"

    attrib -r -h %systemdrive%\progra~1\spyaxe\*.*
    del /q %systemdrive%\progra~1\spyaxe\*.*
    rmdir %systemdrive%\progra~1\spyaxe

    attrib -h -r -s "%systemdrive%\Archivos de programa\SpyTrooper\*.*"
    del /q "%systemdrive%\Archivos de programa\SpyTrooper\*.*"
    rmdir /q /s "%systemdrive%\Archivos de programa\SpyTrooper"
    attrib -h -r -s "%systemdrive%\Archivos de programa\Security Toolbar\*.*"
    del /q "%systemdrive%\Archivos de programa\Security Toolbar\*.*"
    rmdir /q /s "%systemdrive%\Archivos de programa\Security Toolbar"
    attrib -h -r -s "%systemdrive%\progra~1\SpyTrooper\*.*"
    del /q "%systemdrive%\progra~1\SpyTrooper\*.*"
    rmdir /q /s "%systemdrive%\progra~1\SpyTrooper"
    attrib -h -r -s "%systemdrive%\progra~1\Security Toolbar\*.*"
    del /q "%systemdrive%\progra~1\Security Toolbar\*.*"
    rmdir /q /s "%systemdrive%\progra~1\Security Toolbar"

    attrib -r -h -s "%userprofile%\Bureaublad\SpyTrooper.lnk"
    attrib -r -h -s "%UserProfile%\Desktop\SpyTrooper.lnk"
    del /q "%userprofile%\Bureaublad\SpyTrooper.lnk"
    del /q "%UserProfile%\Desktop\SpyTrooper.lnk"
    attrib -h -r -s "%userprofile%\Menu Start\Programma's\SpyTrooper\*.*"
    del /q "%userprofile%\Menu Start\Programma's\SpyTrooper\*.*"
    rmdir /q /s "%userprofile%\Menu Start\Programma's\SpyTrooper"
    attrib -h -r -s "%userprofile%\Start Menu\Programs\SpyTrooper\*.*"
    del /q "%userprofile%\Start Menu\Programs\SpyTrooper\*.*"
    rmdir /q /s "%userprofile%\Start Menu\Programs\SpyTrooper"

    attrib -r -h -s "%UserProfile%\Favori~1\Free XXX Sites List.url"
    del /q "%userprofile%\Favori~1\Free XXX Sites List.url"
    attrib -r -h -s "%UserProfile%\Favori~1\Antivirus Test Online.url"
    del /q "%UserProfile%\Favori~1\Antivirus Test Online.url"

    attrib -h -r -s "%AllUsersProfile%\Favori~1\Cheap Viagra.url"
    attrib -h -r -s "%AllUsersProfile%\Favori~1\Buy Viagra Online.url"
    attrib -h -r -s "%AllUsersProfile%\Start Menu\Anti SPAM.url"
    attrib -h -r -s "%AllUsersProfile%\Start Menu\Online Casino.url"
    attrib -h -r -s "%AllUsersProfile%\Start Menu\Online Security Center.url"
    attrib -h -r -s "%AllUsersProfile%\Start Menu\Computer Security.url"
    del /q "%AllUsersProfile%\Favori~1\Cheap Viagra.url"
    del /q "%AllUsersProfile%\Favori~1\Buy Viagra Online.url"
    del /q "%AllUsersProfile%\Start Menu\Anti SPAM.url"
    del /q "%AllUsersProfile%\Start Menu\Online Casino.url"
    del /q "%AllUsersProfile%\Start Menu\Online Security Center.url"
    del /q "%AllUsersProfile%\Start Menu\Computer Security.url"

    attrib -h -r -s "%AllUsersProfile%\Desktop\Security Troubleshooting.lnk"
    attrib -h -r -s "%AllUsersProfile%\Desktop\Online Security Center.lnk"

    del /q "%AllUsersProfile%\Desktop\Security Troubleshooting.lnk"
    del /q "%AllUsersProfile%\Desktop\Online Security Center.lnk"

    attrib -h -r -s "%AllUsersProfile%\Menu Start\Anti SPAM.url"
    attrib -h -r -s "%AllUsersProfile%\Menu Start\Online Casino.url"
    attrib -h -r -s "%AllUsersProfile%\Menu Start\Online Security Center.url"
    attrib -h -r -s "%AllUsersProfile%\Menu Start\Computer Security.url"
    del /q "%AllUsersProfile%\Menu Start\Anti SPAM.url"
    del /q "%AllUsersProfile%\Menu Start\Online Casino.url"
    del /q "%AllUsersProfile%\Menu Start\Online Security Center.url"
    del /q "%AllUsersProfile%\Menu Start\Computer Security.url"

    attrib -h -r -s "%AllUsersProfile%\Bureaublad\Security Troubleshooting.lnk"
    attrib -h -r -s "%AllUsersProfile%\Bureaublad\Online Security Center.lnk"

    del /q "%AllUsersProfile%\Bureaublad\Security Troubleshooting.lnk"
    del /q "%AllUsersProfile%\Bureaublad\Online Security Center.lnk"

    attrib -h -r -s "%systemroot%\Application Data\Shudder Global Limited\*.*"
    del /q "%systemroot%\Application Data\Shudder Global Limited\*.*"
    rmdir /q /s "%systemroot%\Application Data\Shudder Global Limited"

    attrib -h -r -s "%userprofile%\application data\shudder global limited\*.*"
    del /q "%userprofile%\application data\shudder global limited\*.*"
    rmdir /q /s "%userprofile%\application data\shudder global limited"

