Saturday, November 22, 2008

Smitfraud.c Trojan

Removing Smitfraud.c
Categories: Trojan
This loose category includes a variety of Trojans that damage victim machines or
threaten data integrity, or impair the functioning of the victim machine.

Multi-purpose Trojans are also included in this group, as some virus writers
create multi-functional Trojans rather than Trojan packs.

Visible Symptoms:
Files in system folders:
[%COMMON_DESKTOPDIRECTORY%]\Online Security Center.url
[%COMMON_DESKTOPDIRECTORY%]\Online Security Guide.url
[%COMMON_DESKTOPDIRECTORY%]\Security Troubleshooting.url
[%COMMON_FAVORITES%]\Antivirus Test Online.url
[%COMMON_FAVORITES%]\Buy Viagra Online.url
[%COMMON_FAVORITES%]\Cheap Viagra.url
[%COMMON_STARTMENU%]\Anti SPAM.url
[%COMMON_STARTMENU%]\Computer Security.url
[%COMMON_STARTMENU%]\Online Security Center.url
[%COMMON_STARTMENU%]\Online Security Guide.url
[%COMMON_STARTMENU%]\Security Troubleshooting.url
[%DESKTOP%]\Blackjack.url
[%DESKTOP%]\REMOVE SPYWARE.url
[%DESKTOP%]\remove.exe
[%DESKTOP%]\SpySheriff.lnk
[%DESKTOP%]\Trust Cleaner.lnk
[%DESKTOP%]\VIDEO.EXE
[%FAVORITES%]\Alprazolam.url
[%FAVORITES%]\Antivirus Test Online.url
[%FAVORITES%]\Free XXX Sites List.url
[%FAVORITES%]\Job Search.url
[%FAVORITES%]\Network Security.url
[%FAVORITES%]\online dating.url
[%FAVORITES%]\Online Gambling.url
[%FAVORITES%]\Online Pharmacy.url
[%FAVORITES%]\Remove Spyware.url
[%FAVORITES%]\Spam Filters.url
[%FAVORITES%]\Take It Here - Daily Updated Porn Links.url
[%FAVORITES%]\Web Detective.url
[%PROFILE%]\cmd.exe
[%PROFILE%]\start
[%PROGRAM_FILES%]\AlfaCleaner\digsign.db
[%PROGRAM_FILES%]\Security Toolbar\Security Toolbar.dll
[%PROGRAM_FILES%]\Security Toolbar\Uninstall.bat
[%PROGRAM_FILES%]\SpySheriff\base.avd
[%PROGRAM_FILES%]\SpySheriff\base001.avd
[%PROGRAM_FILES%]\SpySheriff\base002.avd
[%PROGRAM_FILES%]\SpySheriff\found.wav
[%PROGRAM_FILES%]\SpySheriff\heur000.dll
[%PROGRAM_FILES%]\SpySheriff\heur001.dll
[%PROGRAM_FILES%]\SpySheriff\heur002.dll
[%PROGRAM_FILES%]\SpySheriff\heur003.dll
[%PROGRAM_FILES%]\SpySheriff\notfound.wav
[%PROGRAM_FILES%]\SpySheriff\removed.wav
[%PROGRAM_FILES%]\SpySheriff\SpySheriff.dvm
[%PROGRAM_FILES%]\SpySheriff\SpySheriff.exe
[%PROGRAM_FILES%]\SpySheriff\Uninstall.exe
[%PROGRAM_FILES%]\SpyTrooper\Uninstall.exe
[%PROGRAM_FILES%]\SpywareQuake\blacklist.txt
[%PROGRAM_FILES%]\SpywareQuake\msvcp71.dll
[%PROGRAM_FILES%]\SpywareQuake\msvcr71.dll
[%PROGRAM_FILES%]\SpywareQuake\ref.dat
[%PROGRAM_FILES%]\SpywareQuake\SpywareQuake.exe
[%PROGRAM_FILES%]\SpywareQuake\SpywareQuake.url
[%PROGRAM_FILES%]\SpywareQuake\uninst.exe
[%PROGRAM_FILES%]\SpywareStrike\SpywareStrike.exe
[%PROGRAM_FILES%]\SpywareStrike\spywarestrike.ini
[%STARTMENU%]\SpywareStrike 2.5.lnk
[%SYSTEM%]\a.exe
[%SYSTEM%]\adobepnl.dll
[%SYSTEM%]\alxres.dll
[%SYSTEM%]\appmagr.dll
[%SYSTEM%]\atmclk.exe
[%SYSTEM%]\atmtd.dll
[%SYSTEM%]\atmtd.dll._
[%SYSTEM%]\bridge.dll
[%SYSTEM%]\CWS_iestart.exe
[%SYSTEM%]\dailytoolbar.dll
[%SYSTEM%]\dcomcfg.exe
[%SYSTEM%]\dfrgsrv.exe
[%SYSTEM%]\dxmpp.dll
[%SYSTEM%]\dxole32.exe
[%SYSTEM%]\hvnwm.dll
[%SYSTEM%]\intel32.exe
[%SYSTEM%]\intell32.exe
[%SYSTEM%]\ishost.exe
[%SYSTEM%]\ismon.exe
[%SYSTEM%]\isnotify.exe
[%SYSTEM%]\issearch.exe
[%SYSTEM%]\ixt0.dll
[%SYSTEM%]\ixt1.dll
[%SYSTEM%]\ixt2.dll
[%SYSTEM%]\ixt3.dll
[%SYSTEM%]\ixt4.dll
[%SYSTEM%]\ixt5.dll
[%SYSTEM%]\ixt6.dll
[%SYSTEM%]\ixt7.dll
[%SYSTEM%]\ixt8.dll
[%SYSTEM%]\ixt9.dll
[%SYSTEM%]\jao.dll
[%SYSTEM%]\kernels32.exe
[%SYSTEM%]\kernels8.exe
[%SYSTEM%]\lcch.dat
[%SYSTEM%]\mirarsearch_toolbar.exe
[%SYSTEM%]\mscornet.exe
[%SYSTEM%]\msmsgs.exe
[%SYSTEM%]\msole32.exe
[%SYSTEM%]\mswinb32.dll
[%SYSTEM%]\mswinb32.exe
[%SYSTEM%]\mswinup32.dll
[%SYSTEM%]\notepad.exe
[%SYSTEM%]\nvctrl.exe
[%SYSTEM%]\oleadm.dll
[%SYSTEM%]\oleext.dll
[%SYSTEM%]\oleext32.dll
[%SYSTEM%]\page.htm
[%SYSTEM%]\perflibs__
[%SYSTEM%]\phqghume.exe
[%SYSTEM%]\qjrkvy.exe
[%SYSTEM%]\questmod.dll
[%SYSTEM%]\reger.exe
[%SYSTEM%]\regperf.exe
