|
Keskustelualueet
Keskustelualueet
|
|
spyaxe piinaa
|
|
despvi
Newbie
|
29. joulukuuta 2005 @ 13:13 |
Linkki tähän viestiin
|
Apuva!
Spyaxe-ohjelma ei jätä rauhaan. Pyydän nöyrimmästi apua (mahd. yksinkertaisesti selitettynä, olen amatööri). HJT-logi tässä:
Logfile of HijackThis v1.99.1
Scan saved at 18:13:04, on 29.12.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Norman\Nvc\BIN\NPFSVICE.EXE
C:\Norman\bin\ZANDA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Norman\Nvc\BIN\NVCSCHED.EXE
C:\Norman\Nvc\BIN\nipsvc.exe
C:\Norman\bin\NJEEVES.EXE
C:\Norman\Nvc\bin\nvcoas.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvctrl.exe
C:\WINDOWS\system32\mssearchnet.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Norman\bin\ZLH.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Norman\Nvc\BIN\NIP.EXE
C:\Norman\Nvc\bin\cclaw.exe
C:\Norman\Npf\BIN\npfmsg2.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Eero\LOCALS~1\Temp\Tilapäinen kansio 3 hijackthis.zip\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.utu.fi/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.utu.fi/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
O2 - BHO: (no name) - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hpEFAF.tmp (file missing)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll (file missing)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cl... O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE
O23 - Service: Norman Type-R - Unknown owner - C:\Norman\Nvc\BIN\NPFSVICE.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\bin\ZANDA.EXE
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
|
AfterDawn Addict
|
29. joulukuuta 2005 @ 13:18 |
Linkki tähän viestiin
|
Siirrä HjT omaan hakemistoonsa -> c:\hjt\HijackThis.exe
Fixaa HjT:llä (do a system scan only, merkkaa ja paina fix checked):
O2 - BHO: (no name) - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hpEFAF.tmp (file missing)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll (file missing)
Hae smitrem täältä -> http://noahdfear.geekstogo.com/click%20counter/click.php?id=1 Tallenna työpöydälle ja tuplaklikkaa sitä, jolloin se luo smitRem-kansion työpöydälle.
Käynnistä vikasietotilaan (paina F8 käynnistyksen yhteydessä, kunnes tulee valikko. Valitse valikosta vikasietotila), avaa smitRem-kansio ja tuplaklikkaa RunThis.bat. Seuraa ohjeita. Käynnistä kone uudestaan, lähetä uusi HjT-loki ja c:\smitfiles.txt-tiedoston sisältö.
|
despvi
Newbie
|
30. joulukuuta 2005 @ 07:03 |
Linkki tähän viestiin
|
En ole aivan varma, pääsinkö siihen vikasietotilaan. Konetta käynnistettäessä painoin F8:a ja ruutuun tuli: "Please select boot device: SM-HL-DT-ST DVD-RW GWA-4163B
PM-SAMSUNG SP1604N
ESC to boot using defaults"
Ja aina sen jälkeen kone aukeaa ihan normaalisti. Niin että millaiselta sen vikasietotilan kuuluisi näyttää? Smitrem haettu, eikä se RunThis.bat näytä tekevän mitään. Sen muistio näyttää tältä:
@echo off
VER|find "Windows 2000">NUL
IF NOT ERRORLEVEL 1 GOTO notice
VER|find "Windows XP">NUL
IF NOT ERRORLEVEL 1 GOTO notice
VER|find "Windows 95">NUL
IF NOT ERRORLEVEL 1 GOTO notice1
VER|find "Windows 98">NUL
IF NOT ERRORLEVEL 1 GOTO notice1
VER|find "Windows Millennium">NUL
IF NOT ERRORLEVEL 1 GOTO notice1
VER|find "Windows 2003">NUL
IF NOT ERRORLEVEL 1 GOTO notice
echo Unsupported Version
goto end
:notice
color 1F
cls
@echo off
echo.
echo.
echo.
echo ÉÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ»
echo º º
echo º Trojan-Spy.HTML.smitfraud.c Killer º
echo º º
echo º by noahdfear º
echo º º
echo º version 2.8 © º
echo º º
echo ÈÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍͼ
echo.
echo This tool was tailored to remove smitfraud.c and variants
echo.
echo If you do not trust the source, close this window.
echo.
echo noahdfear does not assume any liability
echo.
echo for damage or loss from running this tool
echo.
echo Use at your own risk!!
echo.
echo.
echo.
echo.
pause
cls
@echo off
echo.
echo.
echo This tool will also clean out the contents of temp folders
echo.
echo and the Prefetch folder. It will also run disk cleanup
echo.
echo to clear the Temporary Internet Files on this user profile,
echo.
echo as well as empty the recycle bin.
echo.
echo.
echo.
echo.
pause
cls
GOTO menu2
:notice1
cls
@echo off
echo.
echo.
echo.
echo ÉÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍ»
echo º º
echo º Trojan-Spy.HTML.smitfraud.c Killer º
echo º º
echo º by noahdfear º
echo º º
echo º version 2.8 © º
echo º º
echo ÈÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍÍͼ
echo.
echo This tool was tailored to remove smitfraud.c and variants
echo.
echo If you do not trust the source, close this window.
echo.
echo noahdfear does not assume any liability
echo.
echo for damage or loss from running this tool
echo.
echo Use at your own risk!!
echo.
echo Press 1 to continue or E to exit
echo.
echo.
echo.
echo.
CHOICE /C:1E /N
IF errorlevel==2 GOTO done
IF errorlevel==1 GOTO menu3
cls
:menu3
cls
@echo off
echo.
echo.
echo This tool will also clean out the contents of temp folders.
echo.
echo It will also run disk cleanup to clear the Temporary Internet Files
echo.
echo as well as empty the recycle bin
echo.
echo.
echo Press 1 to continue or E to exit
echo.
echo.
echo.
echo.
CHOICE /C:1E /N
IF errorlevel==2 GOTO done
IF errorlevel==1 GOTO menu2
cls
:menu2
cls
@echo off
VER|find "Windows 2000">NUL
IF NOT ERRORLEVEL 1 GOTO NT
VER|find "Windows XP">NUL
IF NOT ERRORLEVEL 1 GOTO NT
VER|find "Windows 95">NUL
IF NOT ERRORLEVEL 1 GOTO win
VER|find "Windows 98">NUL
IF NOT ERRORLEVEL 1 GOTO win
VER|find "Windows Millennium">NUL
IF NOT ERRORLEVEL 1 GOTO win
VER|find "Windows 2003">NUL
IF NOT ERRORLEVEL 1 GOTO NT
:NT
cls
@echo off
echo.
echo.
echo Please close ALL windows except this one
echo.
echo including the folder you opened to run this tool
echo.
echo Your desktop and taskbar will disappear when you press a key
echo.
echo this window will remain open and others may open.
echo.
echo During this time the bad files will be deleted
echo.
echo When your desktop returns,
echo.
echo continue as instructed by your advisor.
echo.
echo Your desktop background will be reset to blue when you reboot.
echo.
echo.
echo.
echo.
echo.
pause
IF EXIST %systemdrive%\LTD.txt del %systemdrive%\LTD.txt
IF EXIST %systemdrive%\PSGuard.txt del %systemdrive%\PSGuard.txt
cls
@echo off
IF EXIST %systemdrive%\smitfiles.txt del %systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo smitRem © log file>>%systemdrive%\smitfiles.txt
echo version 2.8>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo by noahdfear>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
VER>>%systemdrive%\smitfiles.txt
echo. |date |find "current" >>%systemdrive%\smitfiles.txt
echo. |time |find "current" >>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>%systemdrive%\smitfiles.txt
cls
@echo off
echo.>>%systemdrive%\smitfiles.txt
echo checking for ShudderLTD key>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
regedit.exe /e %systemdrive%\LTD.txt "HKEY_LOCAL_MACHINE\SOFTWARE\SHUDDERLTD"
IF EXIST %systemdrive%\LTD.txt echo ShudderLTD key present!>>%systemdrive%\smitfiles.txt
IF NOT EXIST %systemdrive%\LTD.txt echo ShudderLTD key not present!>>%systemdrive%\smitfiles.txt
IF EXIST %systemdrive%\LTD.txt GOTO LTDFix
IF NOT EXIST %systemdrive%\LTD.txt GOTO psgcheck
:LTDFix
cls
@echo off
echo.>>%systemdrive%\smitfiles.txt
echo Running LTDFix/PSGuard.com fix!>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo checking for PSGuard.com key>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
regedit.exe /e %systemdrive%\PSGuard.txt "HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com"
IF EXIST %systemdrive%\PSGuard.txt echo PSGuard.com key present!>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF NOT EXIST %systemdrive%\PSGuard.txt echo PSGuard.com key not present!>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
cls
@echo off
echo.>>%systemdrive%\smitfiles.txt
echo.
echo.
echo SmitRem © add-on ShudderLTD/PSGuard.com registry Fix
echo.
echo by Miekiemoes, Atribune and noahdfear
echo.
echo.
echo.
echo.
pause
cls
@echo off
echo REGEDIT4>>C:\psguardrem.reg
echo.>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.FoundCollection]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.FoundCollection.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.FoundObject]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.FoundObject.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.KilledProcessesCollection]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.KilledProcessesCollection.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.KilledProcessInfo]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.KilledProcessInfo.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.License]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.License.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.Options]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.Options.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.Quarantine]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.Quarantine.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.RealTime]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.RealTime.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.RTObject]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.RTObject.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.SafeMode]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.SafeMode.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.Scaner]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.Scaner.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.ScanStatistic]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.ScanStatistic.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.theApp]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.theApp.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.Update]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.Update.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.UpdateInfo]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.UpdateInfo.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.VersionInfo]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.VersionInfo.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\WndLayer.Window]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\WndLayer.Window.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\WndLayer.WindowCollection]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\WndLayer.WindowCollection.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\WndLayer.WindowLayer]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\WndLayer.WindowLayer.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{F880B4F2-75BF-44EC-B7AA-45EC37448027}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{E479197F-49E5-4E60-9FA2-A71D4C7C2BBC}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{E12AAACF-8AF2-4C31-BA94-E3787B44F90E}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{D25F7446-4D36-4203-9EA5-5422B26FA9D0}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{CDD964C2-FB78-4A74-BB1E-1CB1FCB72018}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{CBE4B748-08F9-44DB-8FB1-9AD25979DA35}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{C5B70256-5B08-4056-B84E-C6CE084967F5}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{ACC647EE-991A-4811-B420-F063F50CDDC1}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{8DCA6B3D-1FCA-4500-B210-76119BB5C69E}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{8C2A05C5-780F-4A2E-AE1C-FB8181F860E4}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{82847700-FE61-46A3-B3EE-761A1E312ACA}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{7198F8DA-012C-4DB4-ABD8-923A54C87900}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{67196B3E-55A0-49DE-BA11-66F07DF804DB}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{5E5A79A6-C67B-444E-BE58-BD0ACEFCDA07}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{58E68548-42E2-479D-A9E0-86D9F2EAF02E}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{5206DF89-97FC-41AD-BAE3-993E87053A99}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{4F93062D-7BDA-48BE-AEB6-88AF2B1FE2D4}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{4AA55E8C-2C19-4F3A-91EC-43B6DF937C4F}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{41D7BB0A-64E0-4AB2-BD0B-69EA78E462E8}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{0EA04667-E53B-4E81-8E7C-DE2CA114CBD6}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{3946A33D-BBC6-4792-A383-D855E0F76D91}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{265C2AF8-C94C-4AFF-B2B6-340D3982562C}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{0878F045-B52E-46B3-9724-D3AE69D50067}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{04F3168F-5AFC-4531-B3B4-16CA93720415}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{187A8428-BD94-470D-A178-A2347F940519}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{2865930B-4588-4FF3-8227-6D4F66C92C7A}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{2FE2EDC0-9E62-4F34-8A73-BC66DAE48EF3}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{3A3A8C24-8FF0-4140-9731-54D9483EA70B}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{3A906593-B4BD-48ED-84B0-3249BED65EF9}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{49B72A72-01F5-4AE8-BBD7-DAA67F1E303B}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{6AE3ACA6-1BE3-4443-98DD-EFFCFA793D35}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{9F89E240-06A6-4E1C-BA84-F267DE7DB391}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{79DDF2EF-D881-464B-B2AF-5AF8816A3964}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{813C8E86-4C90-4617-B59E-E130CC068140}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{89133BCE-57D0-4D2B-AFAF-A97B74AD704E}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{8F40CC34-FE77-4618-AA3D-BD2EFACAA8DC}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{9F89E240-06A6-4E1C-BA84-F267DE7DB391}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{B60A0E56-548D-40AE-9383-D752531F653F}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{B67B0756-2528-4996-B4BD-C993614CC0B6}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{BCC51EA9-6340-4EBE-8736-13A752ECB0BE}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{E9719D38-EC55-4C8B-9DF0-080ADE95A9FA}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{F4B3E25A-33B4-4647-9A78-B627DDE211A6}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{08101C3E-6C90-439E-9734-6E4DD1B53B69}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{0BACA3C1-F734-4A5F-970A-15DBF7D3C09C}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{09B90087-4FFA-4A44-BE69-DA117A710F07}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{0D4385DF-F78A-4264-A32C-7DD4A72DE539}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{1449F89C-AD28-427A-97FF-1D5BD812EA43}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{19A0B5C9-65FE-4D3B-8BDD-EFB7FE553C58}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{1C08D3D0-1E04-4DDE-AB0A-75355EA2585E}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{19C99256-D011-47E2-BC64-6322096E20A5}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{20F8B70D-9F16-4DCB-8788-90A0498E46B9}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{2871B7AF-2D4C-478F-BE89-881881C272AB}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{28FEDB90-53C7-4928-994A-CEE782606507}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{2B94CDFD-4A45-4B08-B105-54C709D07B28}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{3A350193-C7F7-4E10-B347-02FF4C3CC4E9}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{2C354A9B-A5DF-41A3-BF40-2D72FEAC14D3}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{4723879B-8F52-4BE7-9994-626AFA539366}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{2C797AA0-978C-4AC2-BBB4-F89D410B614E}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{7B6A3434-8625-4ABF-B79D-09D98C2498C4}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{54007809-0689-4A40-9D8F-94C79D87D931}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{8B6C0168-BAAC-4C7C-911E-0132590F5661}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{557C3787-D066-496E-8CAF-BA47DA7365C1}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{8EC33B7D-9953-4EDB-ACE2-D4C105968601}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{5C083B7E-A083-4B20-A7AD-7C8E29085494}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{A00E2305-7001-4200-BA00-5779F9A3E7D3}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{649D371E-D3E3-4FC0-AC82-E91F73D8E79E}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{B803D266-A08D-4A4C-9604-6D35689ABE09}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{655980F1-13D5-4DA2-9E80-AA56C36876CB}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{A917B2F3-A9BF-477C-A0E3-0382D0376159}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{6AF126A9-B07A-4DE4-883E-28D3ECCD75D8}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{B26B5883-F15F-4283-B3D5-A1728077DE47}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{6B436BDD-8B8B-4A1F-ADD5-E67B30C8F7DD}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{B803D266-A08D-4A4C-9604-6D35689ABE09}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{71BF80FD-7E91-4730-B6E8-8F3E81F5C38B}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{CB9385AB-8541-4B2F-A363-48F64C612993}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{81723C8C-918F-4456-B7E8-A68CF7A10C6D}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{D6A7D177-0B2F-4283-B2E8-B6310A45E606}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{82A10659-A1E5-4732-A839-C910D955C88B}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{D5D6E9B5-30D5-4457-AC8B-399205F50411}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{84844B27-0D53-4C71-AB24-0151B33AB02F}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{D6A7D177-0B2F-4283-B2E8-B6310A45E606}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{A8BCF2B9-ED19-4637-AC77-BF59F131FA1F}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{E0D6C30A-B9A3-4181-8099-3B0D5A2B98AF}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{A9A73A66-B0E0-4FFB-828F-3A55E1FA4271}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{B6049D5D-718F-44C0-B965-06840D27E206}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{F100A342-3AC5-47FF-B5B3-FCDB6FC9F016}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{B817D284-1B82-4793-B1F3-58A06DAB03A1}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{BC077DD0-42B5-451C-B78C-4AC97E4B116B}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{C123DBA0-52DF-4272-BBAA-BFD092D07C2E}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{CB9DD914-68B6-4710-A04E-4745470706CE}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{DE1E317F-716A-4784-BA90-FDA6D6A8FAD5}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{E36DCDBC-57AD-4A1C-B9C6-1161441B51CA}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{E51AC62C-E82E-4E60-97AB-C66C4969AF39}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{EF5750B1-0ABA-45C5-BF12-FB4D1D1150D2}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{F1D9585E-20A6-4689-84C7-C19FE21C9A71}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{F1E1A6B0-6CAC-471B-99C4-4DBADA883BE8}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{F8C9D1A9-B7B7-47CA-8B93-27C5B64D3A47}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\TypeLib\{F61D1CE1-5199-4B57-B59E-C6819EA92F3B}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\TypeLib\{31E956BF-8CA9-4D75-B534-7EBC79770002}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\TypeLib\{6E9E448E-B195-4627-953C-5377FA9BBA36}]>>C:\psguardrem.reg
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PSGuard spyware remover]>>C:\psguardrem.reg
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\P.S.Guard spyware remover]>>C:\psguardrem.reg
swreg add HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.comdummy
swreg add HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTDdummy
swreg save HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTDdummy ShudderLTDdummy.hiv
swreg save HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.comdummy PSGuard.comdummy.hiv
swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTDdummy /f
swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.comdummy /f
swreg restore HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTD ShudderLTDdummy.hiv
swreg restore HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com PSGuard.comdummy.hiv
swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTD /f
swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com /f
regedit /s C:\psguardrem.reg
del ShudderLTDdummy.hiv
del PSGuard.comdummy.hiv
del /q C:\psguardrem.reg
del /q %systemdrive%\LTD.txt
del /q %systemdrive%\PSGuard.txt
regedit.exe /e %systemdrive%\LTD.txt "HKEY_LOCAL_MACHINE\SOFTWARE\SHUDDERLTD"
IF EXIST %systemdrive%\LTD.txt echo ShudderLTD key was NOT successfully removed!>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF NOT EXIST %systemdrive%\LTD.txt echo ShudderLTD key was successfully removed! :)>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
regedit.exe /e %systemdrive%\PSGuard.txt "HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com"
IF EXIST %systemdrive%\PSGuard.txt echo PSGuard.com key was NOT successfully removed!>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF NOT EXIST %systemdrive%\PSGuard.txt echo if previously present, PSGuard.com key was successfully removed! :)>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
del /q %systemdrive%\PSGuard.txt
del /q %systemdrive%\LTD.txt
GOTO WinHchck
:psgcheck
cls
@echo off
echo.>>%systemdrive%\smitfiles.txt
echo checking for PSGuard.com key>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
regedit.exe /e %systemdrive%\PSGuard.txt "HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com"
IF EXIST %systemdrive%\PSGuard.txt echo PSGuard.com key present!>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF NOT EXIST %systemdrive%\PSGuard.txt echo PSGuard.com key not present!>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF EXIST %systemdrive%\PSGuard.txt GOTO psgfix
IF NOT EXIST %systemdrive%\PSGuard.txt GOTO WinHchck
:psgfix
cls
@echo off
echo.>>%systemdrive%\smitfiles.txt
echo Running LTDFix/PSGuard.com fix!>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
cls
@echo off
echo.>>%systemdrive%\smitfiles.txt
echo.