    attrib -r -h -s "%userprofile%\Bureaublad\Air Tickets.url"
    attrib -r -h -s "%userprofile%\Bureaublad\Big Tits.url"
    attrib -r -h -s "%userprofile%\Bureaublad\Blackjack.url"
    attrib -r -h -s "%userprofile%\Bureaublad\Britney Spears.url"
    attrib -r -h -s "%userprofile%\Bureaublad\Car Insurance.url"
    attrib -r -h -s "%userprofile%\Bureaublad\Cheap Cigarettes.url"
    attrib -r -h -s "%userprofile%\Bureaublad\Credit Card.url"
    attrib -r -h -s "%userprofile%\Bureaublad\Cruises.url"
    attrib -r -h -s "%userprofile%\Bureaublad\Currency Trading.url"
    attrib -r -h -s "%userprofile%\Bureaublad\Lesbian Sex.url"
    attrib -r -h -s "%userprofile%\Bureaublad\MP3.url"
    attrib -r -h -s "%userprofile%\Bureaublad\Online Betting.url"
    attrib -r -h -s "%userprofile%\Bureaublad\Online Gambling.url"
    attrib -r -h -s "%userprofile%\Bureaublad\Oral Sex.url"
    attrib -r -h -s "%userprofile%\Bureaublad\Party Poker.url"
    attrib -r -h -s "%userprofile%\Bureaublad\Pharmacy.url"
    attrib -r -h -s "%userprofile%\Bureaublad\Phentermine.url"
    attrib -r -h -s "%userprofile%\Bureaublad\Pornstars.url"
    attrib -r -h -s "%userprofile%\Bureaublad\Remove Spyware.url"
    attrib -r -h -s "%userprofile%\Bureaublad\viagra.url"
    attrib -r -h -s "%UserProfile%\Desktop\Air Tickets.url"
    attrib -r -h -s "%UserProfile%\Desktop\Big Tits.url"
    attrib -r -h -s "%UserProfile%\Desktop\Blackjack.url"
    attrib -r -h -s "%UserProfile%\Desktop\Britney Spears.url"
    attrib -r -h -s "%UserProfile%\Desktop\Car Insurance.url"
    attrib -r -h -s "%UserProfile%\Desktop\Cheap Cigarettes.url"
    attrib -r -h -s "%UserProfile%\Desktop\Credit Card.url"
    attrib -r -h -s "%UserProfile%\Desktop\Cruises.url"
    attrib -r -h -s "%UserProfile%\Desktop\Currency Trading.url"
    attrib -r -h -s "%UserProfile%\Desktop\Lesbian Sex.url"
    attrib -r -h -s "%UserProfile%\Desktop\MP3.url"
    attrib -r -h -s "%UserProfile%\Desktop\Online Betting.url"
    attrib -r -h -s "%UserProfile%\Desktop\Online Gambling.url"
    attrib -r -h -s "%UserProfile%\Desktop\Oral Sex.url"
    attrib -r -h -s "%UserProfile%\Desktop\Party Poker.url"
    attrib -r -h -s "%UserProfile%\Desktop\Pharmacy.url"
    attrib -r -h -s "%UserProfile%\Desktop\Phentermine.url"
    attrib -r -h -s "%UserProfile%\Desktop\Pornstars.url"
    attrib -r -h -s "%UserProfile%\Desktop\Remove Spyware.url"
    attrib -r -h -s "%UserProfile%\Desktop\viagra.url"
    attrib -r -h -s "%UserProfile%\Favori~1\Need Money.url"

    del /q "%userprofile%\Bureaublad\Air Tickets.url"
    del /q "%userprofile%\Bureaublad\Big Tits.url"
    del /q "%userprofile%\Bureaublad\Blackjack.url"
    del /q "%userprofile%\Bureaublad\Britney Spears.url"
    del /q "%userprofile%\Bureaublad\Car Insurance.url"
    del /q "%userprofile%\Bureaublad\Cheap Cigarettes.url"
    del /q "%userprofile%\Bureaublad\Credit Card.url"
    del /q "%userprofile%\Bureaublad\Cruises.url"
    del /q "%userprofile%\Bureaublad\Currency Trading.url"
    del /q "%userprofile%\Bureaublad\Lesbian Sex.url"
    del /q "%userprofile%\Bureaublad\MP3.url"
    del /q "%userprofile%\Bureaublad\Online Betting.url"
    del /q "%userprofile%\Bureaublad\Online Gambling.url"
    del /q "%userprofile%\Bureaublad\Oral Sex.url"
    del /q "%userprofile%\Bureaublad\Party Poker.url"
    del /q "%userprofile%\Bureaublad\Pharmacy.url"
    del /q "%userprofile%\Bureaublad\Phentermine.url"
    del /q "%userprofile%\Bureaublad\Pornstars.url"
    del /q "%userprofile%\Bureaublad\Remove Spyware.url"
    del /q "%userprofile%\Bureaublad\viagra.url"
    del /q "%UserProfile%\Desktop\Air Tickets.url"
    del /q "%UserProfile%\Desktop\Big Tits.url"
    del /q "%UserProfile%\Desktop\Blackjack.url"
    del /q "%UserProfile%\Desktop\Britney Spears.url"
    del /q "%UserProfile%\Desktop\Car Insurance.url"
    del /q "%UserProfile%\Desktop\Cheap Cigarettes.url"
    del /q "%UserProfile%\Desktop\Credit Card.url"
    del /q "%UserProfile%\Desktop\Cruises.url"
    del /q "%UserProfile%\Desktop\Currency Trading.url"
    del /q "%UserProfile%\Desktop\Lesbian Sex.url"
    del /q "%UserProfile%\Desktop\MP3.url"
    del /q "%UserProfile%\Desktop\Online Betting.url"
    del /q "%UserProfile%\Desktop\Online Gambling.url"
    del /q "%UserProfile%\Desktop\Oral Sex.url"
    del /q "%UserProfile%\Desktop\Party Poker.url"
    del /q "%UserProfile%\Desktop\Pharmacy.url"
    del /q "%UserProfile%\Desktop\Phentermine.url"
    del /q "%UserProfile%\Desktop\Pornstars.url"
    del /q "%UserProfile%\Desktop\Remove Spyware.url"
    del /q "%UserProfile%\Desktop\viagra.url"
    del /q "%UserProfile%\Favori~1\Need Money.url"

    attrib -h -r -s "%AllUsersProfile%\Start Menu\Programs\PSGuard spyware remover\*.*"
    del /q "%AllUsersProfile%\Start Menu\Programs\PSGuard spyware remover\*.*"
    rmdir /q /s "%AllUsersProfile%\Start Menu\Programs\PSGuard spyware remover"

    attrib -h -r -s "%AllUsersProfile%\Start Menu\Programs\PSGuard spyware remover\*.*"
    del /q "%AllUsersProfile%\Start Menu\Programs\PSGuard spyware remover\*.*"
    rmdir /q /s "%AllUsersProfile%\Start Menu\Programs\PSGuard spyware remover"

    attrib -h -r -s "%UserProfile%\Bureaublad\AntivirusGold.lnk"
    del /q "%UserProfile%\Bureaublad\AntivirusGold.lnk"

    attrib -h -r -s "%UserProfile%\Desktop\AntivirusGold.lnk"
    del /q "%UserProfile%\Desktop\AntivirusGold.lnk"

    attrib -h -r -s "%AllUsersProfile%\Bureaublad\PSGuard spyware remover.lnk"
    del /q "%AllUsersProfile%\Bureaublad\PSGuard spyware remover.lnk"

    attrib -h -r -s "%AllUsersProfile%\Desktop\PSGuard spyware remover.lnk"
    del /q "%AllUsersProfile%\Desktop\PSGuard spyware remover.lnk"

    attrib -h -r -s "%userprofile%\Favori~1\adult\*.*"
    attrib -h -r -s "%userprofile%\Favori~1\cars\*.*"
    attrib -h -r -s "%userprofile%\Favori~1\sexual life\*.*"
    attrib -h -r -s "%userprofile%\Favori~1\shopping\*.*"
    attrib -h -r -s "%userprofile%\Favori~1\anti spam.url"
    attrib -h -r -s "%userprofile%\Favori~1\job search.url"
    attrib -h -r -s "%userprofile%\Favori~1\poker.url"
    attrib -h -r -s "%userprofile%\Favori~1\spyware removal.url"