[%SYSTEM%]\repigsp.exe
[%SYSTEM%]\runsrv32.dll
[%SYSTEM%]\runsrv32.exe
[%SYSTEM%]\shell386.exe
[%SYSTEM%]\shellgui32.dll
[%SYSTEM%]\SUSP.exe
[%SYSTEM%]\svehost.exe
[%SYSTEM%]\sywsvcs.exe
[%SYSTEM%]\taskdir.dll
[%SYSTEM%]\taskdir.exe
[%SYSTEM%]\taskdir~.exe
[%SYSTEM%]\tcpservice2.exe
[%SYSTEM%]\thlwin32.dll
[%SYSTEM%]\txfdb32.dll
[%SYSTEM%]\udpmod.dll
[%SYSTEM%]\users32.exe
[%SYSTEM%]\voblaizdupla.exe
[%SYSTEM%]\winapi32.dll
[%SYSTEM%]\winbl32.dll
[%SYSTEM%]\winflash.dll
[%SYSTEM%]\winlfl32.dll
[%SYSTEM%]\winlogon.exe
[%SYSTEM%]\winsrv32.exe
[%SYSTEM%]\wldr.dll
[%SYSTEM%]\wp.bmp
[%SYSTEM%]\wppp.html
[%SYSTEM%]\wstart.dll
[%SYSTEM%]\yephk.dll
[%SYSTEM%]\yephk.dll
[%SYSTEM%]\zlbw.dll
[%WINDOWS%]\alexaie.dll
[%WINDOWS%]\alxie328.dll
[%WINDOWS%]\alxtb1.dll
[%WINDOWS%]\BTGrab.dll
[%WINDOWS%]\desktop.html
[%WINDOWS%]\dlmax.dll
[%WINDOWS%]\inetloader.dll
[%WINDOWS%]\Pynix.dll
[%WINDOWS%]\screen.html
[%WINDOWS%]\secure32.html
[%WINDOWS%]\sites.ini
[%WINDOWS%]\susp.exe
[%WINDOWS%]\svchosts.dll
[%WINDOWS%]\tool1.exe
[%WINDOWS%]\tool2.exe
[%WINDOWS%]\tool3.exe
[%WINDOWS%]\tool4.exe
[%WINDOWS%]\tool5.exe
[%WINDOWS%]\uninstDsk.exe
[%WINDOWS%]\uninstIU.exe
[%WINDOWS%]\web\desktop.html
[%WINDOWS%]\WUPDMGR.EXE
[%WINDOWS%]\ZServ.dll
[%COMMON_DESKTOPDIRECTORY%]\Online Security Center.url
[%COMMON_DESKTOPDIRECTORY%]\Online Security Guide.url
[%COMMON_DESKTOPDIRECTORY%]\Security Troubleshooting.url
[%COMMON_FAVORITES%]\Antivirus Test Online.url
[%COMMON_FAVORITES%]\Buy Viagra Online.url
[%COMMON_FAVORITES%]\Cheap Viagra.url
[%COMMON_STARTMENU%]\Anti SPAM.url
[%COMMON_STARTMENU%]\Computer Security.url
[%COMMON_STARTMENU%]\Online Security Center.url
[%COMMON_STARTMENU%]\Online Security Guide.url
[%COMMON_STARTMENU%]\Security Troubleshooting.url
[%DESKTOP%]\Blackjack.url
[%DESKTOP%]\REMOVE SPYWARE.url
[%DESKTOP%]\remove.exe
[%DESKTOP%]\SpySheriff.lnk
[%DESKTOP%]\Trust Cleaner.lnk
[%DESKTOP%]\VIDEO.EXE
[%FAVORITES%]\Alprazolam.url
[%FAVORITES%]\Antivirus Test Online.url
[%FAVORITES%]\Free XXX Sites List.url
[%FAVORITES%]\Job Search.url
[%FAVORITES%]\Network Security.url
[%FAVORITES%]\online dating.url
[%FAVORITES%]\Online Gambling.url
[%FAVORITES%]\Online Pharmacy.url
[%FAVORITES%]\Remove Spyware.url
[%FAVORITES%]\Spam Filters.url
[%FAVORITES%]\Take It Here - Daily Updated Porn Links.url
[%FAVORITES%]\Web Detective.url
[%PROFILE%]\cmd.exe
[%PROFILE%]\start
[%PROGRAM_FILES%]\AlfaCleaner\digsign.db
[%PROGRAM_FILES%]\Security Toolbar\Security Toolbar.dll
[%PROGRAM_FILES%]\Security Toolbar\Uninstall.bat
[%PROGRAM_FILES%]\SpySheriff\base.avd
[%PROGRAM_FILES%]\SpySheriff\base001.avd
[%PROGRAM_FILES%]\SpySheriff\base002.avd
[%PROGRAM_FILES%]\SpySheriff\found.wav
[%PROGRAM_FILES%]\SpySheriff\heur000.dll
[%PROGRAM_FILES%]\SpySheriff\heur001.dll
[%PROGRAM_FILES%]\SpySheriff\heur002.dll
[%PROGRAM_FILES%]\SpySheriff\heur003.dll
[%PROGRAM_FILES%]\SpySheriff\notfound.wav
[%PROGRAM_FILES%]\SpySheriff\removed.wav
[%PROGRAM_FILES%]\SpySheriff\SpySheriff.dvm
[%PROGRAM_FILES%]\SpySheriff\SpySheriff.exe
[%PROGRAM_FILES%]\SpySheriff\Uninstall.exe
[%PROGRAM_FILES%]\SpyTrooper\Uninstall.exe
[%PROGRAM_FILES%]\SpywareQuake\blacklist.txt
[%PROGRAM_FILES%]\SpywareQuake\msvcp71.dll
[%PROGRAM_FILES%]\SpywareQuake\msvcr71.dll
[%PROGRAM_FILES%]\SpywareQuake\ref.dat
[%PROGRAM_FILES%]\SpywareQuake\SpywareQuake.exe
[%PROGRAM_FILES%]\SpywareQuake\SpywareQuake.url
[%PROGRAM_FILES%]\SpywareQuake\uninst.exe
[%PROGRAM_FILES%]\SpywareStrike\SpywareStrike.exe
[%PROGRAM_FILES%]\SpywareStrike\spywarestrike.ini
[%STARTMENU%]\SpywareStrike 2.5.lnk
[%SYSTEM%]\a.exe
[%SYSTEM%]\adobepnl.dll
[%SYSTEM%]\alxres.dll
[%SYSTEM%]\appmagr.dll
[%SYSTEM%]\atmclk.exe
[%SYSTEM%]\atmtd.dll
[%SYSTEM%]\atmtd.dll._
[%SYSTEM%]\bridge.dll
[%SYSTEM%]\CWS_iestart.exe
[%SYSTEM%]\dailytoolbar.dll
[%SYSTEM%]\dcomcfg.exe
[%SYSTEM%]\dfrgsrv.exe
[%SYSTEM%]\dxmpp.dll
[%SYSTEM%]\dxole32.exe
[%SYSTEM%]\hvnwm.dll
[%SYSTEM%]\intel32.exe
[%SYSTEM%]\intell32.exe
[%SYSTEM%]\ishost.exe