echo.
echo SmitRem © add-on ShudderLTD/PSGuard.com registry Fix
echo.
echo by Miekiemoes, Atribune and noahdfear
echo.
echo.
echo.
echo.
pause
cls
@echo off
echo REGEDIT4>>C:\psguardrem.reg
echo.>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.FoundCollection]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.FoundCollection.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.FoundObject]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.FoundObject.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.KilledProcessesCollection]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.KilledProcessesCollection.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.KilledProcessInfo]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.KilledProcessInfo.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.License]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.License.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.Options]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.Options.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.Quarantine]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.Quarantine.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.RealTime]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.RealTime.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.RTObject]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.RTObject.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.SafeMode]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.SafeMode.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.Scaner]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.Scaner.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.ScanStatistic]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.ScanStatistic.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.theApp]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.theApp.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.Update]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.Update.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.UpdateInfo]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.UpdateInfo.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.VersionInfo]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\AVECore.VersionInfo.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\WndLayer.Window]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\WndLayer.Window.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\WndLayer.WindowCollection]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\WndLayer.WindowCollection.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\WndLayer.WindowLayer]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\WndLayer.WindowLayer.1]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{F880B4F2-75BF-44EC-B7AA-45EC37448027}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{E479197F-49E5-4E60-9FA2-A71D4C7C2BBC}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{E12AAACF-8AF2-4C31-BA94-E3787B44F90E}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{D25F7446-4D36-4203-9EA5-5422B26FA9D0}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{CDD964C2-FB78-4A74-BB1E-1CB1FCB72018}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{CBE4B748-08F9-44DB-8FB1-9AD25979DA35}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{C5B70256-5B08-4056-B84E-C6CE084967F5}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{ACC647EE-991A-4811-B420-F063F50CDDC1}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{8DCA6B3D-1FCA-4500-B210-76119BB5C69E}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{8C2A05C5-780F-4A2E-AE1C-FB8181F860E4}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{82847700-FE61-46A3-B3EE-761A1E312ACA}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{7198F8DA-012C-4DB4-ABD8-923A54C87900}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{67196B3E-55A0-49DE-BA11-66F07DF804DB}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{5E5A79A6-C67B-444E-BE58-BD0ACEFCDA07}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{58E68548-42E2-479D-A9E0-86D9F2EAF02E}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{5206DF89-97FC-41AD-BAE3-993E87053A99}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{4F93062D-7BDA-48BE-AEB6-88AF2B1FE2D4}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{4AA55E8C-2C19-4F3A-91EC-43B6DF937C4F}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{41D7BB0A-64E0-4AB2-BD0B-69EA78E462E8}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{0EA04667-E53B-4E81-8E7C-DE2CA114CBD6}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{3946A33D-BBC6-4792-A383-D855E0F76D91}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{265C2AF8-C94C-4AFF-B2B6-340D3982562C}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{0878F045-B52E-46B3-9724-D3AE69D50067}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{04F3168F-5AFC-4531-B3B4-16CA93720415}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{187A8428-BD94-470D-A178-A2347F940519}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{2865930B-4588-4FF3-8227-6D4F66C92C7A}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{2FE2EDC0-9E62-4F34-8A73-BC66DAE48EF3}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{3A3A8C24-8FF0-4140-9731-54D9483EA70B}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{3A906593-B4BD-48ED-84B0-3249BED65EF9}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{49B72A72-01F5-4AE8-BBD7-DAA67F1E303B}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{6AE3ACA6-1BE3-4443-98DD-EFFCFA793D35}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{9F89E240-06A6-4E1C-BA84-F267DE7DB391}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{79DDF2EF-D881-464B-B2AF-5AF8816A3964}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{813C8E86-4C90-4617-B59E-E130CC068140}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{89133BCE-57D0-4D2B-AFAF-A97B74AD704E}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{8F40CC34-FE77-4618-AA3D-BD2EFACAA8DC}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{9F89E240-06A6-4E1C-BA84-F267DE7DB391}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{B60A0E56-548D-40AE-9383-D752531F653F}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{B67B0756-2528-4996-B4BD-C993614CC0B6}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{BCC51EA9-6340-4EBE-8736-13A752ECB0BE}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{E9719D38-EC55-4C8B-9DF0-080ADE95A9FA}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{F4B3E25A-33B4-4647-9A78-B627DDE211A6}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{08101C3E-6C90-439E-9734-6E4DD1B53B69}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{0BACA3C1-F734-4A5F-970A-15DBF7D3C09C}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{09B90087-4FFA-4A44-BE69-DA117A710F07}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{0D4385DF-F78A-4264-A32C-7DD4A72DE539}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{1449F89C-AD28-427A-97FF-1D5BD812EA43}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{19A0B5C9-65FE-4D3B-8BDD-EFB7FE553C58}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{1C08D3D0-1E04-4DDE-AB0A-75355EA2585E}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{19C99256-D011-47E2-BC64-6322096E20A5}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{20F8B70D-9F16-4DCB-8788-90A0498E46B9}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{2871B7AF-2D4C-478F-BE89-881881C272AB}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{28FEDB90-53C7-4928-994A-CEE782606507}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{2B94CDFD-4A45-4B08-B105-54C709D07B28}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{3A350193-C7F7-4E10-B347-02FF4C3CC4E9}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{2C354A9B-A5DF-41A3-BF40-2D72FEAC14D3}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{4723879B-8F52-4BE7-9994-626AFA539366}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{2C797AA0-978C-4AC2-BBB4-F89D410B614E}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{7B6A3434-8625-4ABF-B79D-09D98C2498C4}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{54007809-0689-4A40-9D8F-94C79D87D931}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{8B6C0168-BAAC-4C7C-911E-0132590F5661}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{557C3787-D066-496E-8CAF-BA47DA7365C1}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{8EC33B7D-9953-4EDB-ACE2-D4C105968601}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{5C083B7E-A083-4B20-A7AD-7C8E29085494}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{A00E2305-7001-4200-BA00-5779F9A3E7D3}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{649D371E-D3E3-4FC0-AC82-E91F73D8E79E}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{B803D266-A08D-4A4C-9604-6D35689ABE09}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{655980F1-13D5-4DA2-9E80-AA56C36876CB}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{A917B2F3-A9BF-477C-A0E3-0382D0376159}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{6AF126A9-B07A-4DE4-883E-28D3ECCD75D8}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{B26B5883-F15F-4283-B3D5-A1728077DE47}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{6B436BDD-8B8B-4A1F-ADD5-E67B30C8F7DD}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{B803D266-A08D-4A4C-9604-6D35689ABE09}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{71BF80FD-7E91-4730-B6E8-8F3E81F5C38B}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{CB9385AB-8541-4B2F-A363-48F64C612993}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{81723C8C-918F-4456-B7E8-A68CF7A10C6D}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{D6A7D177-0B2F-4283-B2E8-B6310A45E606}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{82A10659-A1E5-4732-A839-C910D955C88B}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{D5D6E9B5-30D5-4457-AC8B-399205F50411}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{84844B27-0D53-4C71-AB24-0151B33AB02F}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{D6A7D177-0B2F-4283-B2E8-B6310A45E606}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{A8BCF2B9-ED19-4637-AC77-BF59F131FA1F}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{E0D6C30A-B9A3-4181-8099-3B0D5A2B98AF}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{A9A73A66-B0E0-4FFB-828F-3A55E1FA4271}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{B6049D5D-718F-44C0-B965-06840D27E206}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{F100A342-3AC5-47FF-B5B3-FCDB6FC9F016}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{B817D284-1B82-4793-B1F3-58A06DAB03A1}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{BC077DD0-42B5-451C-B78C-4AC97E4B116B}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{C123DBA0-52DF-4272-BBAA-BFD092D07C2E}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{CB9DD914-68B6-4710-A04E-4745470706CE}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{DE1E317F-716A-4784-BA90-FDA6D6A8FAD5}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{E36DCDBC-57AD-4A1C-B9C6-1161441B51CA}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{E51AC62C-E82E-4E60-97AB-C66C4969AF39}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{EF5750B1-0ABA-45C5-BF12-FB4D1D1150D2}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{F1D9585E-20A6-4689-84C7-C19FE21C9A71}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{F1E1A6B0-6CAC-471B-99C4-4DBADA883BE8}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\Interface\{F8C9D1A9-B7B7-47CA-8B93-27C5B64D3A47}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\TypeLib\{F61D1CE1-5199-4B57-B59E-C6819EA92F3B}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\TypeLib\{31E956BF-8CA9-4D75-B534-7EBC79770002}]>>C:\psguardrem.reg
echo [-HKEY_CLASSES_ROOT\TypeLib\{6E9E448E-B195-4627-953C-5377FA9BBA36}]>>C:\psguardrem.reg
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PSGuard spyware remover]>>C:\psguardrem.reg
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\P.S.Guard spyware remover]>>C:\psguardrem.reg
swreg add HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.comdummy
swreg add HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTDdummy
swreg save HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTDdummy ShudderLTDdummy.hiv
swreg save HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.comdummy PSGuard.comdummy.hiv
swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTDdummy /f
swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.comdummy /f
swreg restore HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTD ShudderLTDdummy.hiv
swreg restore HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com PSGuard.comdummy.hiv
swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\ShudderLTD /f
swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com /f
regedit /s C:\psguardrem.reg
del ShudderLTDdummy.hiv
del PSGuard.comdummy.hiv
del /q C:\psguardrem.reg
del /q %systemdrive%\PSGuard.txt
regedit.exe /e %systemdrive%\PSGuard.txt "HKEY_LOCAL_MACHINE\SOFTWARE\PSGuard.com"
IF EXIST %systemdrive%\PSGuard.txt echo PSGuard.com key was NOT successfully removed!>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF NOT EXIST %systemdrive%\PSGuard.txt echo PSGuard.com key was successfully removed! :)>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
del /q %systemdrive%\PSGuard.txt
GOTO WinHchck
:WinHchck
cls
@echo off
echo.>>%systemdrive%\smitfiles.txt
echo checking for WinHound.com key>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
cls
@echo off
if exist %systemdrive%\WinHound.txt del %systemdrive%\WinHound.txt
regedit.exe /e %systemdrive%\WinHound.txt "HKEY_LOCAL_MACHINE\SOFTWARE\WinHound.com"
IF EXIST %systemdrive%\WinHound.txt echo WinHound.com key present!>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF NOT EXIST %systemdrive%\WinHound.txt echo WinHound.com key not present!>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF EXIST %systemdrive%\WinHound.txt GOTO WinHfix
IF NOT EXIST %systemdrive%\WinHound.txt GOTO smitrem
:WinHfix
cls
@echo off
echo.>>%systemdrive%\smitfiles.txt
echo Running WinHound.com fix!>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
cls
@echo off
echo.>>%systemdrive%\smitfiles.txt
echo.
echo.
echo SmitRem © add-on WinHound.com registry Fix
echo.
echo by Miekiemoes, Atribune and noahdfear
echo.
echo.
echo.
echo.
pause
swreg add HKEY_LOCAL_MACHINE\SOFTWARE\WinHound.comdummy
swreg save HKEY_LOCAL_MACHINE\SOFTWARE\WinHound.comdummy WinHound.comdummy.hiv
swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\WinHound.comdummy /f
swreg restore HKEY_LOCAL_MACHINE\SOFTWARE\WinHound.com WinHound.comdummy.hiv
swreg delete HKEY_LOCAL_MACHINE\SOFTWARE\WinHound.com /f
del WinHound.comdummy.hiv
del /q %systemdrive%\WinHound.txt
regedit.exe /e %systemdrive%\WinHound.txt "HKEY_LOCAL_MACHINE\SOFTWARE\WinHound.com"
IF EXIST %systemdrive%\WinHound.txt echo WinHound.com key was NOT successfully removed!>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF NOT EXIST %systemdrive%\WinHound.txt echo WinHound.com key was successfully removed! :)>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
del /q %systemdrive%\WinHound.txt
GOTO smitrem
:smitrem
@echo off
echo.
echo If SpyAxe is found and the uninstaller is present,
echo.
echo the SpyAxe uninstaller will start.
echo.
echo Allow it to continue. Close any browser window it may cause to open.
echo.
echo.