    del /q "%userprofile%\Favori~1\adult\*.*"
    del /q "%userprofile%\Favori~1\cars\*.*"
    del /q "%userprofile%\Favori~1\sexual life\*.*"
    del /q "%userprofile%\Favori~1\shopping\*.*"
    rmdir "%userprofile%\Favori~1\adult"
    rmdir "%userprofile%\Favori~1\cars"
    rmdir "%userprofile%\Favori~1\sexual life"
    rmdir "%userprofile%\Favori~1\shopping"
    del /q "%userprofile%\Favori~1\anti spam.url"
    del /q "%userprofile%\Favori~1\job search.url"
    del /q "%userprofile%\Favori~1\poker.url"
    del /q "%userprofile%\Favori~1\spyware removal.url"

    attrib -h -r -s "%userprofile%\Favori~1\Online Gambling\*.*"
    attrib -h -r -s "%userprofile%\Favori~1\online dating.url"
    attrib -h -r -s "%userprofile%\Favori~1\Black Jack Online.url"
    attrib -h -r -s "%userprofile%\Favori~1\Black Jack Online.url"
    attrib -h -r -s "%userprofile%\Favori~1\Home Loan.url"
    attrib -h -r -s "%userprofile%\Favori~1\Network Security.url"
    attrib -h -r -s "%userprofile%\Favori~1\Online Dating.url"
    attrib -h -r -s "%userprofile%\Favori~1\Online Gambling.url"
    attrib -h -r -s "%userprofile%\Favori~1\Online Pharmacy\*.*"
    attrib -h -r -s "%userprofile%\Favori~1\Online Pharmacy.url"
    attrib -h -r -s "%userprofile%\Favori~1\Remove Spyware.url"
    attrib -h -r -s "%userprofile%\Favori~1\Spam Filters.url"
    attrib -h -r -s "%userprofile%\Favori~1\Take It Here - Free * TGP.url"
    attrib -h -r -s "%userprofile%\Favori~1\Web Detective.url"

    del /q "%userprofile%\Favori~1\Online Gambling\*.*"
    del /q "%userprofile%\Favori~1\online dating.url"
    del /q "%userprofile%\Favori~1\Black Jack Online.url"
    del /q "%userprofile%\Favori~1\Black Jack Online.url"
    del /q "%userprofile%\Favori~1\Home Loan.url"
    del /q "%userprofile%\Favori~1\Network Security.url"
    del /q "%userprofile%\Favori~1\Online Dating.url"
    del /q "%userprofile%\Favori~1\Online Gambling.url"
    del /q "%userprofile%\Favori~1\Online Pharmacy\*.*"
    del /q "%userprofile%\Favori~1\Online Pharmacy.url"
    del /q "%userprofile%\Favori~1\Remove Spyware.url"
    del /q "%userprofile%\Favori~1\Spam Filters.url"
    del /q "%userprofile%\Favori~1\Take It Here - Free * TGP.url"
    del /q "%userprofile%\Favori~1\Web Detective.url"

    rmdir /q /s "%userprofile%\Favori~1\Online Gambling"
    rmdir /q /s "%userprofile%\Favori~1\Online Pharmacy"

    rmdir /q /s "%userprofile%\Favori~1\Online Gambling"
    rmdir /q /s "%userprofile%\Favori~1\Online Pharmacy"

    attrib -h -r -s "%systemdrive%\Archivos de programa\P.S.Guard\*.*"
    del /q "%systemdrive%\Archivos de programa\P.S.Guard\*.*"
    rmdir /q /s "%systemdrive%\Archivos de programa\P.S.Guard"

    attrib -h -r -s "%systemdrive%\progra~1\P.S.Guard\*.*"
    del /q "%systemdrive%\progra~1\P.S.Guard\*.*"
    rmdir /q /s "%systemdrive%\progra~1\P.S.Guard"

    attrib -h -r -s "%systemdrive%\Archivos de programa\Security IGuard\*.*"
    attrib -h -r -s "%systemdrive%\Archivos de programa\Virtual Maid\*.*"
    attrib -h -r -s "%systemdrive%\Archivos de programa\Search Maid\*.*"
    attrib -h -r -s "%systemdrive%\Archivos de programa\AntiVirusGold\*.*"
    attrib -h -r -s "%systemdrive%\Archivos de programa\PSGuard\*.*"
    attrib -h -r -s "%systemdrive%\Archivos de programa\SpySheriff\*.*"
    del /q "%systemdrive%\Archivos de programa\Security IGuard\*.*"
    del /q "%systemdrive%\Archivos de programa\Virtual Maid\*.*"
    del /q "%systemdrive%\Archivos de programa\Search Maid\*.*"
    del /q "%systemdrive%\Archivos de programa\AntiVirusGold\*.*"
    del /q "%systemdrive%\Archivos de programa\PSGuard\*.*"
    del /q "%systemdrive%\Archivos de programa\SpySheriff\*.*"
    rmdir /q /s "%systemdrive%\Archivos de programa\Security IGuard"
    rmdir /q /s "%systemdrive%\Archivos de programa\Virtual Maid"
    rmdir /q /s "%systemdrive%\Archivos de programa\Search Maid"
    rmdir /q /s "%systemdrive%\Archivos de programa\AntiVirusGold"
    rmdir /q /s "%systemdrive%\Archivos de programa\PSGuard"
    rmdir /q /s "%systemdrive%\Archivos de programa\SpySheriff"

    attrib -h -r -s "%allusersprofile%\Bureaublad\Spyware Removal.url"
    attrib -h -r -s "%allusersprofile%\Bureaublad\Online Dating.url"
    attrib -h -r -s "%allusersprofile%\Bureaublad\Online Pharmacy.url"

    del /q "%allusersprofile%\Bureaublad\Spyware Removal.url"
    del /q "%allusersprofile%\Bureaublad\Online Dating.url"
    del /q "%allusersprofile%\Bureaublad\Online Pharmacy.url"

    attrib -h -r -s "%allusersprofile%\Desktop\Spyware Removal.url"
    attrib -h -r -s "%allusersprofile%\Desktop\Online Dating.url"
    attrib -h -r -s "%allusersprofile%\Desktop\Online Pharmacy.url"

    del /q "%allusersprofile%\Desktop\Spyware Removal.url"
    del /q "%allusersprofile%\Desktop\Online Dating.url"
    del /q "%allusersprofile%\Desktop\Online Pharmacy.url"

    attrib -h -r -s "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSGuard spyware remover.lnk"
    del /q "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSGuard spyware remover.lnk"

    attrib -h -r -s "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSGuard.lnk"
    del /q "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSGuard.lnk"

    attrib -h -r -s "%userprofile%\Menu Start\Programma's\SpySheriff\*.*"
    del /q "%userprofile%\Menu Start\Programma's\SpySheriff\*.*"
    rmdir /q /s "%userprofile%\Menu Start\Programma's\SpySheriff"

    attrib -h -r -s "%UserProfile%\Bureaublad\SpySheriff.lnk"
    del /q "%UserProfile%\Bureaublad\SpySheriff.lnk"

    attrib -h -r -s "%AllUsersProfile%\Bureaublad\PSGuard.lnk"
    del /q "%AllUsersProfile%\Bureaublad\PSGuard.lnk"