[%SYSTEM%]\ismon.exe
[%SYSTEM%]\isnotify.exe
[%SYSTEM%]\issearch.exe
[%SYSTEM%]\ixt0.dll
[%SYSTEM%]\ixt1.dll
[%SYSTEM%]\ixt2.dll
[%SYSTEM%]\ixt3.dll
[%SYSTEM%]\ixt4.dll
[%SYSTEM%]\ixt5.dll
[%SYSTEM%]\ixt6.dll
[%SYSTEM%]\ixt7.dll
[%SYSTEM%]\ixt8.dll
[%SYSTEM%]\ixt9.dll
[%SYSTEM%]\jao.dll
[%SYSTEM%]\kernels32.exe
[%SYSTEM%]\kernels8.exe
[%SYSTEM%]\lcch.dat
[%SYSTEM%]\mirarsearch_toolbar.exe
[%SYSTEM%]\mscornet.exe
[%SYSTEM%]\msmsgs.exe
[%SYSTEM%]\msole32.exe
[%SYSTEM%]\mswinb32.dll
[%SYSTEM%]\mswinb32.exe
[%SYSTEM%]\mswinup32.dll
[%SYSTEM%]\notepad.exe
[%SYSTEM%]\nvctrl.exe
[%SYSTEM%]\oleadm.dll
[%SYSTEM%]\oleext.dll
[%SYSTEM%]\oleext32.dll
[%SYSTEM%]\page.htm
[%SYSTEM%]\perflibs__
[%SYSTEM%]\phqghume.exe
[%SYSTEM%]\qjrkvy.exe
[%SYSTEM%]\questmod.dll
[%SYSTEM%]\reger.exe
[%SYSTEM%]\regperf.exe
[%SYSTEM%]\repigsp.exe
[%SYSTEM%]\runsrv32.dll
[%SYSTEM%]\runsrv32.exe
[%SYSTEM%]\shell386.exe
[%SYSTEM%]\shellgui32.dll
[%SYSTEM%]\SUSP.exe
[%SYSTEM%]\svehost.exe
[%SYSTEM%]\sywsvcs.exe
[%SYSTEM%]\taskdir.dll
[%SYSTEM%]\taskdir.exe
[%SYSTEM%]\taskdir~.exe
[%SYSTEM%]\tcpservice2.exe
[%SYSTEM%]\thlwin32.dll
[%SYSTEM%]\txfdb32.dll
[%SYSTEM%]\udpmod.dll
[%SYSTEM%]\users32.exe
[%SYSTEM%]\voblaizdupla.exe
[%SYSTEM%]\winapi32.dll
[%SYSTEM%]\winbl32.dll
[%SYSTEM%]\winflash.dll
[%SYSTEM%]\winlfl32.dll
[%SYSTEM%]\winlogon.exe
[%SYSTEM%]\winsrv32.exe
[%SYSTEM%]\wldr.dll
[%SYSTEM%]\wp.bmp
[%SYSTEM%]\wppp.html
[%SYSTEM%]\wstart.dll
[%SYSTEM%]\yephk.dll
[%SYSTEM%]\yephk.dll
[%SYSTEM%]\zlbw.dll
[%WINDOWS%]\alexaie.dll
[%WINDOWS%]\alxie328.dll
[%WINDOWS%]\alxtb1.dll
[%WINDOWS%]\BTGrab.dll
[%WINDOWS%]\desktop.html
[%WINDOWS%]\dlmax.dll
[%WINDOWS%]\inetloader.dll
[%WINDOWS%]\Pynix.dll
[%WINDOWS%]\screen.html
[%WINDOWS%]\secure32.html
[%WINDOWS%]\sites.ini
[%WINDOWS%]\susp.exe
[%WINDOWS%]\svchosts.dll
[%WINDOWS%]\tool1.exe
[%WINDOWS%]\tool2.exe
[%WINDOWS%]\tool3.exe
[%WINDOWS%]\tool4.exe
[%WINDOWS%]\tool5.exe
[%WINDOWS%]\uninstDsk.exe
[%WINDOWS%]\uninstIU.exe
[%WINDOWS%]\web\desktop.html
[%WINDOWS%]\WUPDMGR.EXE
[%WINDOWS%]\ZServ.dll

How to detect Smitfraud.c:

Files:
[%COMMON_DESKTOPDIRECTORY%]\Online Security Center.url
[%COMMON_DESKTOPDIRECTORY%]\Online Security Guide.url
[%COMMON_DESKTOPDIRECTORY%]\Security Troubleshooting.url
[%COMMON_FAVORITES%]\Antivirus Test Online.url
[%COMMON_FAVORITES%]\Buy Viagra Online.url
[%COMMON_FAVORITES%]\Cheap Viagra.url
[%COMMON_STARTMENU%]\Anti SPAM.url
[%COMMON_STARTMENU%]\Computer Security.url
[%COMMON_STARTMENU%]\Online Security Center.url
[%COMMON_STARTMENU%]\Online Security Guide.url
[%COMMON_STARTMENU%]\Security Troubleshooting.url
[%DESKTOP%]\Blackjack.url
[%DESKTOP%]\REMOVE SPYWARE.url
[%DESKTOP%]\remove.exe
[%DESKTOP%]\SpySheriff.lnk
[%DESKTOP%]\Trust Cleaner.lnk
[%DESKTOP%]\VIDEO.EXE
[%FAVORITES%]\Alprazolam.url
[%FAVORITES%]\Antivirus Test Online.url
[%FAVORITES%]\Free XXX Sites List.url
[%FAVORITES%]\Job Search.url
[%FAVORITES%]\Network Security.url
[%FAVORITES%]\online dating.url
[%FAVORITES%]\Online Gambling.url
[%FAVORITES%]\Online Pharmacy.url
[%FAVORITES%]\Remove Spyware.url
[%FAVORITES%]\Spam Filters.url
[%FAVORITES%]\Take It Here - Daily Updated Porn Links.url
[%FAVORITES%]\Web Detective.url
[%PROFILE%]\cmd.exe
[%PROFILE%]\start
[%PROGRAM_FILES%]\AlfaCleaner\digsign.db
[%PROGRAM_FILES%]\Security Toolbar\Security Toolbar.dll
[%PROGRAM_FILES%]\Security Toolbar\Uninstall.bat
[%PROGRAM_FILES%]\SpySheriff\base.avd
[%PROGRAM_FILES%]\SpySheriff\base001.avd
[%PROGRAM_FILES%]\SpySheriff\base002.avd
[%PROGRAM_FILES%]\SpySheriff\found.wav
[%PROGRAM_FILES%]\SpySheriff\heur000.dll
[%PROGRAM_FILES%]\SpySheriff\heur001.dll
[%PROGRAM_FILES%]\SpySheriff\heur002.dll
[%PROGRAM_FILES%]\SpySheriff\heur003.dll
[%PROGRAM_FILES%]\SpySheriff\notfound.wav
[%PROGRAM_FILES%]\SpySheriff\removed.wav
[%PROGRAM_FILES%]\SpySheriff\SpySheriff.dvm
[%PROGRAM_FILES%]\SpySheriff\SpySheriff.exe
[%PROGRAM_FILES%]\SpySheriff\Uninstall.exe
[%PROGRAM_FILES%]\SpyTrooper\Uninstall.exe
[%PROGRAM_FILES%]\SpywareQuake\blacklist.txt