pause
IF EXIST spyaxe.txt del spyaxe.txt
echo.>>spyaxe1.txt
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>spyaxe1.txt
echo.>>spyaxe1.txt
echo SpyAxeFix © by noahdfear>>spyaxe1.txt
echo.>>spyaxe1.txt
IF EXIST C:\progra~1\spyaxe echo spyaxe directory present>>spyaxe1.txt
echo.>>spyaxe1.txt
IF EXIST C:\progra~1\spyaxe\uninst.exe echo spyaxe uninstaller present>>spyaxe1.txt
IF EXIST C:\progra~1\spyaxe\uninst.exe goto cspyaxe
IF NOT EXIST C:\progra~1\spyaxe\uninst.exe goto sys
:cspyaxe
echo.>>spyaxe1.txt
echo Starting spyaxe uninstaller>>spyaxe1.txt
start C:\progra~1\spyaxe\uninst.exe
goto remove
:sys
IF EXIST %systemdrive%\progra~1\spyaxe echo spyaxe directory present>>spyaxe1.txt
echo.>>spyaxe1.txt
IF EXIST %systemdrive%\progra~1\spyaxe\uninst.exe echo spyaxe uninstaller present>>spyaxe1.txt
IF EXIST %systemdrive%\progra~1\spyaxe\uninst.exe goto sysspy
IF NOT EXIST %systemdrive%\progra~1\spyaxe\uninst.exe echo spyaxe uninstaller NOT present>>spyaxe1.txt
IF NOT EXIST %systemdrive%\progra~1\spyaxe\uninst.exe echo spyaxe uninstaller NOT present>>%systemdrive%\smitfiles.txt
IF NOT EXIST %systemdrive%\progra~1\spyaxe\uninst.exe del spyaxe1.txt
IF NOT EXIST %systemdrive%\progra~1\spyaxe\uninst.exe goto winhound
:sysspy
echo.>>spyaxe1.txt
echo Starting spyaxe uninstaller>>spyaxe1.txt
start %systemdrive%\progra~1\spyaxe\uninst.exe
echo.>>spyaxe1.txt
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>spyaxe1.txt
echo.>>spyaxe1.txt
goto remove
:remove
cls
@echo off
echo REGEDIT4>>fix.reg
echo.>>fix.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{E802FFFF-8E58-4d2c-A435-8BEEFB10AB77}]>>fix.reg
echo.>>fix.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{A2D9D3F0-8C2A-2A1D-A376-1BECFB10AB72}]>>fix.reg
echo.>>fix.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{A3D21DFF-2E58-4E2A-A435-8CEAF21F0B29}]>>fix.reg
echo.>>fix.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{C1A8B6A1-2C81-1C3D-A3C6-A1CCDB10B47F}]>>fix.reg
echo.>>fix.reg
echo [-HKEY_CURRENT_USER\Software\Classes\CLSID\{E802FFFF-8E58-4d2c-A435-8BEEFB10AB77}]>>fix.reg
echo.>>fix.reg
echo [-HKEY_CURRENT_USER\Software\Classes\CLSID\{A2D9D3F0-8C2A-2A1D-A376-1BECFB10AB72}]>>fix.reg
echo.>>fix.reg
echo [-HKEY_CURRENT_USER\Software\Classes\CLSID\{A3D21DFF-2E58-4E2A-A435-8CEAF21F0B29}]>>fix.reg
echo.>>fix.reg
echo [-HKEY_CURRENT_USER\Software\Classes\CLSID\{C1A8B6A1-2C81-1C3D-A3C6-A1CCDB10B47F}]>>fix.reg
echo.>>fix.reg
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]>>fix.reg
echo "{E802FFFF-8E58-4d2c-A435-8BEEFB10AB77}"=->>fix.reg
echo "{A2D9D3F0-8C2A-2A1D-A376-1BECFB10AB72}"=->>fix.reg
echo "{A3D21DFF-2E58-4E2A-A435-8CEAF21F0B29}"=->>fix.reg
echo "{C1A8B6A1-2C81-1C3D-A3C6-A1CCDB10B47F}"=->>fix.reg
echo.>>fix.reg
regedit /s fix.reg
cls
@echo off
regedit /a ST.reg HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
echo.>>spyaxe.txt
type spyaxe1.txt >>spyaxe.txt
echo.>>spyaxe.txt
type ST.reg >>spyaxe.txt
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>spyaxe.txt
echo.>>spyaxe.txt
del /q spyaxe1.txt
del /q ST.reg
del /q fix.reg
echo.>>%systemdrive%\smitfiles.txt
type spyaxe.txt>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
del /q spyaxe.txt
cls
echo.
echo.
echo If the SpyAxe uninstaller has completed,
echo.
echo press any key to continue.
echo.
echo.
pause
GOTO winhound
:winhound
@echo off
echo.
echo If Winhound is found and the uninstaller is present,
echo.
echo the Winhound uninstaller will start.
echo.
echo Allow it to continue.
echo.
echo.
pause
IF EXIST winhound.txt del winhound.txt
echo.>>winhound.txt
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>winhound.txt
echo.>>winhound.txt
echo WinhoundFix © by noahdfear>>winhound.txt
echo.>>winhound.txt
IF EXIST C:\progra~1\Winhound echo Winhound directory present>>winhound.txt
echo.>>winhound.txt
IF EXIST C:\progra~1\Winhound\Uninstall.exe echo Winhound uninstaller present>>winhound.txt
IF EXIST C:\progra~1\Winhound\Uninstall.exe goto Winhck
IF NOT EXIST C:\progra~1\Winhound\Uninstall.exe goto winh
:Winhck
echo.>>winhound.txt
echo Starting Winhound uninstaller>>winhound.txt
start C:\progra~1\Winhound\Uninstall.exe
echo.>>winhound.txt
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>winhound.txt
echo.>>winhound.txt
goto removeh
:winh
IF EXIST %systemdrive%\progra~1\Winhound echo Winhound directory present>>winhound.txt
echo.>>winhound.txt
IF EXIST %systemdrive%\progra~1\Winhound\Uninstall.exe echo Winhound uninstaller present>>winhound.txt
IF EXIST %systemdrive%\progra~1\Winhound\Uninstall.exe goto winhrem
IF NOT EXIST %systemdrive%\progra~1\Winhound\Uninstall.exe echo Winhound uninstaller NOT present>>%systemdrive%\smitfiles.txt
IF NOT EXIST %systemdrive%\progra~1\Winhound\Uninstall.exe echo Winhound uninstaller NOT present>>winhound.txt
IF NOT EXIST %systemdrive%\progra~1\Winhound\Uninstall.exe del winhound.txt
IF NOT EXIST %systemdrive%\progra~1\Winhound\Uninstall.exe goto smitrem1
:winhrem
echo.>>winhound.txt
echo Starting Winhound uninstaller>>winhound.txt
start %systemdrive%\progra~1\Winhound\Uninstall.exe
echo.>>winhound.txt
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>winhound.txt
echo.>>winhound.txt
goto removeh
:removeh
cls
echo.
echo.
echo If the Winhound uninstaller has completed,
echo.
echo press any key to continue.
echo.
echo.
pause
echo.>>winhound.txt
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>winhound.txt
echo.>>winhound.txt
echo.>>%systemdrive%\smitfiles.txt
type winhound.txt>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
del /q winhound.txt
goto smitrem1
:smitrem1
cls
@echo off
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo Existing Pre-run Files>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo ~~~ Program Files ~~~>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\Archivos de programa\Winhound" echo Winhound>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\progra~1\Winhound" echo Winhound>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\Archivos de programa\spyaxe" echo SpyAxe>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\progra~1\spyaxe" echo SpyAxe>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\Archivos de programa\SpyTrooper" echo SpyTrooper>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\Archivos de programa\Security Toolbar" echo Security Toolbar>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\progra~1\SpyTrooper" echo SpyTrooper>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\progra~1\Security Toolbar" echo Security Toolbar>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\Archivos de programa\P.S.Guard" echo P.S.Guard>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\Archivos de programa\Security IGuard" echo Security IGuard>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\Archivos de programa\Virtual Maid" echo Virtual Maid>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\Archivos de programa\Search Maid" echo Search Maid>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\Archivos de programa\AntiVirusGold" echo AntiVirusGold>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\Archivos de programa\PSGuard" echo PSGuard>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\Archivos de programa\SpySheriff" echo SpySheriff>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\progra~1\P.S.Guard" echo P.S.Guard>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\progra~1\Security IGuard" echo Security IGuard>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\progra~1\Virtual Maid" echo Virtual Maid>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\progra~1\Search Maid" echo Search Maid>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\progra~1\AntiVirusGold" echo AntiVirusGold>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\progra~1\PSGuard" echo PSGuard>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\progra~1\SpySheriff" echo SpySheriff>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo ~~~ Shortcuts ~~~>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Desktop\WinHound spyware remover.lnk" echo WinHound spyware remover.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Bureaublad\WinHound spyware remover.lnk" echo WinHound spyware remover.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinHound spyware remover.lnk" echo quick launch WinHound spyware remover.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Start Menu\Programs\WinHound spyware remover" echo WinHound spyware remover folder>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Menu Start\Programs\WinHound spyware remover" echo WinHound spyware remover folder>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Desktop\Online Security Guide.url" echo Online Security Guide.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Start Menu\Online Security Guide.url" echo Online Security Guide.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Bureaublad\Online Security Guide.url" echo Online Security Guide.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Menu Start\Online Security Guide.url" echo Online Security Guide.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Desktop\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Desktop\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Start Menu\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Desktop\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Desktop\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Bureaublad\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Bureaublad\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Menu Start\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\SpyTrooper.lnk" echo SpyTrooper.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\SpyTrooper.lnk" echo SpyTrooper.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Menu Start\Programma's\SpyTrooper" echo SpyTrooper folder>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Start Menu\Programs\SpyTrooper" echo SpyTrooper folder>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Bureaublad\Security Troubleshooting.lnk" echo Security Troubleshooting.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Bureaublad\Online Security Center.lnk" echo Online Security Center.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Menu Start\Anti SPAM.url" echo Anti SPAM.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Menu Start\Online Casino.url" echo Online Casino.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Menu Start\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Menu Start\Computer Security.url" echo Computer Security.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Desktop\Security Troubleshooting.lnk" echo Security Troubleshooting.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Desktop\Online Security Center.lnk" echo Online Security Center.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Start Menu\Anti SPAM.url" echo Anti SPAM.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Start Menu\Online Casino.url" echo Online Casino.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Start Menu\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Start Menu\Computer Security.url" echo Computer Security.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Air Tickets.url" echo Air Tickets.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Big Tits.url" echo Big Tits.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Blackjack.url" echo Blackjack.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Britney Spears.url" echo Britney Spears.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Car Insurance.url" echo Car Insurance.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Cheap Cigarettes.url" echo Cheap Cigarettes.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Credit Card.url" echo Credit Card.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Cruises.url" echo Cruises.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Currency Trading.url" echo Currency Trading.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Lesbian Sex.url" echo Lesbian Sex.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\MP3.url" echo MP3.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Online Betting.url" echo Online Betting.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Online Gambling.url" echo Online Gambling.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Oral Sex.url" echo Oral Sex.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Party Poker.url" echo Party Poker.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Pharmacy.url" echo Pharmacy.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Phentermine.url" echo Phentermine.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Pornstars.url" echo job Pornstars.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Remove Spyware.url" echo Remove Spyware.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\viagra.url" echo viagra.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Air Tickets.url" echo Air Tickets.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Big Tits.url" echo Big Tits.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Blackjack.url" echo Blackjack.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Britney Spears.url" echo Britney Spears.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Car Insurance.url" echo Car Insurance.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Cheap Cigarettes.url" echo Cheap Cigarettes.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Credit Card.url" echo Credit Card.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Cruises.url" echo Cruises.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Currency Trading.url" echo Currency Trading.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Lesbian Sex.url" echo Lesbian Sex.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\MP3.url" echo MP3.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Online Betting.url" echo Online Betting.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Online Gambling.url" echo Online Gambling.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Oral Sex.url" echo Oral Sex.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Party Poker.url" echo Party Poker.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Pharmacy.url" echo Pharmacy.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Phentermine.url" echo Phentermine.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Pornstars.url" echo job Pornstars.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Remove Spyware.url" echo Remove Spyware.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\viagra.url" echo viagra.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Start Menu\Programs\PSGuard spyware remover" echo PSGuard spyware remover>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Menu Start\Programma's\PSGuard spyware remover" echo PSGuard spyware remover>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Bureaublad\AntivirusGold.lnk" echo AntivirusGold.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\AntivirusGold.lnk" echo AntivirusGold.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Bureaublad\PSGuard spyware remover.lnk" echo PSGuard spyware remover.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Desktop\PSGuard spyware remover.lnk" echo PSGuard spyware remover.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Bureaublad\Spyware Removal.url" echo Spyware Removal.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Bureaublad\Online Dating.url" echo Online Dating.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Bureaublad\Online Pharmacy.url" echo Online Pharmacy.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Desktop\Spyware Removal.url" echo Spyware Removal.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Desktop\Online Dating.url" echo Online Dating.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Desktop\Online Pharmacy.url" echo Online Pharmacy.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSGuard spyware remover.lnk" echo quick launch PSGuard spyware remover.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSGuard.lnk" echo quick launch PSGuard.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Menu Start\Programma's\SpySheriff" echo SpySheriff>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Bureaublad\SpySheriff.lnk" echo SpySheriff.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Bureaublad\PSGuard.lnk" echo PSGuard.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Application Data\PSGuard.com" echo PSGuard.com>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Start Menu\Programs\SpySheriff" echo SpySheriff>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Application Data\Install.dat" echo Install.dat>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\SpySheriff.lnk" echo SpySheriff.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Desktop\PSGuard.lnk" echo PSGuard.lnk>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo ~~~ Favorites ~~~>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Take It Here - Daily Updated Porn Links.url" echo Take It Here - Daily Updated Porn Links.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Take It Here - Daily Updated Porn Links.url" echo Take It Here - Daily Updated Porn Links.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Favori~1\Free XXX Sites List.url" echo Free XXX Sites List.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Favori~1\Antivirus Test Online.url" echo Antivirus Test Online.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Favori~1\Cheap Viagra.url" echo Cheap Viagra.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Favori~1\Buy Viagra Online.url" echo Buy Viagra Online.