    attrib -h -r -s "%userprofile%\Application Data\PSGuard.com\*.*"
    del /q "%userprofile%\Application Data\PSGuard.com\*.*"
    rmdir /q /s "%userprofile%\Application Data\PSGuard.com"

    attrib -h -r -s "%userprofile%\Start Menu\Programs\SpySheriff\*.*"
    del /q /s "%userprofile%\Start Menu\Programs\SpySheriff\*.*"
    rmdir /q /s "%userprofile%\Start Menu\Programs\SpySheriff"

    attrib -h -r -s "%userprofile%\Application Data\Install.dat"
    del /q "%userprofile%\Application Data\Install.dat"

    attrib -h -r -s "%UserProfile%\Desktop\SpySheriff.lnk"
    del /q "%UserProfile%\Desktop\SpySheriff.lnk"

    attrib -h -r -s "%AllUsersProfile%\Desktop\PSGuard.lnk"
    del /q ""%AllUsersProfile%\Desktop\PSGuard.lnk"

    attrib -h -r -s "%systemdrive%\progra~1\Security IGuard\*.*"
    attrib -h -r -s "%systemdrive%\progra~1\Virtual Maid\*.*"
    attrib -h -r -s "%systemdrive%\progra~1\Search Maid\*.*"
    attrib -h -r -s "%systemdrive%\progra~1\AntiVirusGold\*.*"
    attrib -h -r -s "%systemdrive%\progra~1\PSGuard\*.*"
    attrib -h -r -s "%systemdrive%\progra~1\SpySheriff\*.*"
    del /q "%systemdrive%\progra~1\Security IGuard\*.*"
    del /q "%systemdrive%\progra~1\Virtual Maid\*.*"
    del /q "%systemdrive%\progra~1\Search Maid\*.*"
    del /q "%systemdrive%\progra~1\AntiVirusGold\*.*"
    del /q "%systemdrive%\progra~1\PSGuard\*.*"
    del /q "%systemdrive%\progra~1\SpySheriff\*.*"
    rmdir /q /s "%systemdrive%\progra~1\Security IGuard"
    rmdir /q /s "%systemdrive%\progra~1\Virtual Maid"
    rmdir /q /s "%systemdrive%\progra~1\Search Maid"
    rmdir /q /s "%systemdrive%\progra~1\AntiVirusGold"
    rmdir /q /s "%systemdrive%\progra~1\PSGuard"
    rmdir /q /s "%systemdrive%\progra~1\SpySheriff"

    attrib -h -r -s %temp%\*.*
    del /q %temp%\*.*
    rmdir /q /s %temp%
    mkdir %temp%

    cls
    @echo off
    cd %systemroot%\system32
    cls
    @echo off

    attrib -r -h -s wbeconm.dll
    del /q wbeconm.dll

    attrib -r -h -s "_plastilin_"
    attrib -r -h -s "atmtd.dll"
    attrib -r -h -s "atmtd.dll._"
    attrib -r -h -s "Defpia32.dll"
    attrib -r -h -s "fhpd.dll"
    attrib -r -h -s "Kdfdlh32.dll"
    attrib -r -h -s "klja.dll"
    attrib -r -h -s "ll.exe"
    attrib -r -h -s "Mhpcja32.dll"
    attrib -r -h -s "Nbfgemln.exe"
    attrib -r -h -s "ongi.dll"
    attrib -r -h -s "perflibs__"
    attrib -r -h -s "svcp.csv"
    attrib -r -h -s "sywsvcs.exe"
    attrib -r -h -s "windesktop.dll"
    attrib -r -h -s "windesktop.exe"
    attrib -r -h -s "wins32.dll"
    attrib -r -h -s "winselect.exe"
    attrib -r -h -s "winsub.xml"
    attrib -r -h -s "zlbw.dll"

    del /q "_plastilin_"
    del /q "atmtd.dll"
    del /q "atmtd.dll._"
    del /q "Defpia32.dll"
    del /q "fhpd.dll"
    del /q "Kdfdlh32.dll"
    del /q "klja.dll"
    del /q "ll.exe"
    del /q "Mhpcja32.dll"
    del /q "Nbfgemln.exe"
    del /q "ongi.dll"
    del /q "perflibs__"
    del /q "svcp.csv"
    del /q "sywsvcs.exe"
    del /q "windesktop.dll"
    del /q "windesktop.exe"
    del /q "wins32.dll"
    del /q "winselect.exe"
    del /q "winsub.xml"
    del /q "zlbw.dll"

    attrib -r -h -s ioctrl.dll
    del /q ioctrl.dll

    attrib -r -h -s svchosts.dll
    del /q svchosts.dll

    attrib -r -h -s oleext32.dll
    del /q oleext32.dll
    attrib -r -h -s ff.tmp
    del /q ff.tmp

    attrib -h -r -s 1024\*.*
    del /q 1024\*.*
    del /q 1024\*.*
    rmdir /q /s 1024

    attrib -r -h -s svchop.exe
    attrib -r -h -s shdochop.dll
    attrib -h -r -s ts.ico
    attrib -h -r -s ot.ico
    attrib -r -h -s ptainfo1.ico
    attrib -r -h -s ptainfo2.ico
    attrib -r -h -s zlbw.dll
    attrib -r -h -s msvol.tlb
    attrib -r -h -s ld****.tmp
    attrib -r -h -s mssearchnet.exe
    attrib -r -h -s ncompat.tlb
    attrib -r -h -s nvctrl.exe
    attrib -r -h -s mscornet.exe
    attrib -r -h -s gunist.exe
    attrib -r -h -s param32.dll
    attrib -r -h -s pop_up.dll
    attrib -r -h -s MP3.ico
    attrib -r -h -s Pharmacy.ico
    attrib -r -h -s viagra.ico
    attrib -r -h -s "searchdll.dll"
    attrib -r -h -s "Air Tickets.ico"
    attrib -r -h -s "Big Tits.ico"
    attrib -r -h -s "Blackjack.ico"
    attrib -r -h -s "Britney Spears.ico"
    attrib -r -h -s "Car Insurance.ico"
    attrib -r -h -s "Cheap Cigarettes.ico"
    attrib -r -h -s "Credit Card.ico"
    attrib -r -h -s Cruises.ico
    attrib -r -h -s "Currency Trading.ico"
    attrib -r -h -s "Lesbian Sex.ico"
    attrib -r -h -s "Online Betting.ico"
    attrib -r -h -s "Online Gambling.ico"
    attrib -r -h -s "Oral Sex.ico"
    attrib -r -h -s "Party Poker.ico"
    attrib -r -h -s "Phentermine.ico"
    attrib -r -h -s "Pornstars.ico"
    attrib -r -h -s "Remove Spyware.ico"