[%PROGRAM_FILES%]\SpywareQuake\msvcp71.dll
[%PROGRAM_FILES%]\SpywareQuake\msvcr71.dll
[%PROGRAM_FILES%]\SpywareQuake\ref.dat
[%PROGRAM_FILES%]\SpywareQuake\SpywareQuake.exe
[%PROGRAM_FILES%]\SpywareQuake\SpywareQuake.url
[%PROGRAM_FILES%]\SpywareQuake\uninst.exe
[%PROGRAM_FILES%]\SpywareStrike\SpywareStrike.exe
[%PROGRAM_FILES%]\SpywareStrike\spywarestrike.ini
[%STARTMENU%]\SpywareStrike 2.5.lnk
[%SYSTEM%]\a.exe
[%SYSTEM%]\adobepnl.dll
[%SYSTEM%]\alxres.dll
[%SYSTEM%]\appmagr.dll
[%SYSTEM%]\atmclk.exe
[%SYSTEM%]\atmtd.dll
[%SYSTEM%]\atmtd.dll._
[%SYSTEM%]\bridge.dll
[%SYSTEM%]\CWS_iestart.exe
[%SYSTEM%]\dailytoolbar.dll
[%SYSTEM%]\dcomcfg.exe
[%SYSTEM%]\dfrgsrv.exe
[%SYSTEM%]\dxmpp.dll
[%SYSTEM%]\dxole32.exe
[%SYSTEM%]\hvnwm.dll
[%SYSTEM%]\intel32.exe
[%SYSTEM%]\intell32.exe
[%SYSTEM%]\ishost.exe
[%SYSTEM%]\ismon.exe
[%SYSTEM%]\isnotify.exe
[%SYSTEM%]\issearch.exe
[%SYSTEM%]\ixt0.dll
[%SYSTEM%]\ixt1.dll
[%SYSTEM%]\ixt2.dll
[%SYSTEM%]\ixt3.dll
[%SYSTEM%]\ixt4.dll
[%SYSTEM%]\ixt5.dll
[%SYSTEM%]\ixt6.dll
[%SYSTEM%]\ixt7.dll
[%SYSTEM%]\ixt8.dll
[%SYSTEM%]\ixt9.dll
[%SYSTEM%]\jao.dll
[%SYSTEM%]\kernels32.exe
[%SYSTEM%]\kernels8.exe
[%SYSTEM%]\lcch.dat
[%SYSTEM%]\mirarsearch_toolbar.exe
[%SYSTEM%]\mscornet.exe
[%SYSTEM%]\msmsgs.exe
[%SYSTEM%]\msole32.exe
[%SYSTEM%]\mswinb32.dll
[%SYSTEM%]\mswinb32.exe
[%SYSTEM%]\mswinup32.dll
[%SYSTEM%]\notepad.exe
[%SYSTEM%]\nvctrl.exe
[%SYSTEM%]\oleadm.dll
[%SYSTEM%]\oleext.dll
[%SYSTEM%]\oleext32.dll
[%SYSTEM%]\page.htm
[%SYSTEM%]\perflibs__
[%SYSTEM%]\phqghume.exe
[%SYSTEM%]\qjrkvy.exe
[%SYSTEM%]\questmod.dll
[%SYSTEM%]\reger.exe
[%SYSTEM%]\regperf.exe
[%SYSTEM%]\repigsp.exe
[%SYSTEM%]\runsrv32.dll
[%SYSTEM%]\runsrv32.exe
[%SYSTEM%]\shell386.exe
[%SYSTEM%]\shellgui32.dll
[%SYSTEM%]\SUSP.exe
[%SYSTEM%]\svehost.exe
[%SYSTEM%]\sywsvcs.exe
[%SYSTEM%]\taskdir.dll
[%SYSTEM%]\taskdir.exe
[%SYSTEM%]\taskdir~.exe
[%SYSTEM%]\tcpservice2.exe
[%SYSTEM%]\thlwin32.dll
[%SYSTEM%]\txfdb32.dll
[%SYSTEM%]\udpmod.dll
[%SYSTEM%]\users32.exe
[%SYSTEM%]\voblaizdupla.exe
[%SYSTEM%]\winapi32.dll
[%SYSTEM%]\winbl32.dll
[%SYSTEM%]\winflash.dll
[%SYSTEM%]\winlfl32.dll
[%SYSTEM%]\winlogon.exe
[%SYSTEM%]\winsrv32.exe
[%SYSTEM%]\wldr.dll
[%SYSTEM%]\wp.bmp
[%SYSTEM%]\wppp.html
[%SYSTEM%]\wstart.dll
[%SYSTEM%]\yephk.dll
[%SYSTEM%]\yephk.dll
[%SYSTEM%]\zlbw.dll
[%WINDOWS%]\alexaie.dll
[%WINDOWS%]\alxie328.dll
[%WINDOWS%]\alxtb1.dll
[%WINDOWS%]\BTGrab.dll
[%WINDOWS%]\desktop.html
[%WINDOWS%]\dlmax.dll
[%WINDOWS%]\inetloader.dll
[%WINDOWS%]\Pynix.dll
[%WINDOWS%]\screen.html
[%WINDOWS%]\secure32.html
[%WINDOWS%]\sites.ini
[%WINDOWS%]\susp.exe
[%WINDOWS%]\svchosts.dll
[%WINDOWS%]\tool1.exe
[%WINDOWS%]\tool2.exe
[%WINDOWS%]\tool3.exe
[%WINDOWS%]\tool4.exe
[%WINDOWS%]\tool5.exe
[%WINDOWS%]\uninstDsk.exe
[%WINDOWS%]\uninstIU.exe
[%WINDOWS%]\web\desktop.html
[%WINDOWS%]\WUPDMGR.EXE
[%WINDOWS%]\ZServ.dll
[%COMMON_DESKTOPDIRECTORY%]\Online Security Center.url
[%COMMON_DESKTOPDIRECTORY%]\Online Security Guide.url
[%COMMON_DESKTOPDIRECTORY%]\Security Troubleshooting.url
[%COMMON_FAVORITES%]\Antivirus Test Online.url
[%COMMON_FAVORITES%]\Buy Viagra Online.url
[%COMMON_FAVORITES%]\Cheap Viagra.url
[%COMMON_STARTMENU%]\Anti SPAM.url
[%COMMON_STARTMENU%]\Computer Security.url
[%COMMON_STARTMENU%]\Online Security Center.url
[%COMMON_STARTMENU%]\Online Security Guide.url
[%COMMON_STARTMENU%]\Security Troubleshooting.url
[%DESKTOP%]\Blackjack.url
[%DESKTOP%]\REMOVE SPYWARE.url
[%DESKTOP%]\remove.exe
[%DESKTOP%]\SpySheriff.lnk
[%DESKTOP%]\Trust Cleaner.lnk
[%DESKTOP%]\VIDEO.EXE
[%FAVORITES%]\Alprazolam.url
[%FAVORITES%]\Antivirus Test Online.url
[%FAVORITES%]\Free XXX Sites List.url
[%FAVORITES%]\Job Search.url
[%FAVORITES%]\Network Security.url
[%FAVORITES%]\online dating.url
[%FAVORITES%]\Online Gambling.url
[%FAVORITES%]\Online Pharmacy.url
[%FAVORITES%]\Remove Spyware.url
[%FAVORITES%]\Spam Filters.url
[%FAVORITES%]\Take It Here - Daily Updated Porn Links.url
[%FAVORITES%]\Web Detective.url