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Favori~1\Need Money.url" echo Need Money.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\adult" echo adult>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\cars" echo cars>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\sexual life" echo sexual life>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\shopping" echo shopping>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\anti spam.url" echo anti spam.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\job search.url" echo job search.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\poker.url" echo poker.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\spyware removal.url" echo spyware removal.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Online Gambling.url" echo Online Gambling.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\online dating.url" echo online dating.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Black Jack Online.url" echo Black Jack Online.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Online Pharmacy\Adipex.url" echo Online Pharmacy\Adipex.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Black Jack Online.url" echo Black Jack Online.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Home Loan.url" echo Home Loan.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Network Security.url" echo Network Security.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Online Dating.url" echo Online Dating.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Adipex.url" echo Adipex.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Alprazolam.url" echo Alprazolam.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Carisoprodol.url" echo Carisoprodol.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Diazepam.url" echo Diazepam.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Hydrocodone.url" echo Hydrocodone.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Lortab.url" echo Lortab.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Online Pharmacy.url" echo Online Pharmacy.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Prozac.url" echo Prozac.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Valium.url" echo Valium.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Vicodin.url" echo Vicodin.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Xanax.url" echo Xanax.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Remove Spyware.url" echo Remove Spyware.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Spam Filters.url" echo Spam Filters.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Take It Here - Free * TGP.url" echo Take It Here - Free * TGP.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Web Detective.url" echo Web Detective.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Online Gambling" echo Online Gambling folder>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Online Pharmacy" echo Online Pharmacy folder>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo ~~~ system32 folder ~~~>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\wbeconm.dll" echo wbeconm.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\_plastilin_" echo _plastilin_>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\atmtd.dll" echo atmtd.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\atmtd.dll._" echo atmtd.dll._>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Defpia32.dll" echo Defpia32.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\fhpd.dll" echo fhpd.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Kdfdlh32.dll" echo Kdfdlh32.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\klja.dll" echo klja.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\ll.exe" echo ll.exe>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Mhpcja32.dll" echo Mhpcja32.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Nbfgemln.exe" echo Nbfgemln.exe>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\ongi.dll" echo ongi.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\perflibs__" echo perflibs__>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\svcp.csv" echo svcp.csv>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\sywsvcs.exe" echo sywsvcs.exe>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\windesktop.dll" echo windesktop.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\windesktop.exe" echo windesktop.exe>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\wins32.dll" echo wins32.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\winselect.exe" echo winselect.exe>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\winsub.xml" echo winsub.xml>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\zlbw.dll" echo zlbw.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\ioctrl.dll" echo ioctrl.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\svchosts.dll" echo svchosts.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\ff.tmp" echo ff.tmp>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\oleext32.dll" echo oleext32.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\1024" echo 1024 dir>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\svchop.exe" echo svchop.exe>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\shdochop.dll" echo shdochop.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\zlbw.dll" echo zlbw.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\msvol.tlb" echo msvol.tlb>>%systemdrive%\smitfiles.txt
IF EXIST "%systemroot%\system32\ld****.tmp" echo ld****.tmp>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\mssearchnet.exe" echo mssearchnet.exe>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\ncompat.tlb" echo ncompat.tlb>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\nvctrl.exe" echo nvctrl.exe>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\mscornet.exe" echo mscornet.exe>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\gunist.exe" echo gunist.exe>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\param32.dll" echo param32.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\pop_up.dll" echo pop_up.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\searchdll.dll" echo searchdll.dll>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\thn.dll echo thn.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%systemroot%\system32\__delete_on_reboot__intel32.exe" echo __delete_on_reboot__intel32.exe>>%systemdrive%\smitfiles.txt
IF EXIST "%systemroot%\system32\__delete_on_reboot__OLEADM.dll" echo __delete_on_reboot__OLEADM.dll>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\intell32.exe echo intell32.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\oleext.dll echo oleext.dll>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\wppp.html echo wppp.html>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\svcnt.exe echo svcnt.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\oleadm.dll echo oleadm.dll>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\intel32.exe echo intel32.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\hhk.dll.tcf echo hhk.dll.tcf>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\perfcii.ini echo perfcii.ini>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\oleadm32.dll echo oleadm32.dll>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\wp.bmp echo wp.bmp>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\hookdump.exe echo hookdump.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\winnook.exe echo winnook.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\wldr.dll echo wldr.dll>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\helper.exe echo helper.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\intmonp.exe echo intmonp.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\msmsgs.exe echo msmsgs.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\ole32vbs.exe echo ole32vbs.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\msole32.exe echo msole32.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\hp***.tmp echo hp***.tmp>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\shnlog.exe echo shnlog.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\intmon.exe echo intmon.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\hhk.dll echo hhk.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%systemroot%\system32\__delete_on_reboot__intmon.exe" echo __delete_on_reboot__intmon.exe>>%systemdrive%\smitfiles.txt
IF EXIST "%systemroot%\system32\Log Files" echo Log Files>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\logfiles echo logfiles>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo ~~~ Icons in System32 ~~~>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\ts.ico" echo ts.ico>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\ot.ico" echo ot.ico>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\ptainfo1.ico" echo ptainfo1>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\ptainfo2.ico" echo ptainfo2>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Air Tickets.ico" echo Air Tickets>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Big Tits.ico" echo Big Tits>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Blackjack.ico" echo Blackjack>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Britney Spears.ico" echo Britney Spears>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Car Insurance.ico" echo Car Insurance>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Cheap Cigarettes.ico" echo Cheap Cigarettes>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Credit Card.ico" echo Credit Card>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Cruises.ico" echo Cruises>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Currency Trading.ico" echo Currency Trading>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Lesbian Sex.ico" echo Lesbian Sex>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\MP3.ico" echo MP3>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Online Betting.ico" echo Online Betting>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Online Gambling.ico" echo Online Gambling>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Oral Sex.ico" echo Oral Sex>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Party Poker.ico" echo Party Poker>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Pharmacy.ico" echo Pharmacy>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Phentermine.ico" echo Phentermine>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Pornstars.ico" echo Pornstars>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Remove Spyware.ico" echo Remove Spyware>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\viagra.ico" echo viagra>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo ~~~ Windows directory ~~~>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\RGF2ZQ echo RGF2ZQ folder>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\warnhp.html echo warnhp.html>>%systemdrive%\smitfiles.txt
IF EXIST "%systemroot%\Application Data\Shudder Global Limited" echo Application Data\Shudder Global Limited>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\wp.bmp echo wp.bmp>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\uninstIU.exe echo uninstIU.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\zloader3.exe echo zloader3.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\desktop.html echo desktop.html>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\screen.html echo screen.html>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\sites.ini echo sites.ini>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\popuper.exe echo popuper.exe>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo ~~~ Drive root ~~~>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF EXIST %systemdrive%\bsw.exe echo bsw.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemdrive%\wp.exe echo wp.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemdrive%\wp.bmp echo wp.bmp>>%systemdrive%\smitfiles.txt
IF EXIST %systemdrive%\bsw.bmp echo bsw.bmp>>%systemdrive%\smitfiles.txt
IF EXIST %systemdrive%\winstall.exe echo winstall.exe>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo ~~~ Miscellaneous Files/folders ~~~>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\application data\shudder global limited" echo shudder global limited>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
cls
@echo off
if exist %systemdrive%\replace.cmd del replace.cmd
copy replace.cmd %systemdrive%\replace.cmd
cls
@echo off
if exist %systemdrive%\delfiles.cmd del delfiles.cmd
copy delfiles.cmd %systemdrive%\delfiles.cmd
cls
@echo off
echo.>>%systemdrive%\smitfiles.txt
process -k explorer.exe>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo Starting registry repairs>>%systemdrive%\smitfiles.txt
cls
@echo off
echo REGEDIT4>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{e0103cd4-d1ce-411a-b75b-4fec072867f4}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e0103cd4-d1ce-411a-b75b-4fec072867f4}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e0103cd4-d1ce-411a-b75b-4fec072867f4}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]>>C:\smitfrau.reg
echo "{A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F}"=->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CURRENT_USER\Software\Classes\CLSID\{A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CMDSERVICE]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MCHINJDRV]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdService]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mchInjDrv]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MCHINJDRV]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mchInjDrv]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]>>C:\smitfrau.reg
echo "windesktop" =->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]>>C:\smitfrau.reg
echo "windesktop" =->>C:\smitfrau.reg
echo "WinHound" =->>C:\smitfrau.reg
echo "sp" =->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchAssistant Uninstall]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinHound spyware remover]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Policies]>>C:\smitfrau.reg
echo "{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}" =->>C:\smitfrau.reg
echo "{645FF040-5081-101B-9F08-00AA002F954E}" =->>C:\smitfrau.reg
echo "{6BF52A52-394A-11D3-B153-00C04F79FAA6}" =->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced]>>C:\smitfrau.reg
echo "SeparateProcess" =dword:00000000>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3E01D51F-E9BD-4902-A0DE-2F4AA5A03092}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\New Windows]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DownloadManager]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\text/html]>>C:\smitfrau.reg
echo "{348722EC-7332-496E-B944-FF60A9456D46}" =->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\text/plain]>>C:\smitfrau.reg
echo "{348722EC-7332-496E-B944-FF60A9456D46}" =->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]>>C:\smitfrau.reg
echo "NoActiveDesktopChanges"=dword:00000000>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{736B5468-BDAD-41BE-92D0-22AE2DDF7BCB}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{1ca480cd-c0e5-4548-874e-b85b17905b3a}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1ca480cd-c0e5-4548-874e-b85b17905b3a}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1ca480cd-c0e5-4548-874e-b85b17905b3a}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objecta\{724510c3-f3c8-4fb7-879a-d99f29008a2f}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{724510C3-F3C8-4FB7-879A-D99F29008A2F}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]>>C:\smitfrau.reg
echo "SpyAxe"=->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{724510c3-f3c8-4fb7-879a-d99f29008a2f}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{724510c3-f3c8-4fb7-879a-d99f29008a2f}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]>>C:\smitfrau.reg
echo "Display Inline Images"=->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{736B5468-BDAD-41BE-92D0-22AE2DDF7BCB}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{736B5468-BDAD-41BE-92D0-22AE2DDF7BCB}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]>>C:\smitfrau.reg
echo "{736B5468-BDAD-41BE-92D0-22AE2DDF7BCB}"=->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{3e9b951e-6f72-431b-82cf-4a9fbf2f53bc}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3e9b951e-6f72-431b-82cf-4a9fbf2f53bc}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7288c0bd-7f2f-4229-a0c4-3c90a6e2a881}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7caf96a2-c556-460a-988e-76fc7895d284}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\clsid\{e9ccf15d-4c68-4b5a-9e9a-8e12e4bd39bd}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{736B5468-BDAD-41BE-92D0-22AE2DDF7BCB}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\clsid\{057e242f-2947-4e0a-8e61-a11345d97ea6}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CURRENT_USER\Software\SNO2]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CURRENT_USER\Software\SpyTrooper]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e9ccf15d-4c68-4b5a-9e9a-8e12e4bd39bd}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]>>C:\smitfrau.reg
echo "{736b5468-bdad-41be-92d0-22ae2ddf7bcb}"=->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpyTrooper]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]>>C:\smitfrau.reg
echo "FH"=->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]>>C:\smitfrau.reg