    del /q svchop.exe
    del /q shdochop.dll
    del /q ts.ico
    del /q ot.ico
    del /q ptainfo1.ico
    del /q ptainfo2.ico
    del /q zlbw.dll
    del /q msvol.tlb
    del /q ld****.tmp
    del /q mssearchnet.exe
    del /q ncompat.tlb
    del /q nvctrl.exe
    del /q mscornet.exe
    del /q gunist.exe
    del /q param32.dll
    del /q pop_up.dll
    del /q MP3.ico
    del /q Pharmacy.ico
    del /q viagra.ico
    del /q "searchdll.dll"
    del /q "Air Tickets.ico"
    del /q "Big Tits.ico"
    del /q "Blackjack.ico"
    del /q "Britney Spears.ico"
    del /q "Car Insurance.ico"
    del /q "Cheap Cigarettes.ico"
    del /q "Credit Card.ico"
    del /q Cruises.ico
    del /q "Currency Trading.ico"
    del /q "Lesbian Sex.ico"
    del /q "Online Betting.ico"
    del /q "Online Gambling.ico"
    del /q "Oral Sex.ico"
    del /q "Party Poker.ico"
    del /q "Phentermine.ico"
    del /q "Pornstars.ico"
    del /q "Remove Spyware.ico"

    attrib -h -r -s thn.dll
    del /q thn.dll
    attrib -h -r -s "__delete_on_reboot__intel32.exe"
    del /q "__delete_on_reboot__intel32.exe"
    attrib -h -r -s "__delete_on_reboot__OLEADM.dll"
    del /q "__delete_on_reboot__OLEADM.dll"
    attrib -h -r -s intell32.exe
    del /q intell32.exe
    attrib -h -r -s oleext.dll
    del /q oleext.dll
    attrib -h -r -s oleadm.dll
    del /q oleadm.dll
    attrib -h -r -s wppp.html
    del /q wppp.html
    attrib -h -r -s svcnt.exe
    del /q svcnt.exe
    attrib -h -r -s intel32.exe
    del /q intel32.exe
    attrib -h -r -s hhk.dll.tcf
    del /q hhk.dll.tcf
    attrib -h -r -s perfcii.ini
    del /q perfcii.ini
    attrib -h -r -s oleadm32.dll
    del /q oleadm32.dll
    attrib -h -r -s wp.bmp
    del /q wp.bmp
    attrib -h -r -s hookdump.exe
    del /q hookdump.exe
    attrib -h -r -s winnook.exe
    del /q winnook.exe
    attrib -h -r -s wldr.dll
    del /q wldr.dll
    attrib -h -r -s helper.exe
    del /q helper.exe
    attrib -h -r -s intmonp.exe
    del /q intmonp.exe
    attrib -h -r -s msmsgs.exe
    del /q msmsgs.exe
    attrib -h -r -s ole32vbs.exe
    del /q ole32vbs.exe
    attrib -h -r -s msole32.exe
    del /q msole32.exe
    attrib -h -r -s hp***.tmp
    del /q hp***.tmp
    attrib -h -r -s shnlog.exe
    del /q shnlog.exe
    attrib -h -r -s intmon.exe
    del /q intmon.exe
    attrib -h -r -s hhk.dll
    del /q hhk.dll
    attrib -h -r -s "__delete_on_reboot__intmon.exe"
    del /q "__delete_on_reboot__intmon.exe"
    attrib -h -r -s "Log Files\*.*"
    attrib -h -r -s logfiles\*.*
    del /q "Log Files\*.*"
    del /q logfiles\*.*
    rmdir /q /s "Log Files"
    rmdir /q /s logfiles

    cls
    @echo off
    cd %systemroot%

    cls
    @echo off
    attrib -r -h %systemroot%\RGF2ZQ\*.*
    del /q %systemroot%\RGF2ZQ\*.*
    rmdir %systemroot%\RGF2ZQ

    attrib -h -r -s warnhp.html
    del /q warnhp.html
    attrib -h -r -s wp.bmp
    del /q wp.bmp
    attrib -h -r -s uninstIU.exe
    del /q uninstIU.exe
    attrib -h -r -s zloader3.exe
    del /q zloader3.exe
    attrib -h -r -s desktop.html
    del /q desktop.html
    attrib -h -r -s screen.html
    del /q screen.html
    attrib -h -r -s sites.ini
    del /q sites.ini
    attrib -h -r -s popuper.exe
    del /q popuper.exe

    attrib -h -r -s prefetch\*.*
    del /q prefetch\*.*
    del /q /s prefetch
    attrib -h -r -s temp\*.*
    del /q temp\*.*
    rmdir /q /s temp
    mkdir temp

    cls
    @echo off
    cd %systemroot%\system32\config\system~1\Local Settings

    cls
    @echo off
    attrib -h -r -s temp\*.*
    del /q temp\*.*
    rmdir /q /s temp
    mkdir temp

    cls
    @echo off
    cd %systemroot%\system32\config\system~1\Local Settings\Tempor~1

    cls
    @echo off
    attrib -h -r -s "Content.IE5\*.*"
    del /q "Content.IE5\*.*"
    rmdir /q /s "Content.IE5"
    mkdir "Content.IE5"

    cls
    @echo off
    cd \

    cls
    @echo off
    IF EXIST \temp attrib -h -r -s \temp\*.*
    IF EXIST \temp del /q temp\*.*

    attrib -h -r -s bsw.exe
    del /q bsw.exe
    attrib -h -r -s wp.exe
    del /q wp.exe
    attrib -h -r -s wp.bmp
    del /q wp.bmp
    attrib -h -r -s bsw.bmp
    del /q bsw.bmp
    attrib -h -r -s winstall.exe
    del /q winstall.exe