[%PROFILE%]\cmd.exe
[%PROFILE%]\start
[%PROGRAM_FILES%]\AlfaCleaner\digsign.db
[%PROGRAM_FILES%]\Security Toolbar\Security Toolbar.dll
[%PROGRAM_FILES%]\Security Toolbar\Uninstall.bat
[%PROGRAM_FILES%]\SpySheriff\base.avd
[%PROGRAM_FILES%]\SpySheriff\base001.avd
[%PROGRAM_FILES%]\SpySheriff\base002.avd
[%PROGRAM_FILES%]\SpySheriff\found.wav
[%PROGRAM_FILES%]\SpySheriff\heur000.dll
[%PROGRAM_FILES%]\SpySheriff\heur001.dll
[%PROGRAM_FILES%]\SpySheriff\heur002.dll
[%PROGRAM_FILES%]\SpySheriff\heur003.dll
[%PROGRAM_FILES%]\SpySheriff\notfound.wav
[%PROGRAM_FILES%]\SpySheriff\removed.wav
[%PROGRAM_FILES%]\SpySheriff\SpySheriff.dvm
[%PROGRAM_FILES%]\SpySheriff\SpySheriff.exe
[%PROGRAM_FILES%]\SpySheriff\Uninstall.exe
[%PROGRAM_FILES%]\SpyTrooper\Uninstall.exe
[%PROGRAM_FILES%]\SpywareQuake\blacklist.txt
[%PROGRAM_FILES%]\SpywareQuake\msvcp71.dll
[%PROGRAM_FILES%]\SpywareQuake\msvcr71.dll
[%PROGRAM_FILES%]\SpywareQuake\ref.dat
[%PROGRAM_FILES%]\SpywareQuake\SpywareQuake.exe
[%PROGRAM_FILES%]\SpywareQuake\SpywareQuake.url
[%PROGRAM_FILES%]\SpywareQuake\uninst.exe
[%PROGRAM_FILES%]\SpywareStrike\SpywareStrike.exe
[%PROGRAM_FILES%]\SpywareStrike\spywarestrike.ini
[%STARTMENU%]\SpywareStrike 2.5.lnk
[%SYSTEM%]\a.exe
[%SYSTEM%]\adobepnl.dll
[%SYSTEM%]\alxres.dll
[%SYSTEM%]\appmagr.dll
[%SYSTEM%]\atmclk.exe
[%SYSTEM%]\atmtd.dll
[%SYSTEM%]\atmtd.dll._
[%SYSTEM%]\bridge.dll
[%SYSTEM%]\CWS_iestart.exe
[%SYSTEM%]\dailytoolbar.dll
[%SYSTEM%]\dcomcfg.exe
[%SYSTEM%]\dfrgsrv.exe
[%SYSTEM%]\dxmpp.dll
[%SYSTEM%]\dxole32.exe
[%SYSTEM%]\hvnwm.dll
[%SYSTEM%]\intel32.exe
[%SYSTEM%]\intell32.exe
[%SYSTEM%]\ishost.exe
[%SYSTEM%]\ismon.exe
[%SYSTEM%]\isnotify.exe
[%SYSTEM%]\issearch.exe
[%SYSTEM%]\ixt0.dll
[%SYSTEM%]\ixt1.dll
[%SYSTEM%]\ixt2.dll
[%SYSTEM%]\ixt3.dll
[%SYSTEM%]\ixt4.dll
[%SYSTEM%]\ixt5.dll
[%SYSTEM%]\ixt6.dll
[%SYSTEM%]\ixt7.dll
[%SYSTEM%]\ixt8.dll
[%SYSTEM%]\ixt9.dll
[%SYSTEM%]\jao.dll
[%SYSTEM%]\kernels32.exe
[%SYSTEM%]\kernels8.exe
[%SYSTEM%]\lcch.dat
[%SYSTEM%]\mirarsearch_toolbar.exe
[%SYSTEM%]\mscornet.exe
[%SYSTEM%]\msmsgs.exe
[%SYSTEM%]\msole32.exe
[%SYSTEM%]\mswinb32.dll
[%SYSTEM%]\mswinb32.exe
[%SYSTEM%]\mswinup32.dll
[%SYSTEM%]\notepad.exe
[%SYSTEM%]\nvctrl.exe
[%SYSTEM%]\oleadm.dll
[%SYSTEM%]\oleext.dll
[%SYSTEM%]\oleext32.dll
[%SYSTEM%]\page.htm
[%SYSTEM%]\perflibs__
[%SYSTEM%]\phqghume.exe
[%SYSTEM%]\qjrkvy.exe
[%SYSTEM%]\questmod.dll
[%SYSTEM%]\reger.exe
[%SYSTEM%]\regperf.exe
[%SYSTEM%]\repigsp.exe
[%SYSTEM%]\runsrv32.dll
[%SYSTEM%]\runsrv32.exe
[%SYSTEM%]\shell386.exe
[%SYSTEM%]\shellgui32.dll
[%SYSTEM%]\SUSP.exe
[%SYSTEM%]\svehost.exe
[%SYSTEM%]\sywsvcs.exe
[%SYSTEM%]\taskdir.dll
[%SYSTEM%]\taskdir.exe
[%SYSTEM%]\taskdir~.exe
[%SYSTEM%]\tcpservice2.exe
[%SYSTEM%]\thlwin32.dll
[%SYSTEM%]\txfdb32.dll
[%SYSTEM%]\udpmod.dll
[%SYSTEM%]\users32.exe
[%SYSTEM%]\voblaizdupla.exe
[%SYSTEM%]\winapi32.dll
[%SYSTEM%]\winbl32.dll
[%SYSTEM%]\winflash.dll
[%SYSTEM%]\winlfl32.dll
[%SYSTEM%]\winlogon.exe
[%SYSTEM%]\winsrv32.exe
[%SYSTEM%]\wldr.dll
[%SYSTEM%]\wp.bmp
[%SYSTEM%]\wppp.html
[%SYSTEM%]\wstart.dll
[%SYSTEM%]\yephk.dll
[%SYSTEM%]\yephk.dll
[%SYSTEM%]\zlbw.dll
[%WINDOWS%]\alexaie.dll
[%WINDOWS%]\alxie328.dll
[%WINDOWS%]\alxtb1.dll
[%WINDOWS%]\BTGrab.dll
[%WINDOWS%]\desktop.html
[%WINDOWS%]\dlmax.dll
[%WINDOWS%]\inetloader.dll
[%WINDOWS%]\Pynix.dll
[%WINDOWS%]\screen.html
[%WINDOWS%]\secure32.html
[%WINDOWS%]\sites.ini
[%WINDOWS%]\susp.exe
[%WINDOWS%]\svchosts.dll
[%WINDOWS%]\tool1.exe
[%WINDOWS%]\tool2.exe
[%WINDOWS%]\tool3.exe
[%WINDOWS%]\tool4.exe
[%WINDOWS%]\tool5.exe
[%WINDOWS%]\uninstDsk.exe
[%WINDOWS%]\uninstIU.exe
[%WINDOWS%]\web\desktop.html
[%WINDOWS%]\WUPDMGR.EXE
[%WINDOWS%]\ZServ.dll

Folders:
[%COMMON_PROGRAMS%]\WinHound spyware remover
[%PROGRAMS%]\SpySheriff
[%PROGRAMS%]\SpywareStrike
[%PROGRAM_FILES%]\alfacleaner
[%PROGRAM_FILES%]\Crystalys media
[%PROGRAM_FILES%]\P.S.Guard
[%PROGRAM_FILES%]\psguard
[%PROGRAM_FILES%]\Security Toolbar
[%PROGRAM_FILES%]\SpyAxe
