# For use with Merijn's Brute Force Uninstaller # available from http://www.merijn.org/ # # Script Name: 2search.bfu # Author: Pieter Arntz ProcessKill %PROGRAMFILES%\Internet Explorer\iexplore.exe|1 ProcessKill %PROGRAMFILES%\IM Names\IM-svr.EXE|1 OptionUnloadShell DllUnregister %PROGRAMFILES%\2search\plugin.dll|1 DllUnregister %PROGRAMFILES%\2search\2search.dll|1 FolderDelete %PROGRAMFILES%\2SEARCH FolderDelete %PROGRAMFILES%\IM Names RegDeleteKey HKCR\IEsearch.clsIESpy RegDeleteKey HKCR\GoogleCatch.clsIESpy RegDeleteKey HKCR\The007Guard.The007GuardCtrl.1 RegDeleteKey HKCR\STOPLITE.StopLiteCtrl.1 RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4508E20C-ACAD-11D2-9FC0-00550076E06F} RegDeleteKey HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4508E20C-ACAD-11D2-9FC0-00550076E06F} RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall|2search RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall|2search RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall|the guard RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall|the guard RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|svchost RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|svchost RegDeleteKey HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\2search RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\2search RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|2Search RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|IMprocess RegDelValue HKLM\SOFTWARE\WinRAR SFX|C%%Program Files%The Guard RegDelValue HKLM\SOFTWARE\WinRAR SFX|C%%Program Files%IM Names RegDelValue HKCU\WinRAR SFX|C%%Program Files%The Guard RegDelValue HKCU\WinRAR SFX|C%%Program Files%IM Names RegDelValue HKCU\SOFTWARE\WinRAR SFX|C%%Program Files%2search RegDelValue HKLM\SOFTWARE\WinRAR SFX|C%%Program Files%2search RegDeleteKey HKCR\CLSID\{4508E20C-ACAD-11D2-9FC0-00550076E06F} RegDeleteKey HKCR\CLSID\{20048BB3-DB68-11CF-9CAF-00AA006CB425} RegDeleteKey HKCR\Interface\{03BE31FE-6526-4D9C-B197-4A3E5DCFF696} RegDeleteKey HKCR\Interface\{0EB61AF8-0B15-48B6-A971-1F206F2E3D5E} RegDeleteKey HKCR\Interface\{20048BB1-DB68-11CF-9CAF-00AA006CB425} RegDeleteKey HKCR\TypeLib\{68E774CB-72D1-4A52-B55B-C0B1011E013B} RegDeleteKey HKCR\TypeLib\{20048BB0-DB68-11CF-9CAF-00AA006CB425} RegDeleteKey HKCR\Component Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4} HostsFileDelLine 69.20.16.183 auto.search.msn.com HostsFileDelLine 69.20.16.183 search.netscape.com HostsFileDelLine 69.20.16.183 ieautosearch FolderDelete %SYSDIR%\feeds FolderDelete %PROGRAMFILES%\The Guard FileDelete %SYSDIR%\007guard.exe FileDelete %SYSDIR%\2searchinstaller.exe FileDelete %SYSDIR%\2search.exe FileDelete %SYSDIR%\svmhost.exe FileDelete %SYSDIR%\spectreysb.exe FileDelete %SYSDIR%\access.ocx