    cd %systemroot%\system32

    IF EXIST wininet.dll GOTO test
    IF NOT EXIST wininet.dll GOTO missing

    :missing
    del /q %systemdrive%\delfiles.cmd
    cls
    @echo off
    echo.>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo Remaining Post-run Files>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo ~~~ Program Files ~~~>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\Archivos de programa\Winhound" echo Winhound>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\progra~1\Winhound" echo Winhound>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\Archivos de programa\spyaxe" echo SpyAxe>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\progra~1\spyaxe" echo SpyAxe>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\Archivos de programa\SpyTrooper" echo SpyTrooper>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\Archivos de programa\Security Toolbar" echo Security Toolbar>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\progra~1\SpyTrooper" echo SpyTrooper>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\progra~1\Security Toolbar" echo Security Toolbar>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\Archivos de programa\P.S.Guard" echo P.S.Guard>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\Archivos de programa\Security IGuard" echo Security IGuard>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\Archivos de programa\Virtual Maid" echo Virtual Maid>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\Archivos de programa\Search Maid" echo Search Maid>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\Archivos de programa\AntiVirusGold" echo AntiVirusGold>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\Archivos de programa\PSGuard" echo PSGuard>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\Archivos de programa\SpySheriff" echo SpySheriff>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\progra~1\P.S.Guard" echo P.S.Guard>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\progra~1\Security IGuard" echo Security IGuard>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\progra~1\Virtual Maid" echo Virtual Maid>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\progra~1\Search Maid" echo Search Maid>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\progra~1\AntiVirusGold" echo AntiVirusGold>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\progra~1\PSGuard echo" PSGuard>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemdrive%\progra~1\SpySheriff" echo SpySheriff>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo ~~~ Shortcuts ~~~>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Desktop\WinHound spyware remover.lnk" echo WinHound spyware remover.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Bureaublad\WinHound spyware remover.lnk" echo WinHound spyware remover.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinHound spyware remover.lnk" echo quick launch WinHound spyware remover.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Start Menu\Programs\WinHound spyware remover" echo WinHound spyware remover folder>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Menu Start\Programs\WinHound spyware remover" echo WinHound spyware remover folder>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Desktop\Online Security Guide.url" echo Online Security Guide.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Start Menu\Online Security Guide.url" echo Online Security Guide.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Bureaublad\Online Security Guide.url" echo Online Security Guide.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Menu Start\Online Security Guide.url" echo Online Security Guide.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Desktop\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Desktop\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Start Menu\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Desktop\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Desktop\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Bureaublad\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Bureaublad\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Menu Start\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\SpyTrooper.lnk" echo SpyTrooper.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\SpyTrooper.lnk" echo SpyTrooper.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Menu Start\Programma's\SpyTrooper" echo SpyTrooper folder>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Start Menu\Programs\SpyTrooper" echo SpyTrooper folder>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Favori~1\Cheap Viagra.url" echo Cheap Viagra.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Favori~1\Buy Viagra Online.url" echo Buy Viagra Online.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Start Menu\Anti SPAM.url" echo Anti SPAM.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Start Menu\Online Casino.url" echo Online Casino.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Start Menu\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Start Menu\Computer Security.url" echo Computer Security.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Desktop\Security Troubleshooting.lnk" echo Security Troubleshooting.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Desktop\Online Security Center.lnk" echo Online Security Center.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\favorieten\Cheap Viagra.url" echo Cheap Viagra.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\favorieten\Buy Viagra Online.url" echo Buy Viagra Online.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Menu Start\Anti SPAM.url" echo Anti SPAM.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Menu Start\Online Casino.url" echo Online Casino.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Menu Start\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Menu Start\Computer Security.url" echo Computer Security.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Bureaublad\Security Troubleshooting.lnk" echo Security Troubleshooting.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Bureaublad\Online Security Center.lnk" echo Online Security Center.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Air Tickets.url" echo Air Tickets.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Big Tits.url" echo Big Tits.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Blackjack.url" echo Blackjack.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Britney Spears.url" echo Britney Spears.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Car Insurance.url" echo Car Insurance.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Cheap Cigarettes.url" echo Cheap Cigarettes.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Credit Card.url" echo Credit Card.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Cruises.url" echo Cruises.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Currency Trading.url" echo Currency Trading.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Lesbian Sex.url" echo Lesbian Sex.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\MP3.url" echo MP3.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Online Betting.url" echo Online Betting.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Online Gambling.url" echo Online Gambling.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Oral Sex.url" echo Oral Sex.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Party Poker.url" echo Party Poker.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Pharmacy.url" echo Pharmacy.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Phentermine.url" echo Phentermine.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Pornstars.url" echo job Pornstars.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\Remove Spyware.url" echo Remove Spyware.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Bureaublad\viagra.url" echo viagra.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Air Tickets.url" echo Air Tickets.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Big Tits.url" echo Big Tits.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Blackjack.url" echo Blackjack.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Britney Spears.url" echo Britney Spears.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Car Insurance.url" echo Car Insurance.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Cheap Cigarettes.url" echo Cheap Cigarettes.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Credit Card.url" echo Credit Card.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Cruises.url" echo Cruises.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Currency Trading.url" echo Currency Trading.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Lesbian Sex.url" echo Lesbian Sex.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\MP3.url" echo MP3.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Online Betting.url" echo Online Betting.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Online Gambling.url" echo Online Gambling.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Oral Sex.url" echo Oral Sex.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Party Poker.url" echo Party Poker.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Pharmacy.url" echo Pharmacy.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Phentermine.url" echo Phentermine.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Pornstars.url" echo job Pornstars.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\Remove Spyware.url" echo Remove Spyware.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\viagra.url" echo viagra.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Start Menu\Programs\PSGuard spyware remover" echo PSGuard spyware remover>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Menu Start\Programma's\PSGuard spyware remover" echo PSGuard spyware remover>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Bureaublad\AntivirusGold.lnk" echo AntivirusGold.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\AntivirusGold.lnk" echo AntivirusGold.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Bureaublad\PSGuard spyware remover.lnk" echo PSGuard spyware remover.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Desktop\PSGuard spyware remover.lnk" echo PSGuard spyware remover.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Bureaublad\Spyware Removal.url" echo Spyware Removal.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Bureaublad\Online Dating.url" echo Online Dating.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Bureaublad\Online Pharmacy.url" echo Online Pharmacy.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Desktop\Spyware Removal.url" echo Spyware Removal.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Desktop\Online Dating.url" echo Online Dating.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Desktop\Online Pharmacy.url" echo Online Pharmacy.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSGuard spyware remover.lnk" echo quick launch PSGuard spyware remover.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSGuard.lnk" echo quick launch PSGuard.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Menu Start\Programma's\SpySheriff" echo SpySheriff>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Bureaublad\SpySheriff.lnk" echo SpySheriff.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Bureaublad\PSGuard.lnk" echo PSGuard.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Application Data\PSGuard.com" echo PSGuard.com>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Start Menu\Programs\SpySheriff" echo SpySheriff>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Application Data\Install.dat" echo Install.dat>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Desktop\SpySheriff.lnk" echo SpySheriff.lnk>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Desktop\PSGuard.lnk" echo PSGuard.lnk>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo ~~~ Favorites ~~~>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Take It Here - Daily Updated Porn Links.url" echo Take It Here - Daily Updated Porn Links.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Take It Here - Daily Updated Porn Links.url" echo Take It Here - Daily Updated Porn Links.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Favori~1\Free XXX Sites List.url" echo Free XXX Sites List.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Favori~1\Antivirus Test Online.url" echo Antivirus Test Online.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Favori~1\Cheap Viagra.url" echo Cheap Viagra.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%AllUsersProfile%\Favori~1\Buy Viagra Online.url" echo Buy Viagra Online.