[%PROGRAM_FILES%]\SpyFalcon
[%PROGRAM_FILES%]\spysheriff
[%PROGRAM_FILES%]\SpywareQuake
[%PROGRAM_FILES%]\SpywareStrike
[%PROGRAM_FILES%]\Trust Cleaner
[%PROGRAM_FILES%]\Virtual Maid
[%PROGRAM_FILES%]\WinHound

Registry Keys:
HKEY_CLASSES_ROOT\adobepnl.ADOBE_PANEL
HKEY_CLASSES_ROOT\band.MITBHO
HKEY_CLASSES_ROOT\CLSID\System
HKEY_CLASSES_ROOT\CLSID\VMHomepage
HKEY_CLASSES_ROOT\CLSID\VMHomepage.1
HKEY_CLASSES_ROOT\CLSID\{00000000-59D4-4008-9058-080011001200}
HKEY_CLASSES_ROOT\CLSID\{00000000-C1EC-0345-6EC2-4D0300000000}
HKEY_CLASSES_ROOT\CLSID\{00000000-F09C-02B4-6EC2-AD0300000000}
HKEY_CLASSES_ROOT\clsid\{057e242f-2947-4e0a-8e61-a11345d97ea6}
HKEY_CLASSES_ROOT\CLSID\{05a91164-3c96-47d6-aa74-2c855791b2d0}
HKEY_CLASSES_ROOT\CLSID\{0c7416f0-dd23-420f-97f5-aae352ea2bf1}
HKEY_CLASSES_ROOT\CLSID\{0F25878F-F8AE-5D5D-2BB7-31B5F803290D}
HKEY_CLASSES_ROOT\CLSID\{145E6FB1-1256-44ED-A336-8BBA43373BE6}
HKEY_CLASSES_ROOT\CLSID\{159C2E51-9823-11D2-8DDC-D84A1B4ACD4D}
HKEY_CLASSES_ROOT\CLSID\{15DC7116-E58E-4395-A45A-A1C99B17C030}
HKEY_CLASSES_ROOT\CLSID\{17E02586-A91D-4A9D-A74E-187B05DFFE6F}
HKEY_CLASSES_ROOT\CLSID\{1BD98DFD-2DA9-4C54-85D7-BE03A0F9C487}
HKEY_CLASSES_ROOT\CLSID\{1C94EA51-3800-4F08-B5DC-A5B67823FFEA}
HKEY_CLASSES_ROOT\CLSID\{1ca480cd-c0e5-4548-874e-b85b17905b3a}
HKEY_CLASSES_ROOT\CLSID\{20D1AF34-6E19-42D8-AF9F-BDFBE45C2454}
HKEY_CLASSES_ROOT\CLSID\{210b4043-35ca-4aa0-8796-191f9663dfb3}
HKEY_CLASSES_ROOT\CLSID\{210b4043-35ca-4aa0-8796-191f9663dfb3}
HKEY_CLASSES_ROOT\CLSID\{21E132C9-1F98-4151-BDAD-7D9B49C60A8E}
HKEY_CLASSES_ROOT\CLSID\{23F7AD29-F51A-4BA1-BE70-143B1CB25BD1}
HKEY_CLASSES_ROOT\CLSID\{24E27EA9-FCF3-444F-BD80-20543BA5D946}
HKEY_CLASSES_ROOT\CLSID\{2513A321-CB50-4C5F-91C5-80342AFACFB1}
HKEY_CLASSES_ROOT\CLSID\{27150F81-0877-42E9-AF13-55E5A3439A26}
HKEY_CLASSES_ROOT\CLSID\{2C1CD3D7-86AC-4068-93BC-A02304BB8C34}
HKEY_CLASSES_ROOT\CLSID\{2C59D5EC-6B91-4896-BD6F-5F121D87A7F8}
HKEY_CLASSES_ROOT\CLSID\{2F34E0E0-F0BB-477F-AFB8-509262FA0AD1}
HKEY_CLASSES_ROOT\CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}
HKEY_CLASSES_ROOT\CLSID\{357A87ED-3E5D-437d-B334-DEB7EB4982A3}
HKEY_CLASSES_ROOT\CLSID\{35a88e51-b53d-43e9-b8a7-75d4c31b4676}
HKEY_CLASSES_ROOT\CLSID\{35ED274E-3F42-4A78-BBDC-3B7D73E85578}
HKEY_CLASSES_ROOT\CLSID\{38D4D5D0-423E-4220-B6F9-30918C2AE4A4}
HKEY_CLASSES_ROOT\CLSID\{3ceff6cd-6f08-4e4d-bccd-ff7415288c3b}
HKEY_CLASSES_ROOT\CLSID\{3D74D140-F780-4AE3-8D6D-F8DC39107213}
HKEY_CLASSES_ROOT\CLSID\{3e9b951e-6f72-431b-82cf-4a9fbf2f53bc}
HKEY_CLASSES_ROOT\CLSID\{49443D6E-CE4E-47A9-8DEB-F5774CE14984}
HKEY_CLASSES_ROOT\CLSID\{4da4616d-7e6e-4fd9-a2d5-b6c535733e22}
HKEY_CLASSES_ROOT\CLSID\{52034AD2-914C-4634-B375-9299631E5525}
HKEY_CLASSES_ROOT\CLSID\{55059d4f-a1ac-4837-ae07-4859101f598d}
HKEY_CLASSES_ROOT\CLSID\{5839511e-ec1b-4f91-ace3-fb88e52f5239}
HKEY_CLASSES_ROOT\CLSID\{5aaf6542-f4ba-4df4-873d-4902ecbe794c}
HKEY_CLASSES_ROOT\CLSID\{5B55C4E3-C179-BA0B-B4FD-F2DB862D6202}
HKEY_CLASSES_ROOT\CLSID\{5bc82bdb-bc03-4671-9a78-3ef2b68449de}
HKEY_CLASSES_ROOT\CLSID\{5E8FA924-DEF0-4E71-8A82-A11CA0C1413B}
HKEY_CLASSES_ROOT\CLSID\{5f4c3d09-b3b9-4f88-aa82-31332fee1c08}
HKEY_CLASSES_ROOT\CLSID\{62eb0924-19d2-4226-b4b9-8ad1f70904c1}
HKEY_CLASSES_ROOT\CLSID\{6379A99A-9102-446C-A837-0623E1810D75}
HKEY_CLASSES_ROOT\CLSID\{64ba30a2-811a-4597-b0af-d551128be340}
HKEY_CLASSES_ROOT\CLSID\{686a161d-5bd1-4999-8832-6393f41e564c}
HKEY_CLASSES_ROOT\CLSID\{6ab7158b-4bff-4160-ad7d-4d622df548cf}
HKEY_CLASSES_ROOT\CLSID\{6af69c4d-420a-4c95-b34f-e4635f84f53b}
HKEY_CLASSES_ROOT\CLSID\{736B5468-BDAD-41BE-92D0-22AE2DDF7BCB}
HKEY_CLASSES_ROOT\CLSID\{7702C521-76AE-42C0-A181-3B5A96C2EEF7}
HKEY_CLASSES_ROOT\CLSID\{77701e16-9bfe-4b63-a5b4-7bd156758a37}
HKEY_CLASSES_ROOT\CLSID\{7a932ed2-1737-4ab8-b84d-c71779958551}
HKEY_CLASSES_ROOT\CLSID\{7ADDA344-1D36-4446-9F4B-B2351FB19EFD}
HKEY_CLASSES_ROOT\CLSID\{7b55bb05-0b4d-44fd-81a6-b136188f5deb}
HKEY_CLASSES_ROOT\CLSID\{7D98221E-AF8F-4D29-8BB1-1DFABC288173}