echo "SpyTrooper"=->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\uuid]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Classes\HP]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Classes\HP.1]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{15DC7116-E58E-4395-A45A-A1C99B17C030}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{17E02586-A91D-4A9D-A74E-187B05DFFE6F}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{1BD98DFD-2DA9-4C54-85D7-BE03A0F9C487}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{1C94EA51-3800-4F08-B5DC-A5B67823FFEA}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{20D1AF34-6E19-42D8-AF9F-BDFBE45C2454}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{21E132C9-1F98-4151-BDAD-7D9B49C60A8E}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{23F7AD29-F51A-4BA1-BE70-143B1CB25BD1}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{2C59D5EC-6B91-4896-BD6F-5F121D87A7F8}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{2F34E0E0-F0BB-477F-AFB8-509262FA0AD1}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{35ED274E-3F42-4A78-BBDC-3B7D73E85578}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{3D74D140-F780-4AE3-8D6D-F8DC39107213}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{49443D6E-CE4E-47A9-8DEB-F5774CE14984}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{52034AD2-914C-4634-B375-9299631E5525}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{7702C521-76AE-42C0-A181-3B5A96C2EEF7}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{7ADDA344-1D36-4446-9F4B-B2351FB19EFD}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{7D98221E-AF8F-4D29-8BB1-1DFABC288173}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{9746B450-6064-4EC8-9480-72A289AA2237}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{C5A40FCE-0A0F-40CA-985E-661C28B5B431}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{C7F22879-7151-4C71-8C50-9557AFDA66C6}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{CA5E7959-60B5-47B7-80AC-1606309733F3}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{CEABF027-6CDC-4D47-ADF6-AC5D065826A6}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{E0AA0493-C410-4CBD-B1DB-1723374FA8E0}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{E5D78BD8-3874-4AA0-9D45-CFB79382C484}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\NVideoCodek.Chl]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{77B2F8DE-CB3F-4B6B-839B-807DD1ADBA1C}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{081669BA-EFC4-48C2-A8F4-874052D02553}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{145E6FB1-1256-44ED-A336-8BBA43373BE6}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{1D27320E-2DA2-41E2-A103-B5FD9D6A798B}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B599C57E-113A-4488-A5E9-BC552C4F1152}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{D56A1203-1452-EBA1-7294-EE3377770000}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{C7EDAB2E-D7F9-11D8-BA48-C79B0C409D70}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Classes\Interface\{C7EDAB2E-D7F9-11D8-BA48-C79B0C409D70}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Classes\Typelib\{C7EDAB2E-D7F9-11D8-BA48-C79B0C409D70}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Classes\Serch_hook.transURL]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Classes\Serch_hook.transURL.1]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database\Distribution Units\{11120607-1001-1111-1000-110199901123}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\{081669BA-EFC4-48C2-A8F4-874052D02553}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Internet Connection Update and HomeP KB234087]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\{081669BA-EFC4-48C2-A8F4-874052D02553}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{081669BA-EFC4-48C2-A8F4-874052D02553}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]>>C:\smitfrau.reg
echo "{D56A1203-1452-EBA1-7294-EE3377770000}"=->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]>>C:\smitfrau.reg
echo "{C7EDAB2E-D7F9-11D8-BA48-C79B0C409D70}"=->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\{E7C9AF76-A50A-423A-A5CA-88DB1A24CEAE}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PSGUARD SPYWARE REMOVER]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]>>C:\smitfrau.reg
echo "P.S.Guard"=->>C:\smitfrau.reg
echo "Fast Start"=->>C:\smitfrau.reg
echo "AntivirusGold"=->>C:\smitfrau.reg
echo "PSGuard spyware remover"=->>C:\smitfrau.reg
echo "intell32.exe"=->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Update]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager]>>C:\smitfrau.reg
echo "AllowProtectedRenames"="0">>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\AdwareDelete]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Desktop]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]>>C:\smitfrau.reg
echo "SNInstall"=->>C:\smitfrau.reg
echo "Windows installer"=->>C:\smitfrau.reg
echo "SpySheriff"=->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]>>C:\smitfrau.reg
echo "ForceActiveDesktopOn"=->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]>>C:\smitfrau.reg
echo "Wallpaper"=->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]>>C:\smitfrau.reg
echo "DisableTaskMgr"=dword:00000000>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\LocalUser\Software\Microsoft\Windows\CurrentVersion\Policies\System]>>C:\smitfrau.reg
echo "DisableTaskMgr"=dword:00000000>>C:\smitfrau.reg
echo "**del.DisableTaskMgr"=" ">>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]>>C:\smitfrau.reg
echo "DisableTaskMgr"=dword:00000000>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]>>C:\smitfrau.reg
echo "DisableCAD"=dword:00000000>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{357A87ED-3E5D-437d-B334-DEB7EB4982A3}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]>>C:\smitfrau.reg
echo "WindowsFZ"=->>C:\smitfrau.reg
echo "PSGuard"=->>C:\smitfrau.reg
echo "intel32.exe"=->>C:\smitfrau.reg
echo "RegSvr32"=->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]>>C:\smitfrau.reg
echo "Intel system tool"=->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\AntivirusGold]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]>>C:\smitfrau.reg
echo "Use Search Asst"=->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]>>C:\smitfrau.reg
echo "NoDispAppearancePage"=->>C:\smitfrau.reg
echo "Wallpaper"=->>C:\smitfrau.reg
echo "WallpaperStyle"=->>C:\smitfrau.reg
echo "NoDispBackgroundPage"=->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]>>C:\smitfrau.reg
echo "NoActiveDesktopChanges"=->>C:\smitfrau.reg
echo "NoActiveDesktop"=->>C:\smitfrau.reg
echo "NoSaveSettings"=->>C:\smitfrau.reg
echo "ClassicShell"=->>C:\smitfrau.reg
echo "NoThemesTab"=->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]>>C:\smitfrau.reg
echo "wininet.dll"=->>C:\smitfrau.reg
echo "kernel32.dll"=->>C:\smitfrau.reg
echo "nvctrl.exe"=->>C:\smitfrau.reg
echo "notepad.exe"=->>C:\smitfrau.reg
echo "notepad2.exe"=->>C:\smitfrau.reg
echo "winlogon.exe"=->>C:\smitfrau.reg
echo "paint.exe"=->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_CURRENT_USER\Control Panel\Desktop]>>C:\smitfrau.reg
echo "Wallpaper"=->>C:\smitfrau.reg
echo "WallpaperStyle"=->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_CURRENT_USER\Control Panel\Colors]>>C:\smitfrau.reg
echo "Background"="0 78 152">>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop]>>C:\smitfrau.reg
echo "NoChangingWallPaper"=->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{893fad3a-931e-4e53-b515-b1426d63799b}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3bf1f86f-b1a8-489b-8d8b-43781d51411f}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]>>C:\smitfrau.reg
echo "SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm"... echo "CustomizeSearch"="http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm"... echo "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"... echo.>>C:\smitfrau.reg
echo [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]>>C:\smitfrau.reg
echo "Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"... echo "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"... echo.>>C:\smitfrau.reg
echo [HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main]>>C:\smitfrau.reg
echo "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"... echo "Search Bar"="Search Bar"="http://search.msn.com/intl/searchpane/en-au/prov2.htm">&g... echo.>>C:\smitfrau.reg
echo [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\main]>>C:\smitfrau.reg
echo "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"... echo "Search Bar"="http://search.msn.com/spbasic.htm">>C:\smitfrau.reg echo "Use Custom Search URL"=dword:00000000>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]>>C:\smitfrau.reg
echo ""="http://home.microsoft.com/access/autosearch.asp?p=%s">>... echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\VMHomepage]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\CLSID\VMHomepage.1]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\Interface\{1E1B2878-88FF-11D2-8D96-D7ACAC95951F}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\TypeLib\{1E1B286C-88FF-11D2-8D96-D7ACAC95951F}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\VMHomepage]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_CLASSES_ROOT\VMHomepage.1]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objecta]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\HTTP\Parameters\S]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\HTTP\Parameters\S]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\r]>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]>>C:\smitfrau.reg
echo "NoActiveDesktopChanges"=hex:00000000>>C:\smitfrau.reg
echo "NoActiveDesktop"=dword:00000000>>C:\smitfrau.reg
echo "NoSaveSettings"=dword:00000000>>C:\smitfrau.reg
echo "ClassicShell"=dword:00000000>>C:\smitfrau.reg
echo "NoThemesTab"=dword:00000000>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]>>C:\smitfrau.reg
echo "NoDispAppearancePage"=dword:00000000>>C:\smitfrau.reg
echo "NoColorChoice"=dword:00000000>>C:\smitfrau.reg
echo "NoSizeChoice"=dword:00000000>>C:\smitfrau.reg
echo "NoDispBackgroundPage"=dword:00000000>>C:\smitfrau.reg
echo "NoDispScrSavPage"=dword:00000000>>C:\smitfrau.reg
echo "NoDispCPL"=dword:00000000>>C:\smitfrau.reg
echo "NoVisualStyleChoice"=dword:00000000>>C:\smitfrau.reg
echo "NoDispSettingsPage"=dword:00000000>>C:\smitfrau.reg
echo "NoDispScrSavPage"=dword:00000000>>C:\smitfrau.reg
echo "NoVisualStyleChoice"=dword:00000000>>C:\smitfrau.reg
echo "NoSizeChoice"=dword:00000000>>C:\smitfrau.reg
echo "SetVisualStyle"=->>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop]>>C:\smitfrau.reg
echo "NoChangingWallPaper"=dword:00000000>>C:\smitfrau.reg
echo "NoAddingComponents"=dword:00000000>>C:\smitfrau.reg
echo "NoComponents"=dword:00000000>>C:\smitfrau.reg
echo "NoDeletingComponents"=dword:00000000>>C:\smitfrau.reg
echo "NoEditingComponents"=dword:00000000>>C:\smitfrau.reg
echo "NoCloseDragDropBands"=dword:00000000>>C:\smitfrau.reg
echo "NoMovingBands"=dword:00000000>>C:\smitfrau.reg
echo "NoHTMLWallPaper"=dword:00000000>>C:\smitfrau.reg
echo.>>C:\smitfrau.reg
echo [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ThemeManager]>>C:\smitfrau.reg
echo "ThemeActive"="1"
echo "DllName"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\>>C:\smitfrau.reg
echo 74,00,25,00,5c,00,72,00,65,00,73,00,6f,00,75,00,72,00,63,00,65,00,73,00,5c,\>>C:\smitfrau.reg
echo 00,54,00,68,00,65,00,6d,00,65,00,73,00,5c,00,6c,00,75,00,6e,00,61,00,5c,00,\>>C:\smitfrau.reg
echo 6c,00,75,00,6e,00,61,00,2e,00,6d,00,73,00,73,00,74,00,79,00,6c,00,65,00,73,\>>C:\smitfrau.reg
echo 00,00,00>>C:\smitfrau.reg
cls
@echo off
regedit.exe /s C:\smitfrau.reg
echo.>>%systemdrive%\smitfiles.txt
echo Deleting files>>%systemdrive%\smitfiles.txt
cls
@echo off
attrib -h -r -s "%AllUsersProfile%\Desktop\WinHound spyware remover.lnk"
attrib -h -r -s "%AllUsersProfile%\Bureaublad\WinHound spyware remover.lnk"
attrib -h -r -s "%AllUsersProfile%\Start Menu\WinHound spyware remover\*.*"
attrib -h -r -s "%AllUsersProfile%\Menu Start\WinHound spyware remover\*.*"
del /q "%AllUsersProfile%\Desktop\WinHound spyware remover.lnk"
del /q "%AllUsersProfile%\Bureaublad\WinHound spyware remover.lnk"
del /q "%AllUsersProfile%\Start Menu\WinHound spyware remover\*.*"
del /q "%AllUsersProfile%\Menu Start\WinHound spyware remover\*.*"
rmdir /q /s "%AllUsersProfile%\Start Menu\Programs\WinHound spyware remover"
rmdir /q /s "%AllUsersProfile%\Menu Start\Programs\WinHound spyware remover"
attrib -h -r -s "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinHound spyware remover.lnk"
del /q "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinHound spyware remover.lnk"
attrib -r -h "%systemdrive%\Archivos de programa\Winhound\Trash\*.*"
del /q "%systemdrive%\Archivos de programa\Winhound\Trash\*.*"
rmdir "%systemdrive%\Archivos de programa\Winhound\Trash"
attrib -r -h %systemdrive%\progra~1\Winhound\Trash\*.*
del /q %systemdrive%\progra~1\Winhound\Trash\*.*
rmdir %systemdrive%\progra~1\Winhound\Trash\
attrib -r -h "%systemdrive%\Archivos de programa\Winhound\*.*"
del /q "%systemdrive%\Archivos de programa\Winhound\*.*"
rmdir "%systemdrive%\Archivos de programa\Winhound"
attrib -r -h %systemdrive%\progra~1\Winhound\*.*
del /q %systemdrive%\progra~1\Winhound\*.*
rmdir %systemdrive%\progra~1\Winhound
attrib -h -r -s "%AllUsersProfile%\Desktop\WinHound spyware remover.lnk"
attrib -h -r -s "%AllUsersProfile%\Bureaublad\WinHound spyware remover.lnk"
attrib -h -r -s "%AllUsersProfile%\Start Menu\WinHound spyware remover\*.*"
attrib -h -r -s "%AllUsersProfile%\Menu Start\WinHound spyware remover\*.*"
del /q "%AllUsersProfile%\Desktop\WinHound spyware remover.lnk"
del /q "%AllUsersProfile%\Bureaublad\WinHound spyware remover.lnk"
del /q "%AllUsersProfile%\Start Menu\WinHound spyware remover\*.*"
del /q "%AllUsersProfile%\Menu Start\WinHound spyware remover\*.*"
rmdir /q /s "%AllUsersProfile%\Start Menu\Programs\WinHound spyware remover"
rmdir /q /s "%AllUsersProfile%\Menu Start\Programs\WinHound spyware remover"
attrib -h -r -s "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinHound spyware remover.lnk"
del /q "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinHound spyware remover.lnk"
attrib -h -r -s "%AllUsersProfile%\Desktop\Online Security Center.url"
attrib -h -r -s "%AllUsersProfile%\Start Menu\Security Troubleshooting.url"
attrib -h -r -s "%AllUsersProfile%\Bureaublad\Online Security Center.url"
attrib -h -r -s "%AllUsersProfile%\Menu Start\Security Troubleshooting.url"
del /q "%AllUsersProfile%\Desktop\Online Security Center.url"
del /q "%AllUsersProfile%\Start Menu\Security Troubleshooting.url"
del /q "%AllUsersProfile%\Bureaublad\Online Security Center.url"
del /q "%AllUsersProfile%\Menu Start\Security Troubleshooting.url"
attrib -h -r -s "%AllUsersProfile%\Desktop\Security Troubleshooting.url"
attrib -h -r -s "%AllUsersProfile%\Desktop\Online Security Center.url"
attrib -h -r -s "%AllUsersProfile%\Start Menu\Security Troubleshooting.url"
attrib -h -r -s "%userprofile%\Desktop\Security Troubleshooting.url"
attrib -h -r -s "%userprofile%\Desktop\Online Security Center.url"
attrib -h -r -s "%userprofile%\Favori~1\Take It Here - Daily Updated Porn Links.url"
del /q "%AllUsersProfile%\Desktop\Security Troubleshooting.url"
del /q "%AllUsersProfile%\Desktop\Online Security Center.url"
del /q "%AllUsersProfile%\Start Menu\Security Troubleshooting.url"
del /q "%userprofile%\Desktop\Security Troubleshooting.url"
del /q "%userprofile%\Desktop\Online Security Center.url"
del /q "%userprofile%\Favori~1\Take It Here - Daily Updated Porn Links.url"
attrib -h -r -s "%AllUsersProfile%\Bureaublad\Security Troubleshooting.url"
attrib -h -r -s "%AllUsersProfile%\Bureaublad\Online Security Center.url"
attrib -h -r -s "%AllUsersProfile%\Menu Start\Security Troubleshooting.url"
attrib -h -r -s "%userprofile%\Bureaublad\Security Troubleshooting.url"
attrib -h -r -s "%userprofile%\Bureaublad\Online Security Center.url"
attrib -h -r -s "%userprofile%\Favori~1\Take It Here - Daily Updated Porn Links.url"
del /q "%AllUsersProfile%\Bureaublad\Security Troubleshooting.url"
del /q "%AllUsersProfile%\Bureaublad\Online Security Center.url"
del /q "%AllUsersProfile%\Menu Start\Security Troubleshooting.url"
del /q "%userprofile%\Bureaublad\Security Troubleshooting.url"
del /q "%userprofile%\Bureaublad\Online Security Center.url"
del /q "%userprofile%\Favori~1\Take It Here - Daily Updated Porn Links.url"
attrib -r -h "%systemdrive%\Archivos de programa\spyaxe\*.*"
del /q "%systemdrive%\Archivos de programa\spyaxe\*.*"
rmdir "%systemdrive%\Archivos de programa\spyaxe"
attrib -r -h %systemdrive%\progra~1\spyaxe\*.*
del /q %systemdrive%\progra~1\spyaxe\*.*
rmdir %systemdrive%\progra~1\spyaxe
attrib -h -r -s "%systemdrive%\Archivos de programa\SpyTrooper\*.*"
del /q "%systemdrive%\Archivos de programa\SpyTrooper\*.*"
rmdir /q /s "%systemdrive%\Archivos de programa\SpyTrooper"
attrib -h -r -s "%systemdrive%\Archivos de programa\Security Toolbar\*.*"
del /q "%systemdrive%\Archivos de programa\Security Toolbar\*.*"
rmdir /q /s "%systemdrive%\Archivos de programa\Security Toolbar"
attrib -h -r -s "%systemdrive%\progra~1\SpyTrooper\*.*"
del /q "%systemdrive%\progra~1\SpyTrooper\*.*"
rmdir /q /s "%systemdrive%\progra~1\SpyTrooper"
attrib -h -r -s "%systemdrive%\progra~1\Security Toolbar\*.*"
del /q "%systemdrive%\progra~1\Security Toolbar\*.*"
rmdir /q /s "%systemdrive%\progra~1\Security Toolbar"
attrib -r -h -s "%userprofile%\Bureaublad\SpyTrooper.lnk"
attrib -r -h -s "%UserProfile%\Desktop\SpyTrooper.lnk"