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%UserProfile%\Favori~1\Need Money.url" echo Need Money.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\adult" echo adult>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\cars" echo cars>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\sexual life" echo sexual life>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\shopping" echo shopping>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\anti spam.url" echo anti spam.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\job search.url" echo job search.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\poker.url" echo poker.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\spyware removal.url" echo spyware removal.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Online Gambling.url" echo Online Gambling.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\online dating.url" echo online dating.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Black Jack Online.url" echo Black Jack Online.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Online Pharmacy\Adipex.url" echo Online Pharmacy\Adipex.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Black Jack Online.url" echo Black Jack Online.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Home Loan.url" echo Home Loan.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Network Security.url" echo Network Security.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Online Dating.url" echo Online Dating.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Adipex.url" echo Adipex.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Alprazolam.url" echo Alprazolam.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Carisoprodol.url" echo Carisoprodol.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Diazepam.url" echo Diazepam.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Hydrocodone.url" echo Hydrocodone.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Lortab.url" echo Lortab.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Online Pharmacy.url" echo Online Pharmacy.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Prozac.url" echo Prozac.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Valium.url" echo Valium.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Vicodin.url" echo Vicodin.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Xanax.url" echo Xanax.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Remove Spyware.url" echo Remove Spyware.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Spam Filters.url" echo Spam Filters.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Take It Here - Free * TGP.url" echo Take It Here - Free * TGP.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Web Detective.url" echo Web Detective.url>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Online Gambling" echo Online Gambling folder>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\Favori~1\Online Pharmacy" echo Online Pharmacy folder>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo ~~~ system32 folder ~~~>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\wbeconm.dll" echo wbeconm.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\_plastilin_" echo _plastilin_>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\atmtd.dll" echo atmtd.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\atmtd.dll._" echo atmtd.dll._>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Defpia32.dll" echo Defpia32.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\fhpd.dll" echo fhpd.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Kdfdlh32.dll" echo Kdfdlh32.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\klja.dll" echo klja.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\ll.exe" echo ll.exe>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Mhpcja32.dll" echo Mhpcja32.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Nbfgemln.exe" echo Nbfgemln.exe>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\ongi.dll" echo ongi.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\perflibs__" echo perflibs__>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\svcp.csv" echo svcp.csv>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\sywsvcs.exe" echo sywsvcs.exe>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\windesktop.dll" echo windesktop.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\windesktop.exe" echo windesktop.exe>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\wins32.dll" echo wins32.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\winselect.exe" echo winselect.exe>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\winsub.xml" echo winsub.xml>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\zlbw.dll" echo zlbw.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\ioctrl.dll" echo ioctrl.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\svchosts.dll" echo svchosts.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\ff.tmp" echo ff.tmp>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\oleext32.dll" echo oleext32.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\1024" echo 1024 dir>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\svchop.exe" echo svchop.exe>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\shdochop.dll" echo shdochop.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\zlbw.dll" echo zlbw.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\msvol.tlb" echo msvol.tlb>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemroot%\system32\ld****.tmp" echo ld****.tmp>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\mssearchnet.exe" echo mssearchnet.exe>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\ncompat.tlb" echo ncompat.tlb>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\nvctrl.exe" echo nvctrl.exe>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\mscornet.exe" echo mscornet.exe>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\gunist.exe" echo gunist.exe>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\param32.dll" echo param32.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\pop_up.dll" echo pop_up.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\searchdll.dll" echo searchdll.dll>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\thn.dll echo thn.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemroot%\system32\__delete_on_reboot__intel32.exe" echo __delete_on_reboot__intel32.exe>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemroot%\system32\__delete_on_reboot__OLEADM.dll" echo __delete_on_reboot__OLEADM.dll>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\intell32.exe echo intell32.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\oleext.dll echo oleext.dll>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\wppp.html echo wppp.html>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\svcnt.exe echo svcnt.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\oleadm.dll echo oleadm.dll>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\intel32.exe echo intel32.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\hhk.dll.tcf echo hhk.dll.tcf>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\perfcii.ini echo perfcii.ini>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\oleadm32.dll echo oleadm32.dll>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\wp.bmp echo wp.bmp>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\hookdump.exe echo hookdump.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\winnook.exe echo winnook.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\wldr.dll echo wldr.dll>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\helper.exe echo helper.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\intmonp.exe echo intmonp.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\msmsgs.exe echo msmsgs.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\ole32vbs.exe echo ole32vbs.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\msole32.exe echo msole32.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\hp***.tmp echo hp***.tmp>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\shnlog.exe echo shnlog.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\intmon.exe echo intmon.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\hhk.dll echo hhk.dll>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemroot%\system32\__delete_on_reboot__intmon.exe" echo __delete_on_reboot__intmon.exe>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemroot%\system32\Log Files" echo Log Files>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\system32\logfiles echo logfiles>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo ~~~ Icons in System32 ~~~>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\ts.ico" echo ts.ico>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\ot.ico" echo ot.ico>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\ptainfo1.ico" echo ptainfo1>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\ptainfo2.ico" echo ptainfo2>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Air Tickets.ico" echo Air Tickets>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Big Tits.ico" echo Big Tits>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Blackjack.ico" echo Blackjack>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Britney Spears.ico" echo Britney Spears>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Car Insurance.ico" echo Car Insurance>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Cheap Cigarettes.ico" echo Cheap Cigarettes>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Credit Card.ico" echo Credit Card>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Cruises.ico" echo Cruises>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Currency Trading.ico" echo Currency Trading>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Lesbian Sex.ico" echo Lesbian Sex>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\MP3.ico" echo MP3>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Online Betting.ico" echo Online Betting>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Online Gambling.ico" echo Online Gambling>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Oral Sex.ico" echo Oral Sex>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Party Poker.ico" echo Party Poker>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Pharmacy.ico" echo Pharmacy>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Phentermine.ico" echo Phentermine>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Pornstars.ico" echo Pornstars>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\Remove Spyware.ico" echo Remove Spyware>>%systemdrive%\smitfiles.txt
    IF EXIST "%Systemroot%\system32\viagra.ico" echo viagra>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo ~~~ Windows directory ~~~>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\RGF2ZQ echo RGF2ZQ folder>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\warnhp.html echo warnhp.html>>%systemdrive%\smitfiles.txt
    IF EXIST "%systemroot%\Application Data\Shudder Global Limited" echo Application Data\Shudder Global Limited>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\wp.bmp echo wp.bmp>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\uninstIU.exe echo uninstIU.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\zloader3.exe echo zloader3.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\desktop.html echo desktop.html>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\screen.html echo screen.html>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\sites.ini echo sites.ini>>%systemdrive%\smitfiles.txt
    IF EXIST %systemroot%\popuper.exe echo popuper.exe>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo ~~~ Drive root ~~~>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    IF EXIST %systemdrive%\bsw.exe echo bsw.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemdrive%\wp.exe echo wp.exe>>%systemdrive%\smitfiles.txt
    IF EXIST %systemdrive%\wp.bmp echo wp.bmp>>%systemdrive%\smitfiles.txt
    IF EXIST %systemdrive%\bsw.bmp echo bsw.bmp>>%systemdrive%\smitfiles.txt
    IF EXIST %systemdrive%\winstall.exe echo winstall.exe>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo ~~~ Miscellaneous Files/folders ~~~>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    IF EXIST "%userprofile%\application data\shudder global limited" echo shudder global limited>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    IF EXIST %systemdrive%\winstall.exe echo winstall.exe>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo ~~~ Wininet.dll ~~~>>%systemdrive%\smitfiles.txt
    echo.>>%systemdrive%\smitfiles.txt
    echo wininet.dll is missing!!>>%systemdrive%\smitfiles.txt