HKEY_CLASSES_ROOT\CLSID\{8333C319-0669-4893-A418-F56D9249FCA6}
HKEY_CLASSES_ROOT\CLSID\{89aef01d-d237-49c7-84dc-4e1904c1fd31}
HKEY_CLASSES_ROOT\CLSID\{89e4aaba-3b21-49b3-b922-8ca35193c68e}
HKEY_CLASSES_ROOT\CLSID\{8D83B16E-0DE1-452B-AC52-96EC0B34AA4B}
HKEY_CLASSES_ROOT\CLSID\{8dc1f789-e073-4363-b40d-07376bc5ecc5}
HKEY_CLASSES_ROOT\CLSID\{93ac7c30-3878-4eaa-9420-7977285df5b1}
HKEY_CLASSES_ROOT\CLSID\{93ac7c30-3878-4eaa-9420-7977285df5b1}
HKEY_CLASSES_ROOT\CLSID\{957bab51-81ff-8195-f273-d7e286ea702f}
HKEY_CLASSES_ROOT\CLSID\{9746B450-6064-4EC8-9480-72A289AA2237}
HKEY_CLASSES_ROOT\CLSID\{A1D9D3F0-8C2A-9A1D-A376-2CACFB10AB72}
HKEY_CLASSES_ROOT\CLSID\{A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F}
HKEY_CLASSES_ROOT\CLSID\{A40D9D65-5C09-421A-AFF8-2160D7ABD4E7}
HKEY_CLASSES_ROOT\CLSID\{aea3d2df-2b2c-4d7b-81a0-d975c6dc088e}
HKEY_CLASSES_ROOT\CLSID\{af3fd9a8-1287-4159-9212-9a5b4494af70}
HKEY_CLASSES_ROOT\CLSID\{b0398eca-0bcd-4645-8261-5e9dc70248d0}
HKEY_CLASSES_ROOT\CLSID\{B599C57E-113A-4488-A5E9-BC552C4F1152}
HKEY_CLASSES_ROOT\CLSID\{C1A2FDA2-1A5B-2A8F-F3A2-B22DA1A3C41D}
HKEY_CLASSES_ROOT\CLSID\{C1A2FDA2-2A5B-2C8A-F2A2-BA2DB3A2C31C}
HKEY_CLASSES_ROOT\CLSID\{C1A8B6A1-2C81-1C3D-A3C6-A1CCDB10B47F}
HKEY_CLASSES_ROOT\CLSID\{C5A40FCE-0A0F-40CA-985E-661C28B5B431}
HKEY_CLASSES_ROOT\CLSID\{C7F22879-7151-4C71-8C50-9557AFDA66C6}
HKEY_CLASSES_ROOT\CLSID\{CA14EE13-ED15-C4A2-17FF-DA4D15C1BC5E}
HKEY_CLASSES_ROOT\CLSID\{CA5E7959-60B5-47B7-80AC-1606309733F3}
HKEY_CLASSES_ROOT\CLSID\{CD5E2AC9-25CE-A1C5-D1E2-DC6B28A6ED5A}
HKEY_CLASSES_ROOT\CLSID\{CEABF027-6CDC-4D47-ADF6-AC5D065826A6}
HKEY_CLASSES_ROOT\CLSID\{D1A2E7CD-F5C1-21A8-CA2C-13D0AC72D19D}
HKEY_CLASSES_ROOT\CLSID\{D81E2FC4-B0A2-11D3-21AC-07C04C21A18A}
HKEY_CLASSES_ROOT\CLSID\{da7ff3f8-08be-4cac-bc00-94d91c6ae7f4}
HKEY_CLASSES_ROOT\CLSID\{e0103cd4-d1ce-411a-b75b-4fec072867f4}
HKEY_CLASSES_ROOT\CLSID\{E0AA0493-C410-4CBD-B1DB-1723374FA8E0}
HKEY_CLASSES_ROOT\CLSID\{E2CA7CD1-1AD9-F1C4-3D2A-DC1A33E7AF9D}
HKEY_CLASSES_ROOT\CLSID\{E52DEDBB-D168-4BDB-B229-C48160800E81}
HKEY_CLASSES_ROOT\CLSID\{e5b1e382-817e-4b74-8a96-ec78751e6acf}
HKEY_CLASSES_ROOT\CLSID\{E5D78BD8-3874-4AA0-9D45-CFB79382C484}
HKEY_CLASSES_ROOT\CLSID\{E9CCF15D-4C68-4B5A-9E9A-8E12E4BD39BD}
HKEY_CLASSES_ROOT\CLSID\{EA26CE12-DE64-A1C5-9A4F-FC1A64E6AC2E}
HKEY_CLASSES_ROOT\CLSID\{ee2975b6-e8d5-405e-8448-8fe9590f6cfb}
HKEY_CLASSES_ROOT\CLSID\{f79fd28e-36ee-4989-aa61-9dd8e30a82fa}
HKEY_CLASSES_ROOT\CLSID\{f85e05f5-667e-41b0-ab8a-147337a99e65}
HKEY_CLASSES_ROOT\CLSID\{f8d02387-789a-4c0f-a1d8-8a93f33ee4df}
HKEY_CLASSES_ROOT\CLSID\{f8d02387-789a-4c0f-a1d8-8a93f33ee4df}
HKEY_CLASSES_ROOT\CLSID\{FB153DCE-822E-47ec-8D00-2706E7864B37}
HKEY_CLASSES_ROOT\CLSID\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA}
HKEY_CLASSES_ROOT\Interface\{159C2E50-9823-11D2-8DDC-D84A1B4ACD4D}
HKEY_CLASSES_ROOT\Interface\{1E1B2878-88FF-11D2-8D96-D7ACAC95951F}
HKEY_CLASSES_ROOT\Interface\{5FD68FB1-7D4C-4803-AB57-382E5CE342BC}
HKEY_CLASSES_ROOT\Interface\{EF17C9F7-3ABD-48BA-BCD3-3ADD3C1B65E5}
HKEY_CLASSES_ROOT\MezziaCodec.Chl
HKEY_CLASSES_ROOT\NVideoCodek.Chl
HKEY_CLASSES_ROOT\TypeLib\{159C2E41-9823-11D2-8DDC-D84A1B4ACD4D}
HKEY_CLASSES_ROOT\TypeLib\{1E1B286C-88FF-11D2-8D96-D7ACAC95951F}
HKEY_CLASSES_ROOT\TypeLib\{31F9B5A7-5B94-445D-922C-E97BF52F5FD7}
HKEY_CLASSES_ROOT\TypeLib\{B8CE2641-0F08-43A1-8F28-3AE65B395CB3}
HKEY_CLASSES_ROOT\TypeLib\{C13F6A43-3C5A-429A-87D5-3BBF60099CF0}
HKEY_CLASSES_ROOT\VMHomepage.1
HKEY_CURRENT_USER\Software\ADV
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{159C2E51-9823-11D2-8DDC-D84A1B4ACD4D}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{27150F81-0877-42E9-AF13-55E5A3439A26}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6379A99A-9102-446C-A837-0623E1810D75}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{686a161d-5bd1-4999-8832-6393f41e564c}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{736B5468-BDAD-41BE-92D0-22AE2DDF7BCB}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DA7FF3F8-08BE-4CAC-BC00-94D91C6AE7F4}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}