del /q "%userprofile%\Bureaublad\SpyTrooper.lnk"
del /q "%UserProfile%\Desktop\SpyTrooper.lnk"
attrib -h -r -s "%userprofile%\Menu Start\Programma's\SpyTrooper\*.*"
del /q "%userprofile%\Menu Start\Programma's\SpyTrooper\*.*"
rmdir /q /s "%userprofile%\Menu Start\Programma's\SpyTrooper"
attrib -h -r -s "%userprofile%\Start Menu\Programs\SpyTrooper\*.*"
del /q "%userprofile%\Start Menu\Programs\SpyTrooper\*.*"
rmdir /q /s "%userprofile%\Start Menu\Programs\SpyTrooper"
attrib -r -h -s "%UserProfile%\Favori~1\Free XXX Sites List.url"
del /q "%userprofile%\Favori~1\Free XXX Sites List.url"
attrib -r -h -s "%UserProfile%\Favori~1\Antivirus Test Online.url"
del /q "%UserProfile%\Favori~1\Antivirus Test Online.url"
attrib -h -r -s "%AllUsersProfile%\Favori~1\Cheap Viagra.url"
attrib -h -r -s "%AllUsersProfile%\Favori~1\Buy Viagra Online.url"
attrib -h -r -s "%AllUsersProfile%\Start Menu\Anti SPAM.url"
attrib -h -r -s "%AllUsersProfile%\Start Menu\Online Casino.url"
attrib -h -r -s "%AllUsersProfile%\Start Menu\Online Security Center.url"
attrib -h -r -s "%AllUsersProfile%\Start Menu\Computer Security.url"
del /q "%AllUsersProfile%\Favori~1\Cheap Viagra.url"
del /q "%AllUsersProfile%\Favori~1\Buy Viagra Online.url"
del /q "%AllUsersProfile%\Start Menu\Anti SPAM.url"
del /q "%AllUsersProfile%\Start Menu\Online Casino.url"
del /q "%AllUsersProfile%\Start Menu\Online Security Center.url"
del /q "%AllUsersProfile%\Start Menu\Computer Security.url"
attrib -h -r -s "%AllUsersProfile%\Desktop\Security Troubleshooting.lnk"
attrib -h -r -s "%AllUsersProfile%\Desktop\Online Security Center.lnk"
del /q "%AllUsersProfile%\Desktop\Security Troubleshooting.lnk"
del /q "%AllUsersProfile%\Desktop\Online Security Center.lnk"
attrib -h -r -s "%AllUsersProfile%\Menu Start\Anti SPAM.url"
attrib -h -r -s "%AllUsersProfile%\Menu Start\Online Casino.url"
attrib -h -r -s "%AllUsersProfile%\Menu Start\Online Security Center.url"
attrib -h -r -s "%AllUsersProfile%\Menu Start\Computer Security.url"
del /q "%AllUsersProfile%\Menu Start\Anti SPAM.url"
del /q "%AllUsersProfile%\Menu Start\Online Casino.url"
del /q "%AllUsersProfile%\Menu Start\Online Security Center.url"
del /q "%AllUsersProfile%\Menu Start\Computer Security.url"
attrib -h -r -s "%AllUsersProfile%\Bureaublad\Security Troubleshooting.lnk"
attrib -h -r -s "%AllUsersProfile%\Bureaublad\Online Security Center.lnk"
del /q "%AllUsersProfile%\Bureaublad\Security Troubleshooting.lnk"
del /q "%AllUsersProfile%\Bureaublad\Online Security Center.lnk"
attrib -h -r -s "%systemroot%\Application Data\Shudder Global Limited\*.*"
del /q "%systemroot%\Application Data\Shudder Global Limited\*.*"
rmdir /q /s "%systemroot%\Application Data\Shudder Global Limited"
attrib -h -r -s "%userprofile%\application data\shudder global limited\*.*"
del /q "%userprofile%\application data\shudder global limited\*.*"
rmdir /q /s "%userprofile%\application data\shudder global limited"
attrib -r -h -s "%userprofile%\Bureaublad\Air Tickets.url"
attrib -r -h -s "%userprofile%\Bureaublad\Big Tits.url"
attrib -r -h -s "%userprofile%\Bureaublad\Blackjack.url"
attrib -r -h -s "%userprofile%\Bureaublad\Britney Spears.url"
attrib -r -h -s "%userprofile%\Bureaublad\Car Insurance.url"
attrib -r -h -s "%userprofile%\Bureaublad\Cheap Cigarettes.url"
attrib -r -h -s "%userprofile%\Bureaublad\Credit Card.url"
attrib -r -h -s "%userprofile%\Bureaublad\Cruises.url"
attrib -r -h -s "%userprofile%\Bureaublad\Currency Trading.url"
attrib -r -h -s "%userprofile%\Bureaublad\Lesbian Sex.url"
attrib -r -h -s "%userprofile%\Bureaublad\MP3.url"
attrib -r -h -s "%userprofile%\Bureaublad\Online Betting.url"
attrib -r -h -s "%userprofile%\Bureaublad\Online Gambling.url"
attrib -r -h -s "%userprofile%\Bureaublad\Oral Sex.url"
attrib -r -h -s "%userprofile%\Bureaublad\Party Poker.url"
attrib -r -h -s "%userprofile%\Bureaublad\Pharmacy.url"
attrib -r -h -s "%userprofile%\Bureaublad\Phentermine.url"
attrib -r -h -s "%userprofile%\Bureaublad\Pornstars.url"
attrib -r -h -s "%userprofile%\Bureaublad\Remove Spyware.url"
attrib -r -h -s "%userprofile%\Bureaublad\viagra.url"
attrib -r -h -s "%UserProfile%\Desktop\Air Tickets.url"
attrib -r -h -s "%UserProfile%\Desktop\Big Tits.url"
attrib -r -h -s "%UserProfile%\Desktop\Blackjack.url"
attrib -r -h -s "%UserProfile%\Desktop\Britney Spears.url"
attrib -r -h -s "%UserProfile%\Desktop\Car Insurance.url"
attrib -r -h -s "%UserProfile%\Desktop\Cheap Cigarettes.url"
attrib -r -h -s "%UserProfile%\Desktop\Credit Card.url"
attrib -r -h -s "%UserProfile%\Desktop\Cruises.url"
attrib -r -h -s "%UserProfile%\Desktop\Currency Trading.url"
attrib -r -h -s "%UserProfile%\Desktop\Lesbian Sex.url"
attrib -r -h -s "%UserProfile%\Desktop\MP3.url"
attrib -r -h -s "%UserProfile%\Desktop\Online Betting.url"
attrib -r -h -s "%UserProfile%\Desktop\Online Gambling.url"
attrib -r -h -s "%UserProfile%\Desktop\Oral Sex.url"
attrib -r -h -s "%UserProfile%\Desktop\Party Poker.url"
attrib -r -h -s "%UserProfile%\Desktop\Pharmacy.url"
attrib -r -h -s "%UserProfile%\Desktop\Phentermine.url"
attrib -r -h -s "%UserProfile%\Desktop\Pornstars.url"
attrib -r -h -s "%UserProfile%\Desktop\Remove Spyware.url"
attrib -r -h -s "%UserProfile%\Desktop\viagra.url"
attrib -r -h -s "%UserProfile%\Favori~1\Need Money.url"
del /q "%userprofile%\Bureaublad\Air Tickets.url"
del /q "%userprofile%\Bureaublad\Big Tits.url"
del /q "%userprofile%\Bureaublad\Blackjack.url"
del /q "%userprofile%\Bureaublad\Britney Spears.url"
del /q "%userprofile%\Bureaublad\Car Insurance.url"
del /q "%userprofile%\Bureaublad\Cheap Cigarettes.url"
del /q "%userprofile%\Bureaublad\Credit Card.url"
del /q "%userprofile%\Bureaublad\Cruises.url"
del /q "%userprofile%\Bureaublad\Currency Trading.url"
del /q "%userprofile%\Bureaublad\Lesbian Sex.url"
del /q "%userprofile%\Bureaublad\MP3.url"
del /q "%userprofile%\Bureaublad\Online Betting.url"
del /q "%userprofile%\Bureaublad\Online Gambling.url"
del /q "%userprofile%\Bureaublad\Oral Sex.url"
del /q "%userprofile%\Bureaublad\Party Poker.url"
del /q "%userprofile%\Bureaublad\Pharmacy.url"
del /q "%userprofile%\Bureaublad\Phentermine.url"
del /q "%userprofile%\Bureaublad\Pornstars.url"
del /q "%userprofile%\Bureaublad\Remove Spyware.url"
del /q "%userprofile%\Bureaublad\viagra.url"
del /q "%UserProfile%\Desktop\Air Tickets.url"
del /q "%UserProfile%\Desktop\Big Tits.url"
del /q "%UserProfile%\Desktop\Blackjack.url"
del /q "%UserProfile%\Desktop\Britney Spears.url"
del /q "%UserProfile%\Desktop\Car Insurance.url"
del /q "%UserProfile%\Desktop\Cheap Cigarettes.url"
del /q "%UserProfile%\Desktop\Credit Card.url"
del /q "%UserProfile%\Desktop\Cruises.url"
del /q "%UserProfile%\Desktop\Currency Trading.url"
del /q "%UserProfile%\Desktop\Lesbian Sex.url"
del /q "%UserProfile%\Desktop\MP3.url"
del /q "%UserProfile%\Desktop\Online Betting.url"
del /q "%UserProfile%\Desktop\Online Gambling.url"
del /q "%UserProfile%\Desktop\Oral Sex.url"
del /q "%UserProfile%\Desktop\Party Poker.url"
del /q "%UserProfile%\Desktop\Pharmacy.url"
del /q "%UserProfile%\Desktop\Phentermine.url"
del /q "%UserProfile%\Desktop\Pornstars.url"
del /q "%UserProfile%\Desktop\Remove Spyware.url"
del /q "%UserProfile%\Desktop\viagra.url"
del /q "%UserProfile%\Favori~1\Need Money.url"
attrib -h -r -s "%AllUsersProfile%\Start Menu\Programs\PSGuard spyware remover\*.*"
del /q "%AllUsersProfile%\Start Menu\Programs\PSGuard spyware remover\*.*"
rmdir /q /s "%AllUsersProfile%\Start Menu\Programs\PSGuard spyware remover"
attrib -h -r -s "%AllUsersProfile%\Start Menu\Programs\PSGuard spyware remover\*.*"
del /q "%AllUsersProfile%\Start Menu\Programs\PSGuard spyware remover\*.*"
rmdir /q /s "%AllUsersProfile%\Start Menu\Programs\PSGuard spyware remover"
attrib -h -r -s "%UserProfile%\Bureaublad\AntivirusGold.lnk"
del /q "%UserProfile%\Bureaublad\AntivirusGold.lnk"
attrib -h -r -s "%UserProfile%\Desktop\AntivirusGold.lnk"
del /q "%UserProfile%\Desktop\AntivirusGold.lnk"
attrib -h -r -s "%AllUsersProfile%\Bureaublad\PSGuard spyware remover.lnk"
del /q "%AllUsersProfile%\Bureaublad\PSGuard spyware remover.lnk"
attrib -h -r -s "%AllUsersProfile%\Desktop\PSGuard spyware remover.lnk"
del /q "%AllUsersProfile%\Desktop\PSGuard spyware remover.lnk"
attrib -h -r -s "%userprofile%\Favori~1\adult\*.*"
attrib -h -r -s "%userprofile%\Favori~1\cars\*.*"
attrib -h -r -s "%userprofile%\Favori~1\sexual life\*.*"
attrib -h -r -s "%userprofile%\Favori~1\shopping\*.*"
attrib -h -r -s "%userprofile%\Favori~1\anti spam.url"
attrib -h -r -s "%userprofile%\Favori~1\job search.url"
attrib -h -r -s "%userprofile%\Favori~1\poker.url"
attrib -h -r -s "%userprofile%\Favori~1\spyware removal.url"
del /q "%userprofile%\Favori~1\adult\*.*"
del /q "%userprofile%\Favori~1\cars\*.*"
del /q "%userprofile%\Favori~1\sexual life\*.*"
del /q "%userprofile%\Favori~1\shopping\*.*"
rmdir "%userprofile%\Favori~1\adult"
rmdir "%userprofile%\Favori~1\cars"
rmdir "%userprofile%\Favori~1\sexual life"
rmdir "%userprofile%\Favori~1\shopping"
del /q "%userprofile%\Favori~1\anti spam.url"
del /q "%userprofile%\Favori~1\job search.url"
del /q "%userprofile%\Favori~1\poker.url"
del /q "%userprofile%\Favori~1\spyware removal.url"
attrib -h -r -s "%userprofile%\Favori~1\Online Gambling\*.*"
attrib -h -r -s "%userprofile%\Favori~1\online dating.url"
attrib -h -r -s "%userprofile%\Favori~1\Black Jack Online.url"
attrib -h -r -s "%userprofile%\Favori~1\Black Jack Online.url"
attrib -h -r -s "%userprofile%\Favori~1\Home Loan.url"
attrib -h -r -s "%userprofile%\Favori~1\Network Security.url"
attrib -h -r -s "%userprofile%\Favori~1\Online Dating.url"
attrib -h -r -s "%userprofile%\Favori~1\Online Gambling.url"
attrib -h -r -s "%userprofile%\Favori~1\Online Pharmacy\*.*"
attrib -h -r -s "%userprofile%\Favori~1\Online Pharmacy.url"
attrib -h -r -s "%userprofile%\Favori~1\Remove Spyware.url"
attrib -h -r -s "%userprofile%\Favori~1\Spam Filters.url"
attrib -h -r -s "%userprofile%\Favori~1\Take It Here - Free * TGP.url"
attrib -h -r -s "%userprofile%\Favori~1\Web Detective.url"
del /q "%userprofile%\Favori~1\Online Gambling\*.*"
del /q "%userprofile%\Favori~1\online dating.url"
del /q "%userprofile%\Favori~1\Black Jack Online.url"
del /q "%userprofile%\Favori~1\Black Jack Online.url"
del /q "%userprofile%\Favori~1\Home Loan.url"
del /q "%userprofile%\Favori~1\Network Security.url"
del /q "%userprofile%\Favori~1\Online Dating.url"
del /q "%userprofile%\Favori~1\Online Gambling.url"
del /q "%userprofile%\Favori~1\Online Pharmacy\*.*"
del /q "%userprofile%\Favori~1\Online Pharmacy.url"
del /q "%userprofile%\Favori~1\Remove Spyware.url"
del /q "%userprofile%\Favori~1\Spam Filters.url"
del /q "%userprofile%\Favori~1\Take It Here - Free * TGP.url"
del /q "%userprofile%\Favori~1\Web Detective.url"
rmdir /q /s "%userprofile%\Favori~1\Online Gambling"
rmdir /q /s "%userprofile%\Favori~1\Online Pharmacy"
rmdir /q /s "%userprofile%\Favori~1\Online Gambling"
rmdir /q /s "%userprofile%\Favori~1\Online Pharmacy"
attrib -h -r -s "%systemdrive%\Archivos de programa\P.S.Guard\*.*"
del /q "%systemdrive%\Archivos de programa\P.S.Guard\*.*"
rmdir /q /s "%systemdrive%\Archivos de programa\P.S.Guard"
attrib -h -r -s "%systemdrive%\progra~1\P.S.Guard\*.*"
del /q "%systemdrive%\progra~1\P.S.Guard\*.*"
rmdir /q /s "%systemdrive%\progra~1\P.S.Guard"
attrib -h -r -s "%systemdrive%\Archivos de programa\Security IGuard\*.*"
attrib -h -r -s "%systemdrive%\Archivos de programa\Virtual Maid\*.*"
attrib -h -r -s "%systemdrive%\Archivos de programa\Search Maid\*.*"
attrib -h -r -s "%systemdrive%\Archivos de programa\AntiVirusGold\*.*"
attrib -h -r -s "%systemdrive%\Archivos de programa\PSGuard\*.*"
attrib -h -r -s "%systemdrive%\Archivos de programa\SpySheriff\*.*"
del /q "%systemdrive%\Archivos de programa\Security IGuard\*.*"
del /q "%systemdrive%\Archivos de programa\Virtual Maid\*.*"
del /q "%systemdrive%\Archivos de programa\Search Maid\*.*"
del /q "%systemdrive%\Archivos de programa\AntiVirusGold\*.*"
del /q "%systemdrive%\Archivos de programa\PSGuard\*.*"
del /q "%systemdrive%\Archivos de programa\SpySheriff\*.*"
rmdir /q /s "%systemdrive%\Archivos de programa\Security IGuard"
rmdir /q /s "%systemdrive%\Archivos de programa\Virtual Maid"
rmdir /q /s "%systemdrive%\Archivos de programa\Search Maid"
rmdir /q /s "%systemdrive%\Archivos de programa\AntiVirusGold"
rmdir /q /s "%systemdrive%\Archivos de programa\PSGuard"
rmdir /q /s "%systemdrive%\Archivos de programa\SpySheriff"
attrib -h -r -s "%allusersprofile%\Bureaublad\Spyware Removal.url"
attrib -h -r -s "%allusersprofile%\Bureaublad\Online Dating.url"
attrib -h -r -s "%allusersprofile%\Bureaublad\Online Pharmacy.url"
del /q "%allusersprofile%\Bureaublad\Spyware Removal.url"
del /q "%allusersprofile%\Bureaublad\Online Dating.url"
del /q "%allusersprofile%\Bureaublad\Online Pharmacy.url"
attrib -h -r -s "%allusersprofile%\Desktop\Spyware Removal.url"
attrib -h -r -s "%allusersprofile%\Desktop\Online Dating.url"
attrib -h -r -s "%allusersprofile%\Desktop\Online Pharmacy.url"
del /q "%allusersprofile%\Desktop\Spyware Removal.url"
del /q "%allusersprofile%\Desktop\Online Dating.url"
del /q "%allusersprofile%\Desktop\Online Pharmacy.url"
attrib -h -r -s "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSGuard spyware remover.lnk"
del /q "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSGuard spyware remover.lnk"
attrib -h -r -s "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSGuard.lnk"
del /q "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSGuard.lnk"
attrib -h -r -s "%userprofile%\Menu Start\Programma's\SpySheriff\*.*"
del /q "%userprofile%\Menu Start\Programma's\SpySheriff\*.*"
rmdir /q /s "%userprofile%\Menu Start\Programma's\SpySheriff"
attrib -h -r -s "%UserProfile%\Bureaublad\SpySheriff.lnk"
del /q "%UserProfile%\Bureaublad\SpySheriff.lnk"
attrib -h -r -s "%AllUsersProfile%\Bureaublad\PSGuard.lnk"
del /q "%AllUsersProfile%\Bureaublad\PSGuard.lnk"
attrib -h -r -s "%userprofile%\Application Data\PSGuard.com\*.*"
del /q "%userprofile%\Application Data\PSGuard.com\*.*"
rmdir /q /s "%userprofile%\Application Data\PSGuard.com"
attrib -h -r -s "%userprofile%\Start Menu\Programs\SpySheriff\*.*"
del /q /s "%userprofile%\Start Menu\Programs\SpySheriff\*.*"
rmdir /q /s "%userprofile%\Start Menu\Programs\SpySheriff"
attrib -h -r -s "%userprofile%\Application Data\Install.dat"
del /q "%userprofile%\Application Data\Install.dat"
attrib -h -r -s "%UserProfile%\Desktop\SpySheriff.lnk"
del /q "%UserProfile%\Desktop\SpySheriff.lnk"
attrib -h -r -s "%AllUsersProfile%\Desktop\PSGuard.lnk"
del /q ""%AllUsersProfile%\Desktop\PSGuard.lnk"
attrib -h -r -s "%systemdrive%\progra~1\Security IGuard\*.*"
attrib -h -r -s "%systemdrive%\progra~1\Virtual Maid\*.*"
attrib -h -r -s "%systemdrive%\progra~1\Search Maid\*.*"
attrib -h -r -s "%systemdrive%\progra~1\AntiVirusGold\*.*"
attrib -h -r -s "%systemdrive%\progra~1\PSGuard\*.*"
attrib -h -r -s "%systemdrive%\progra~1\SpySheriff\*.*"
del /q "%systemdrive%\progra~1\Security IGuard\*.*"
del /q "%systemdrive%\progra~1\Virtual Maid\*.*"
del /q "%systemdrive%\progra~1\Search Maid\*.*"
del /q "%systemdrive%\progra~1\AntiVirusGold\*.*"
del /q "%systemdrive%\progra~1\PSGuard\*.*"
del /q "%systemdrive%\progra~1\SpySheriff\*.*"
rmdir /q /s "%systemdrive%\progra~1\Security IGuard"
rmdir /q /s "%systemdrive%\progra~1\Virtual Maid"
rmdir /q /s "%systemdrive%\progra~1\Search Maid"
rmdir /q /s "%systemdrive%\progra~1\AntiVirusGold"
rmdir /q /s "%systemdrive%\progra~1\PSGuard"
rmdir /q /s "%systemdrive%\progra~1\SpySheriff"
attrib -h -r -s %temp%\*.*
del /q %temp%\*.*
rmdir /q /s %temp%
mkdir %temp%
cls
@echo off
cd %systemroot%\system32
cls
@echo off
attrib -r -h -s wbeconm.dll
del /q wbeconm.dll
attrib -r -h -s "_plastilin_"
attrib -r -h -s "atmtd.dll"
attrib -r -h -s "atmtd.dll._"
attrib -r -h -s "Defpia32.dll"
attrib -r -h -s "fhpd.dll"
attrib -r -h -s "Kdfdlh32.dll"
attrib -r -h -s "klja.dll"
attrib -r -h -s "ll.exe"
attrib -r -h -s "Mhpcja32.dll"
attrib -r -h -s "Nbfgemln.exe"
attrib -r -h -s "ongi.dll"
attrib -r -h -s "perflibs__"
attrib -r -h -s "svcp.csv"
attrib -r -h -s "sywsvcs.exe"
attrib -r -h -s "windesktop.dll"
attrib -r -h -s "windesktop.exe"
attrib -r -h -s "wins32.dll"
attrib -r -h -s "winselect.exe"
attrib -r -h -s "winsub.xml"
attrib -r -h -s "zlbw.dll"
del /q "_plastilin_"
del /q "atmtd.dll"
del /q "atmtd.dll._"
del /q "Defpia32.dll"
del /q "fhpd.dll"
del /q "Kdfdlh32.dll"
del /q "klja.dll"
del /q "ll.exe"
del /q "Mhpcja32.dll"
del /q "Nbfgemln.exe"
del /q "ongi.dll"
del /q "perflibs__"
del /q "svcp.csv"
del /q "sywsvcs.exe"
del /q "windesktop.dll"
del /q "windesktop.exe"
del /q "wins32.dll"
del /q "winselect.exe"
del /q "winsub.xml"
del /q "zlbw.dll"
attrib -r -h -s ioctrl.dll
del /q ioctrl.dll
attrib -r -h -s svchosts.dll
del /q svchosts.dll
attrib -r -h -s oleext32.dll
del /q oleext32.dll
attrib -r -h -s ff.tmp
del /q ff.tmp
attrib -h -r -s 1024\*.*
del /q 1024\*.*
del /q 1024\*.*
rmdir /q /s 1024
attrib -r -h -s svchop.exe
attrib -r -h -s shdochop.dll
attrib -h -r -s ts.ico
attrib -h -r -s ot.ico
attrib -r -h -s ptainfo1.ico
attrib -r -h -s ptainfo2.ico
attrib -r -h -s zlbw.dll
attrib -r -h -s msvol.tlb
attrib -r -h -s ld****.tmp
attrib -r -h -s mssearchnet.exe
attrib -r -h -s ncompat.tlb
attrib -r -h -s nvctrl.exe
attrib -r -h -s mscornet.exe
attrib -r -h -s gunist.exe
attrib -r -h -s param32.dll
attrib -r -h -s pop_up.dll
attrib -r -h -s MP3.ico
attrib -r -h -s Pharmacy.ico
attrib -r -h -s viagra.ico
attrib -r -h -s "searchdll.dll"
attrib -r -h -s "Air Tickets.ico"
attrib -r -h -s "Big Tits.ico"
attrib -r -h -s "Blackjack.ico"
attrib -r -h -s "Britney Spears.ico"
attrib -r -h -s "Car Insurance.ico"
attrib -r -h -s "Cheap Cigarettes.ico"
attrib -r -h -s "Credit Card.ico"
attrib -r -h -s Cruises.ico
attrib -r -h -s "Currency Trading.ico"
attrib -r -h -s "Lesbian Sex.ico"
attrib -r -h -s "Online Betting.ico"
attrib -r -h -s "Online Gambling.ico"
attrib -r -h -s "Oral Sex.ico"
attrib -r -h -s "Party Poker.ico"
attrib -r -h -s "Phentermine.ico"
attrib -r -h -s "Pornstars.ico"
attrib -r -h -s "Remove Spyware.ico"
del /q svchop.exe
del /q shdochop.dll
del /q ts.ico
del /q ot.ico
del /q ptainfo1.ico
del /q ptainfo2.ico
del /q zlbw.dll
del /q msvol.tlb
del /q ld****.tmp
del /q mssearchnet.exe
del /q ncompat.tlb
del /q nvctrl.exe
del /q mscornet.exe
del /q gunist.exe
del /q param32.dll
del /q pop_up.dll
del /q MP3.ico
del /q Pharmacy.ico
del /q viagra.ico
del /q "searchdll.dll"
del /q "Air Tickets.ico"
del /q "Big Tits.ico"
del /q "Blackjack.ico"
del /q "Britney Spears.ico"
del /q "Car Insurance.ico"
del /q "Cheap Cigarettes.ico"
del /q "Credit Card.ico"
del /q Cruises.ico
del /q "Currency Trading.ico"
del /q "Lesbian Sex.ico"
del /q "Online Betting.ico"
del /q "Online Gambling.ico"
del /q "Oral Sex.ico"
del /q "Party Poker.ico"
del /q "Phentermine.ico"
del /q "Pornstars.ico"
del /q "Remove Spyware.ico"
attrib -h -r -s thn.dll
del /q thn.dll
attrib -h -r -s "__delete_on_reboot__intel32.exe"
del /q "__delete_on_reboot__intel32.exe"
attrib -h -r -s "__delete_on_reboot__OLEADM.dll"
del /q "__delete_on_reboot__OLEADM.dll"
attrib -h -r -s intell32.exe
del /q intell32.exe
attrib -h -r -s oleext.dll
del /q oleext.dll
attrib -h -r -s oleadm.dll
del /q oleadm.dll
attrib -h -r -s wppp.html
del /q wppp.html
attrib -h -r -s svcnt.exe
del /q svcnt.exe
attrib -h -r -s intel32.exe
del /q intel32.exe
attrib -h -r -s hhk.dll.tcf
del /q hhk.dll.tcf
attrib -h -r -s perfcii.ini
del /q perfcii.ini
attrib -h -r -s oleadm32.dll
del /q oleadm32.dll
attrib -h -r -s wp.bmp
del /q wp.bmp
attrib -h -r -s hookdump.exe
del /q hookdump.exe
attrib -h -r -s winnook.exe
del /q winnook.exe
attrib -h -r -s wldr.dll
del /q wldr.dll
attrib -h -r -s helper.exe
del /q helper.exe
attrib -h -r -s intmonp.exe
del /q intmonp.exe
attrib -h -r -s msmsgs.exe
del /q msmsgs.exe
attrib -h -r -s ole32vbs.exe
del /q ole32vbs.exe
attrib -h -r -s msole32.exe
del /q msole32.exe
attrib -h -r -s hp***.tmp
del /q hp***.tmp
attrib -h -r -s shnlog.exe
del /q shnlog.exe
attrib -h -r -s intmon.exe
del /q intmon.exe
attrib -h -r -s hhk.dll
del /q hhk.dll
attrib -h -r -s "__delete_on_reboot__intmon.exe"
del /q "__delete_on_reboot__intmon.exe"
attrib -h -r -s "Log Files\*.*"
attrib -h -r -s logfiles\*.*
del /q "Log Files\*.*"
del /q logfiles\*.*
rmdir /q /s "Log Files"
rmdir /q /s logfiles
cls
@echo off
cd %systemroot%
cls
@echo off
attrib -r -h %systemroot%\RGF2ZQ\*.*
del /q %systemroot%\RGF2ZQ\*.*
rmdir %systemroot%\RGF2ZQ
attrib -h -r -s warnhp.html
del /q warnhp.html
attrib -h -r -s wp.bmp
del /q wp.bmp
attrib -h -r -s uninstIU.exe
del /q uninstIU.exe
attrib -h -r -s zloader3.exe
del /q zloader3.exe
attrib -h -r -s desktop.html
del /q desktop.html
attrib -h -r -s screen.html
del /q screen.html
attrib -h -r -s sites.ini
del /q sites.ini
attrib -h -r -s popuper.exe
del /q popuper.exe
attrib -h -r -s prefetch\*.*
del /q prefetch\*.*
del /q /s prefetch
attrib -h -r -s temp\*.*
del /q temp\*.*
rmdir /q /s temp
mkdir temp
cls
@echo off
cd %systemroot%\system32\config\system~1\Local Settings
cls
@echo off
attrib -h -r -s temp\*.*
del /q temp\*.*
rmdir /q /s temp
mkdir temp
cls
@echo off
cd %systemroot%\system32\config\system~1\Local Settings\Tempor~1
cls
@echo off
attrib -h -r -s "Content.IE5\*.*"
del /q "Content.IE5\*.*"
rmdir /q /s "Content.IE5"
mkdir "Content.IE5"
cls
@echo off
cd \
cls
@echo off
IF EXIST \temp attrib -h -r -s \temp\*.*
IF EXIST \temp del /q temp\*.*
attrib -h -r -s bsw.exe
del /q bsw.exe
attrib -h -r -s wp.exe
del /q wp.exe
attrib -h -r -s wp.bmp
del /q wp.bmp
attrib -h -r -s bsw.bmp
del /q bsw.bmp
attrib -h -r -s winstall.exe
del /q winstall.exe
cd %systemroot%\system32
IF EXIST wininet.dll GOTO test
IF NOT EXIST wininet.dll GOTO missing
:missing
del /q %systemdrive%\delfiles.cmd
cls
@echo off
echo.>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo Remaining Post-run Files>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo ~~~ Program Files ~~~>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\Archivos de programa\Winhound" echo Winhound>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\progra~1\Winhound" echo Winhound>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\Archivos de programa\spyaxe" echo SpyAxe>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\progra~1\spyaxe" echo SpyAxe>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\Archivos de programa\SpyTrooper" echo SpyTrooper>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\Archivos de programa\Security Toolbar" echo Security Toolbar>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\progra~1\SpyTrooper" echo SpyTrooper>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\progra~1\Security Toolbar" echo Security Toolbar>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\Archivos de programa\P.S.Guard" echo P.S.Guard>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\Archivos de programa\Security IGuard" echo Security IGuard>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\Archivos de programa\Virtual Maid" echo Virtual Maid>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\Archivos de programa\Search Maid" echo Search Maid>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\Archivos de programa\AntiVirusGold" echo AntiVirusGold>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\Archivos de programa\PSGuard" echo PSGuard>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\Archivos de programa\SpySheriff" echo SpySheriff>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\progra~1\P.S.Guard" echo P.S.Guard>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\progra~1\Security IGuard" echo Security IGuard>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\progra~1\Virtual Maid" echo Virtual Maid>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\progra~1\Search Maid" echo Search Maid>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\progra~1\AntiVirusGold" echo AntiVirusGold>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\progra~1\PSGuard echo" PSGuard>>%systemdrive%\smitfiles.txt
IF EXIST "%systemdrive%\progra~1\SpySheriff" echo SpySheriff>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo ~~~ Shortcuts ~~~>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Desktop\WinHound spyware remover.lnk" echo WinHound spyware remover.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Bureaublad\WinHound spyware remover.lnk" echo WinHound spyware remover.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinHound spyware remover.lnk" echo quick launch WinHound spyware remover.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Start Menu\Programs\WinHound spyware remover" echo WinHound spyware remover folder>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Menu Start\Programs\WinHound spyware remover" echo WinHound spyware remover folder>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Desktop\Online Security Guide.url" echo Online Security Guide.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Start Menu\Online Security Guide.url" echo Online Security Guide.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Bureaublad\Online Security Guide.url" echo Online Security Guide.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Menu Start\Online Security Guide.url" echo Online Security Guide.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Desktop\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Desktop\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Start Menu\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Desktop\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Desktop\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Bureaublad\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Bureaublad\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Menu Start\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Security Troubleshooting.url" echo Security Troubleshooting.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\SpyTrooper.lnk" echo SpyTrooper.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\SpyTrooper.lnk" echo SpyTrooper.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Menu Start\Programma's\SpyTrooper" echo SpyTrooper folder>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Start Menu\Programs\SpyTrooper" echo SpyTrooper folder>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Favori~1\Cheap Viagra.url" echo Cheap Viagra.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Favori~1\Buy Viagra Online.url" echo Buy Viagra Online.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Start Menu\Anti SPAM.url" echo Anti SPAM.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Start Menu\Online Casino.url" echo Online Casino.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Start Menu\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Start Menu\Computer Security.url" echo Computer Security.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Desktop\Security Troubleshooting.lnk" echo Security Troubleshooting.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Desktop\Online Security Center.lnk" echo Online Security Center.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\favorieten\Cheap Viagra.url" echo Cheap Viagra.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\favorieten\Buy Viagra Online.url" echo Buy Viagra Online.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Menu Start\Anti SPAM.url" echo Anti SPAM.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Menu Start\Online Casino.url" echo Online Casino.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Menu Start\Online Security Center.url" echo Online Security Center.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Menu Start\Computer Security.url" echo Computer Security.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Bureaublad\Security Troubleshooting.lnk" echo Security Troubleshooting.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Bureaublad\Online Security Center.lnk" echo Online Security Center.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Air Tickets.url" echo Air Tickets.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Big Tits.url" echo Big Tits.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Blackjack.url" echo Blackjack.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Britney Spears.url" echo Britney Spears.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Car Insurance.url" echo Car Insurance.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Cheap Cigarettes.url" echo Cheap Cigarettes.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Credit Card.url" echo Credit Card.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Cruises.url" echo Cruises.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Currency Trading.url" echo Currency Trading.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Lesbian Sex.url" echo Lesbian Sex.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\MP3.url" echo MP3.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Online Betting.url" echo Online Betting.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Online Gambling.url" echo Online Gambling.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Oral Sex.url" echo Oral Sex.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Party Poker.url" echo Party Poker.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Pharmacy.url" echo Pharmacy.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Phentermine.url" echo Phentermine.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Pornstars.url" echo job Pornstars.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\Remove Spyware.url" echo Remove Spyware.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Bureaublad\viagra.url" echo viagra.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Air Tickets.url" echo Air Tickets.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Big Tits.url" echo Big Tits.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Blackjack.url" echo Blackjack.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Britney Spears.url" echo Britney Spears.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Car Insurance.url" echo Car Insurance.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Cheap Cigarettes.url" echo Cheap Cigarettes.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Credit Card.url" echo Credit Card.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Cruises.url" echo Cruises.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Currency Trading.url" echo Currency Trading.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Lesbian Sex.url" echo Lesbian Sex.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\MP3.url" echo MP3.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Online Betting.url" echo Online Betting.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Online Gambling.url" echo Online Gambling.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Oral Sex.url" echo Oral Sex.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Party Poker.url" echo Party Poker.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Pharmacy.url" echo Pharmacy.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Phentermine.url" echo Phentermine.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Pornstars.url" echo job Pornstars.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\Remove Spyware.url" echo Remove Spyware.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\viagra.url" echo viagra.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Start Menu\Programs\PSGuard spyware remover" echo PSGuard spyware remover>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Menu Start\Programma's\PSGuard spyware remover" echo PSGuard spyware remover>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Bureaublad\AntivirusGold.lnk" echo AntivirusGold.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\AntivirusGold.lnk" echo AntivirusGold.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Bureaublad\PSGuard spyware remover.lnk" echo PSGuard spyware remover.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Desktop\PSGuard spyware remover.lnk" echo PSGuard spyware remover.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Bureaublad\Spyware Removal.url" echo Spyware Removal.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Bureaublad\Online Dating.url" echo Online Dating.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Bureaublad\Online Pharmacy.url" echo Online Pharmacy.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Desktop\Spyware Removal.url" echo Spyware Removal.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Desktop\Online Dating.url" echo Online Dating.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Desktop\Online Pharmacy.url" echo Online Pharmacy.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSGuard spyware remover.lnk" echo quick launch PSGuard spyware remover.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\PSGuard.lnk" echo quick launch PSGuard.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Menu Start\Programma's\SpySheriff" echo SpySheriff>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Bureaublad\SpySheriff.lnk" echo SpySheriff.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Bureaublad\PSGuard.lnk" echo PSGuard.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Application Data\PSGuard.com" echo PSGuard.com>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Start Menu\Programs\SpySheriff" echo SpySheriff>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Application Data\Install.dat" echo Install.dat>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Desktop\SpySheriff.lnk" echo SpySheriff.lnk>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Desktop\PSGuard.lnk" echo PSGuard.lnk>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo ~~~ Favorites ~~~>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Take It Here - Daily Updated Porn Links.url" echo Take It Here - Daily Updated Porn Links.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Take It Here - Daily Updated Porn Links.url" echo Take It Here - Daily Updated Porn Links.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Favori~1\Free XXX Sites List.url" echo Free XXX Sites List.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Favori~1\Antivirus Test Online.url" echo Antivirus Test Online.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Favori~1\Cheap Viagra.url" echo Cheap Viagra.url>>%systemdrive%\smitfiles.txt
IF EXIST "%AllUsersProfile%\Favori~1\Buy Viagra Online.url" echo Buy Viagra Online.url>>%systemdrive%\smitfiles.txt
IF EXIST "%UserProfile%\Favori~1\Need Money.url" echo Need Money.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\adult" echo adult>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\cars" echo cars>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\sexual life" echo sexual life>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\shopping" echo shopping>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\anti spam.url" echo anti spam.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\job search.url" echo job search.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\poker.url" echo poker.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\spyware removal.url" echo spyware removal.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Online Gambling.url" echo Online Gambling.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\online dating.url" echo online dating.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Black Jack Online.url" echo Black Jack Online.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Online Pharmacy\Adipex.url" echo Online Pharmacy\Adipex.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Black Jack Online.url" echo Black Jack Online.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Home Loan.url" echo Home Loan.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Network Security.url" echo Network Security.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Online Dating.url" echo Online Dating.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Adipex.url" echo Adipex.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Alprazolam.url" echo Alprazolam.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Carisoprodol.url" echo Carisoprodol.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Diazepam.url" echo Diazepam.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Hydrocodone.url" echo Hydrocodone.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Lortab.url" echo Lortab.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Online Pharmacy.url" echo Online Pharmacy.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Prozac.url" echo Prozac.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Valium.url" echo Valium.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Vicodin.url" echo Vicodin.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Xanax.url" echo Xanax.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Remove Spyware.url" echo Remove Spyware.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Spam Filters.url" echo Spam Filters.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Take It Here - Free * TGP.url" echo Take It Here - Free * TGP.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Web Detective.url" echo Web Detective.url>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Online Gambling" echo Online Gambling folder>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\Favori~1\Online Pharmacy" echo Online Pharmacy folder>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo ~~~ system32 folder ~~~>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\wbeconm.dll" echo wbeconm.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\_plastilin_" echo _plastilin_>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\atmtd.dll" echo atmtd.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\atmtd.dll._" echo atmtd.dll._>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Defpia32.dll" echo Defpia32.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\fhpd.dll" echo fhpd.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Kdfdlh32.dll" echo Kdfdlh32.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\klja.dll" echo klja.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\ll.exe" echo ll.exe>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Mhpcja32.dll" echo Mhpcja32.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Nbfgemln.exe" echo Nbfgemln.exe>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\ongi.dll" echo ongi.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\perflibs__" echo perflibs__>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\svcp.csv" echo svcp.csv>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\sywsvcs.exe" echo sywsvcs.exe>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\windesktop.dll" echo windesktop.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\windesktop.exe" echo windesktop.exe>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\wins32.dll" echo wins32.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\winselect.exe" echo winselect.exe>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\winsub.xml" echo winsub.xml>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\zlbw.dll" echo zlbw.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\ioctrl.dll" echo ioctrl.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\svchosts.dll" echo svchosts.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\ff.tmp" echo ff.tmp>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\oleext32.dll" echo oleext32.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\1024" echo 1024 dir>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\svchop.exe" echo svchop.exe>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\shdochop.dll" echo shdochop.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\zlbw.dll" echo zlbw.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\msvol.tlb" echo msvol.tlb>>%systemdrive%\smitfiles.txt
IF EXIST "%systemroot%\system32\ld****.tmp" echo ld****.tmp>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\mssearchnet.exe" echo mssearchnet.exe>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\ncompat.tlb" echo ncompat.tlb>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\nvctrl.exe" echo nvctrl.exe>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\mscornet.exe" echo mscornet.exe>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\gunist.exe" echo gunist.exe>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\param32.dll" echo param32.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\pop_up.dll" echo pop_up.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\searchdll.dll" echo searchdll.dll>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\thn.dll echo thn.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%systemroot%\system32\__delete_on_reboot__intel32.exe" echo __delete_on_reboot__intel32.exe>>%systemdrive%\smitfiles.txt
IF EXIST "%systemroot%\system32\__delete_on_reboot__OLEADM.dll" echo __delete_on_reboot__OLEADM.dll>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\intell32.exe echo intell32.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\oleext.dll echo oleext.dll>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\wppp.html echo wppp.html>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\svcnt.exe echo svcnt.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\oleadm.dll echo oleadm.dll>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\intel32.exe echo intel32.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\hhk.dll.tcf echo hhk.dll.tcf>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\perfcii.ini echo perfcii.ini>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\oleadm32.dll echo oleadm32.dll>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\wp.bmp echo wp.bmp>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\hookdump.exe echo hookdump.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\winnook.exe echo winnook.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\wldr.dll echo wldr.dll>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\helper.exe echo helper.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\intmonp.exe echo intmonp.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\msmsgs.exe echo msmsgs.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\ole32vbs.exe echo ole32vbs.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\msole32.exe echo msole32.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\hp***.tmp echo hp***.tmp>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\shnlog.exe echo shnlog.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\intmon.exe echo intmon.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\hhk.dll echo hhk.dll>>%systemdrive%\smitfiles.txt
IF EXIST "%systemroot%\system32\__delete_on_reboot__intmon.exe" echo __delete_on_reboot__intmon.exe>>%systemdrive%\smitfiles.txt
IF EXIST "%systemroot%\system32\Log Files" echo Log Files>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\system32\logfiles echo logfiles>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo ~~~ Icons in System32 ~~~>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\ts.ico" echo ts.ico>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\ot.ico" echo ot.ico>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\ptainfo1.ico" echo ptainfo1>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\ptainfo2.ico" echo ptainfo2>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Air Tickets.ico" echo Air Tickets>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Big Tits.ico" echo Big Tits>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Blackjack.ico" echo Blackjack>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Britney Spears.ico" echo Britney Spears>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Car Insurance.ico" echo Car Insurance>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Cheap Cigarettes.ico" echo Cheap Cigarettes>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Credit Card.ico" echo Credit Card>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Cruises.ico" echo Cruises>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Currency Trading.ico" echo Currency Trading>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Lesbian Sex.ico" echo Lesbian Sex>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\MP3.ico" echo MP3>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Online Betting.ico" echo Online Betting>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Online Gambling.ico" echo Online Gambling>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Oral Sex.ico" echo Oral Sex>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Party Poker.ico" echo Party Poker>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Pharmacy.ico" echo Pharmacy>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Phentermine.ico" echo Phentermine>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Pornstars.ico" echo Pornstars>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\Remove Spyware.ico" echo Remove Spyware>>%systemdrive%\smitfiles.txt
IF EXIST "%Systemroot%\system32\viagra.ico" echo viagra>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo ~~~ Windows directory ~~~>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\RGF2ZQ echo RGF2ZQ folder>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\warnhp.html echo warnhp.html>>%systemdrive%\smitfiles.txt
IF EXIST "%systemroot%\Application Data\Shudder Global Limited" echo Application Data\Shudder Global Limited>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\wp.bmp echo wp.bmp>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\uninstIU.exe echo uninstIU.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\zloader3.exe echo zloader3.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\desktop.html echo desktop.html>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\screen.html echo screen.html>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\sites.ini echo sites.ini>>%systemdrive%\smitfiles.txt
IF EXIST %systemroot%\popuper.exe echo popuper.exe>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo ~~~ Drive root ~~~>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF EXIST %systemdrive%\bsw.exe echo bsw.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemdrive%\wp.exe echo wp.exe>>%systemdrive%\smitfiles.txt
IF EXIST %systemdrive%\wp.bmp echo wp.bmp>>%systemdrive%\smitfiles.txt
IF EXIST %systemdrive%\bsw.bmp echo bsw.bmp>>%systemdrive%\smitfiles.txt
IF EXIST %systemdrive%\winstall.exe echo winstall.exe>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo ~~~ Miscellaneous Files/folders ~~~>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF EXIST "%userprofile%\application data\shudder global limited" echo shudder global limited>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
IF EXIST %systemdrive%\winstall.exe echo winstall.exe>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo ~~~ Wininet.dll ~~~>>%systemdrive%\smitfiles.txt
echo.>>%systemdrive%\smitfiles.txt
echo wininet.dll is missing!!>>%systemdrive%\smitfiles.txt
GOTO finish
:test
cls
Eli mitä teen väärin?
|
AfterDawn Addict
|
30. joulukuuta 2005 @ 07:20 |
Linkki tähän viestiin
|
Sun koneessa F8 tuo esiin boot menun eikä sitä valikkoa. Tee näin:
* Sulje kaikki ohjelmat.
* Klikkaa käynnistä -> suorita -> msconfig ja OK
* Valitse BOOT.INI-välilehti, merkkaa "/SAFEBOOT"-valinta, ja sitten klikkaa OK ja käynnistä kone uudelleen sitä pyydettäessä
* Tietokone käynnistyy vikasietotilaan
* Tee vikasietotilassa pyydetyt toimenpiteet(eli aja se RunThis.bat smitrem-kansiosta ohjeiden mukaan).
* Kun olet valmis, mene uudelleen msconfigiin kuten edellä ja ota valinta pois BOOT.INI-välilehdeltä "/SAFEBOOT"-kohdasta ja paina OK, jolloin koneesi käynnistyy normaalisti.
EDIT: Ja editoi toi edellinen viesti vähän pienemmäks :)
Lähetä uusi HjT-loki ja c:\smitfiles.txt-tiedoston sisältö
Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 30. joulukuuta 2005 @ 07:22
|
despvi
Newbie
|
30. joulukuuta 2005 @ 08:17 |
Linkki tähän viestiin
|
Nyt alkaa näyttää valoisammalta!
hjt-loki tässä:
Logfile of HijackThis v1.99.1
Scan saved at 13:09:35, on 30.12.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Norman\Nvc\BIN\NPFSVICE.EXE
C:\Norman\bin\ZANDA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Norman\Nvc\BIN\NVCSCHED.EXE
C:\Norman\Nvc\BIN\nipsvc.exe
C:\Norman\bin\NJEEVES.EXE
C:\Norman\Nvc\bin\nvcoas.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Norman\bin\ZLH.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Norman\Nvc\BIN\NIP.EXE
C:\Norman\Nvc\bin\cclaw.exe
C:\Norman\Npf\BIN\npfmsg2.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\wuauclt.exe
C:\hjt\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.utu.fi/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.utu.fi/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cl... O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Filter: text/html - (no CLSID) - (no file)
O18 - Filter: text/plain - (no CLSID) - (no file)
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE
O23 - Service: Norman Type-R - Unknown owner - C:\Norman\Nvc\BIN\NPFSVICE.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\bin\ZANDA.EXE
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
ja smitfiles.txt tässä:
smitRem © log file
version 2.8
by noahdfear
Microsoft Windows XP [versio 5.1.2600]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
checking for ShudderLTD key
ShudderLTD key not present!
checking for PSGuard.com key
PSGuard.com key not present!
checking for WinHound.com key
WinHound.com key not present!
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
SpyAxeFix © by noahdfear
spyaxe directory present
spyaxe uninstaller present
Starting spyaxe uninstaller
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F}"="Security Update"
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Winhound uninstaller NOT present
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Existing Pre-run Files
~~~ Program Files ~~~
SpyAxe
~~~ Shortcuts ~~~
~~~ Favorites ~~~
~~~ system32 folder ~~~
wbeconm.dll
1024 dir
msvol.tlb
ld****.tmp
mssearchnet.exe
ncompat.tlb
nvctrl.exe
hp***.tmp
~~~ Icons in System32 ~~~
ts.ico
ot.ico
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 728 'explorer.exe'
Starting registry repairs
Deleting files
Remaining Post-run Files
~~~ Program Files ~~~
SpyAxe
~~~ Shortcuts ~~~
~~~ Favorites ~~~
~~~ system32 folder ~~~
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~ Wininet.dll ~~~
CLEAN! :)
Uskaltaako tässä nyt jo riemuita (ja nöyrimmästi kiittää auttajaansa)?
|
AfterDawn Addict
|
30. joulukuuta 2005 @ 08:22 |
Linkki tähän viestiin
|
Aika hyvä :)
Poista tämä hakemisto, jos on.
C:\Program Files\==>SpyAxe<==
Ja fixaa nämä rivit HjT:llä:
O18 - Filter: text/html - (no CLSID) - (no file)
O18 - Filter: text/plain - (no CLSID) - (no file)
Muuten on kunnossa.
|
despvi
Newbie
|
30. joulukuuta 2005 @ 08:52 |
Linkki tähän viestiin
|
Kyseiset rivit fixattu, SpyAxe-hakemistoja ei löytynyt, kaikki kunnossa!
Tuhannesti kiitoksia avusta!
|
despvi
Newbie
|
30. joulukuuta 2005 @ 12:40 |
Linkki tähän viestiin
|
Onhan tämä nyt sitten varmasti puhdas? Aloin epäillä, kun Normanin tarkistus kertoi löytäneensä (ja siirtäneensä karanteeniin) tiedostoja, joissa oli troijalainen nimeltään W32/Zlob.GC
Logfile of HijackThis v1.99.1
Scan saved at 17:35:00, on 30.12.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Norman\Nvc\BIN\NPFSVICE.EXE
C:\Norman\bin\ZANDA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Norman\bin\NJEEVES.EXE
C:\Norman\Nvc\BIN\nipsvc.exe
C:\Norman\Nvc\BIN\NVCSCHED.EXE
C:\Norman\Nvc\bin\nvcoas.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Norman\bin\ZLH.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Norman\Nvc\bin\cclaw.exe
C:\Norman\Nvc\BIN\NIP.EXE
C:\Norman\Npf\BIN\npfmsg2.exe
C:\WINDOWS\system32\wuauclt.exe
C:\hjt\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.utu.fi/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.utu.fi/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cl... O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Filter: text/html - (no CLSID) - (no file)
O18 - Filter: text/plain - (no CLSID) - (no file)
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE
O23 - Service: Norman Type-R - Unknown owner - C:\Norman\Nvc\BIN\NPFSVICE.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\bin\ZANDA.EXE
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
|
Mainos
|
|
|
AfterDawn Addict
|
30. joulukuuta 2005 @ 13:49 |
Linkki tähän viestiin
|
Tyhjennä se Normanin karanteeni vikasietotilassa. Norman on "säilönyt" noita spyaxen pöpöjä sinne. Ja fixaa nämä (vikasietotilassa, jos eivät muuten lähde):
O18 - Filter: text/html - (no CLSID) - (no file)
O18 - Filter: text/plain - (no CLSID) - (no file)
|
|