    GOTO finish

    :test
    cls


    Eli mitä teen väärin?
     
  4. -kemisti-

    -kemisti- Active member

    Joined:
    Jun 6, 2005
    Messages:
    6,305
    Likes Received:
    0
    Trophy Points:
    96
    Sun koneessa F8 tuo esiin boot menun eikä sitä valikkoa. Tee näin:

    * Sulje kaikki ohjelmat.
    * Klikkaa käynnistä -> suorita -> msconfig ja OK
    * Valitse BOOT.INI-välilehti, merkkaa "/SAFEBOOT"-valinta, ja sitten klikkaa OK ja käynnistä kone uudelleen sitä pyydettäessä
    * Tietokone käynnistyy vikasietotilaan
    * Tee vikasietotilassa pyydetyt toimenpiteet(eli aja se RunThis.bat smitrem-kansiosta ohjeiden mukaan).
    * Kun olet valmis, mene uudelleen msconfigiin kuten edellä ja ota valinta pois BOOT.INI-välilehdeltä "/SAFEBOOT"-kohdasta ja paina OK, jolloin koneesi käynnistyy normaalisti.

    EDIT: Ja editoi toi edellinen viesti vähän pienemmäks :)

    Lähetä uusi HjT-loki ja c:\smitfiles.txt-tiedoston sisältö
     
    Last edited: Dec 30, 2005
  5. despvi

    despvi Member

    Joined:
    Dec 29, 2005
    Messages:
    7
    Likes Received:
    0
    Trophy Points:
    11
    Nyt alkaa näyttää valoisammalta!

    hjt-loki tässä:

    Logfile of HijackThis v1.99.1
    Scan saved at 13:09:35, on 30.12.2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Norman\Nvc\BIN\NPFSVICE.EXE
    C:\Norman\bin\ZANDA.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\Norman\Nvc\BIN\NVCSCHED.EXE
    C:\Norman\Nvc\BIN\nipsvc.exe
    C:\Norman\bin\NJEEVES.EXE
    C:\Norman\Nvc\bin\nvcoas.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Norman\bin\ZLH.EXE
    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Norman\Nvc\BIN\NIP.EXE
    C:\Norman\Nvc\bin\cclaw.exe
    C:\Norman\Npf\BIN\npfmsg2.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\hjt\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.utu.fi/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.utu.fi/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1121071860546
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O18 - Filter: text/html - (no CLSID) - (no file)
    O18 - Filter: text/plain - (no CLSID) - (no file)
    O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe
    O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE
    O23 - Service: Norman Type-R - Unknown owner - C:\Norman\Nvc\BIN\NPFSVICE.EXE
    O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\bin\ZANDA.EXE
    O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe
    O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    ja smitfiles.txt tässä:

    smitRem © log file
    version 2.8

    by noahdfear


    Microsoft Windows XP [versio 5.1.2600]

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    checking for ShudderLTD key

    ShudderLTD key not present!

    checking for PSGuard.com key


    PSGuard.com key not present!


    checking for WinHound.com key


    WinHound.com key not present!




    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    SpyAxeFix © by noahdfear

    spyaxe directory present

    spyaxe uninstaller present

    Starting spyaxe uninstaller

    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
    "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
    "{A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F}"="Security Update"

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


    Winhound uninstaller NOT present
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Existing Pre-run Files


    ~~~ Program Files ~~~

    SpyAxe


    ~~~ Shortcuts ~~~



    ~~~ Favorites ~~~



    ~~~ system32 folder ~~~

    wbeconm.dll
    1024 dir
    msvol.tlb
    ld****.tmp
    mssearchnet.exe
    ncompat.tlb
    nvctrl.exe
    hp***.tmp


    ~~~ Icons in System32 ~~~

    ts.ico
    ot.ico


    ~~~ Windows directory ~~~



    ~~~ Drive root ~~~


    ~~~ Miscellaneous Files/folders ~~~




    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



    Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
    Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
    Killing PID 728 'explorer.exe'

    Starting registry repairs

    Deleting files


    Remaining Post-run Files


    ~~~ Program Files ~~~

    SpyAxe


    ~~~ Shortcuts ~~~



    ~~~ Favorites ~~~



    ~~~ system32 folder ~~~



    ~~~ Icons in System32 ~~~



    ~~~ Windows directory ~~~



    ~~~ Drive root ~~~



    ~~~ Miscellaneous Files/folders ~~~




    ~~~ Wininet.dll ~~~

    CLEAN! :)

    Uskaltaako tässä nyt jo riemuita (ja nöyrimmästi kiittää auttajaansa)?
     
  6. -kemisti-

    -kemisti- Active member

    Joined:
    Jun 6, 2005
    Messages:
    6,305
    Likes Received:
    0
    Trophy Points:
    96
    Aika hyvä :)

    Poista tämä hakemisto, jos on.

    C:\Program Files\==>SpyAxe<==

    Ja fixaa nämä rivit HjT:llä:

    O18 - Filter: text/html - (no CLSID) - (no file)
    O18 - Filter: text/plain - (no CLSID) - (no file)

    Muuten on kunnossa.
     
  7. despvi

    despvi Member

    Joined:
    Dec 29, 2005
    Messages:
    7
    Likes Received:
    0
    Trophy Points:
    11
    Kyseiset rivit fixattu, SpyAxe-hakemistoja ei löytynyt, kaikki kunnossa!

    Tuhannesti kiitoksia avusta!
     
  8. despvi

    despvi Member

    Joined:
    Dec 29, 2005
    Messages:
    7
    Likes Received:
    0
    Trophy Points:
    11
    Onhan tämä nyt sitten varmasti puhdas? Aloin epäillä, kun Normanin tarkistus kertoi löytäneensä (ja siirtäneensä karanteeniin) tiedostoja, joissa oli troijalainen nimeltään W32/Zlob.GC

    Logfile of HijackThis v1.99.1
    Scan saved at 17:35:00, on 30.12.2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Norman\Nvc\BIN\NPFSVICE.EXE
    C:\Norman\bin\ZANDA.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\Norman\bin\NJEEVES.EXE
    C:\Norman\Nvc\BIN\nipsvc.exe
    C:\Norman\Nvc\BIN\NVCSCHED.EXE
    C:\Norman\Nvc\bin\nvcoas.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Norman\bin\ZLH.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Norman\Nvc\bin\cclaw.exe
    C:\Norman\Nvc\BIN\NIP.EXE
    C:\Norman\Npf\BIN\npfmsg2.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\hjt\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.utu.fi/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.utu.fi/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1121071860546
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O18 - Filter: text/html - (no CLSID) - (no file)
    O18 - Filter: text/plain - (no CLSID) - (no file)
    O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe
    O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE
    O23 - Service: Norman Type-R - Unknown owner - C:\Norman\Nvc\BIN\NPFSVICE.EXE
    O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\bin\ZANDA.EXE
    O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe
    O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

     
  9. -kemisti-

    -kemisti- Active member

    Joined:
    Jun 6, 2005
    Messages:
    6,305
    Likes Received:
    0
    Trophy Points:
    96
    Tyhjennä se Normanin karanteeni vikasietotilassa. Norman on "säilönyt" noita spyaxen pöpöjä sinne. Ja fixaa nämä (vikasietotilassa, jos eivät muuten lähde):

    O18 - Filter: text/html - (no CLSID) - (no file)
    O18 - Filter: text/plain - (no CLSID) - (no file)
     

Share This Page