HKEY_CURRENT_USER\Software\SNO2
HKEY_CURRENT_USER\Software\Trust Cleaner
HKEY_LOCAL_MACHINE\SOFTWARE\AntivirusGold
HKEY_LOCAL_MACHINE\Software\Crystalys Media
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objecta
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objecta\{27150f81-0877-42e9-af13-55e5a3439a26}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00000000-59D4-4008-9058-080011001200}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00000000-C1EC-0345-6EC2-4D0300000000}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00000000-F09C-02B4-6EC2-AD0300000000}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1ca480cd-c0e5-4548-874e-b85b17905b3a}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2520BA45-3D97-4864-82FF-F47F951727BA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27150F81-0877-42E9-AF13-55E5A3439A26}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3ceff6cd-6f08-4e4d-bccd-ff7415288c3b}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3e9b951e-6f72-431b-82cf-4a9fbf2f53bc}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4da4616d-7e6e-4fd9-a2d5-b6c535733e22}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5E8FA924-DEF0-4E71-8A82-A11CA0C1413B}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5f4c3d09-b3b9-4f88-aa82-31332fee1c08}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{686a161d-5bd1-4999-8832-6393f41e564c}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6AB7158B-4BFF-4160-AD7D-4D622DF548CF}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77701e16-9bfe-4b63-a5b4-7bd156758a37}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7a932ed2-1737-4ab8-b84d-c71779958551}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7b55bb05-0b4d-44fd-81a6-b136188f5deb}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7caf96a2-c556-460a-988e-76fc7895d284}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8333c319-0669-4893-a418-f56d9249fca6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D83B16E-0DE1-452B-AC52-96EC0B34AA4B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b0398eca-0bcd-4645-8261-5e9dc70248d0}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C3E7E8D3-0B97-4FF3-B1BD-DAB4B04CD697}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{da7ff3f8-08be-4cac-bc00-94d91c6ae7f4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e0103cd4-d1ce-411a-b75b-4fec072867f4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e52dedbb-d168-4bdb-b229-c48160800e81}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E9CCF15D-4C68-4B5A-9E9A-8E12E4BD39BD}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f79fd28e-36ee-4989-aa61-9dd8e30a82fa}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ffd2825e-0785-40c5-9a41-518f53a8261f}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Desktop Uninstall
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Internet Connection Update and HomeP KB234087
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Internet Update
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\SearchAssistant Uninstall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Trust Cleaner
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{3877C2CD-F137-4144-BDB2-0A811492F920}

Registry Values:
HKEY_CURRENT_USER\Control Panel\Desktop\
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\software\policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies
HKEY_LOCAL_MACHINE\SOFTWARE\Policies

Removing Smitfraud.c:

You can download trial version of "Exterminate-It" antivirus software here, to check your computer instantly.

Or buy it to remove ALL viruses from your computer.

Also Be Aware of the Following Threats:
Lazy.Admin Backdoor Symptoms
Removing MailSpam.Aenima DoS
Zlob.Fam.HQVideoCodec Trojan Information
Interneter Trojan Symptoms
Generic.MultiDropper Trojan Removal instruction

No comments: