# For use with Merijn's Brute Force Uninstaller # available from http://www.merijn.org/ # # Script Name: alcanshorty.BFU # Author: Pieter Arntz OptionStatusOn OptionSetStatus Stopping processes ProcessKill MsConfigs.exe|1 ProcessKill p2pnetwork.exe|1 ProcessKill winupdates.exe|1 ProcessKill winupdate.exe|1 ProcessKill winsupdater.exe|1 ProcessKill MsUpdate.exe|1 ProcessKill winlog.exe|1 ProcessKill MsMovies.exe|1 ProcessKill p2pnetworking.exe|1 ProcessKill winlogi.exe|1 ProcessKill MSDATA32.EXE|1 ProcessKill %PROGRAMFILES%\wmplayer\wmplayer.exe|1 ProcessKillIfMD5Match \wmplayer.exe|ce9928d88ad3f914c06e07d185d61968|1 ProcessKill %STARTUP%\wmplayer.exe|1 ProcessKill %ALLUSERSSTARTUP%\wmplayer.exe|1 ProcessKill %ALLUSERSSTARTUP%\msconfig.exe|1 ProcessKill %ALLUSERSSTARTUP%\taskmgr.exe|1 ProcessKillIfMD5Match \wmplayer.exe|4E092016BFA0441061483ED71C85C98D|1 ProcessKill %PROGRAMFILES%\outlook\outlook.exe|1 ProcessKillIfMD5Match \outlook.exe|B420A430D733A3A1D8B27E71F78590E1|1 ProcessKill \scvhost.exe|1 ProcessKill %ALLUSERSSTARTUP%\svchost.exe|1 ProcessKill %ALLUSERSSTARTUP%\dllhost.exe|1 ProcessKill \stub_113_*.exe|1 ProcessKill \mousepad*.exe|1 ProcessKill \keyboard*.exe|1 ProcessKill \newname*.exe|1 ProcessKill \services32.exe|1 ProcessKill \winsysban*.exe|1 ProcessKill \netmon.exe|1 ProcessKill \paytime.exe|1 ProcessKill \VCClient.exe|1 ProcessKill \VCMain.exe|1 ProcessKill \newfrn.exe|1 ProcessKill \eee2.exe|1 ProcessKill \SYSC00.exe|1 ProcessKill \SYSC0*.exe|1 ProcessKill \CheckS02.exe|1 ProcessKill \CheckS0*.exe|1 ProcessKill \errorhandler.exe|1 ProcessKill \EQAdvice.exe|1 ProcessKill \vxgame6.exe|1 ProcessKill \sysvx.exe|1 ProcessKill %SYSDIR%\mssearchnet.exe|1 ProcessKill %SYSDIR%\wintask.exe|1 ProcessKill \tetriz3.exe|1 ProcessKill \tool2.exe|1 ProcessKill *.tmp3584.exe|1 ProcessKill \ac2_00*.exe|1 ProcessKill \ac3_00*.exe|1 ProcessKill \gimmysmileys*.exe|1 ProcessKill \defender*.exe|1 ProcessKill %WINDIR%\cfg32.exe|1 ProcessKill %WINDIR%\cfg32a.exe|1 ProcessKill %SYSDIR%\WinSys.exe|1 ProcessKill %PROGRAMFILES%\winupdates\serialno.exe|1 ProcessKill \winrnt.exe|1 ProcessKill \mdrive\my.exe|1 ProcessKill \PECarlin.exe|1 ProcessKill \AXVenore.exe|1 ProcessKill \EQBranch.exe|1 ProcessKill \dfndr.exe|1 ProcessKill \dfndr*.exe|1 ProcessKill \nwnm*.exe|1 ProcessKill \kybrd*.exe|1 ProcessKillIfContainsText %SYSDIR%\*.exe|ZStart.lnk|1 ProcessKillIfContainsText %SYSDIR%\*.exe|Z_Start.lnk|1 ProcessKillIfContainsText %SYSDIR%\*.exe|TA_Start.lnk|1 ProcessKillIfContainsText %SYSDIR%\*.exe|Zeno.lnk|1 ProcessKillIfMD5Match eventwvr.exe|E665EEFEEBEFE3177CA1551E75EFCBBB|1 ProcessKillIfContainsText %WINDIR%\sys0*.exe|Zombie_GetTypeInfo|1 ProcessKillIfContainsText %WINDIR%\ms0*.exe|Zombie_GetTypeInfo|1 ProcessKill %SYSDIR%\wfxqhv.exe|1 ProcessKill %SYSDIR%\zqskw.exe|1 ProcessKill %SYSDIR%\l3jdfs.exe|1 ProcessKill %SYSDIR%\vp1i4.exe|1 ProcessKill \TheMatrixHasYou.exe|1 ProcessKill \truetype.exe|1 ProcessKill %WINDIR%\v1201.exe|1 ProcessKill %WINDIR%\Duce6.exe|1 ProcessKill \cmappclient.exe|1 ProcessKill %WINDIR%\thiselt.exe|1 ProcessKill \CMFibula.exe|1 ProcessKill \PSLister.exe|1 ProcessKill \PSCloner.exe|1 ProcessKill \PSDream.exe|1 ProcessKill %WINDIR%\xload.exe|1 ProcessKill \septpop06apsept.exe|1 ProcessKill \ItBill\itbill.exe|1 ProcessKill \p2pnetworks\p2pnetworks.exe|1 ProcessKill %SYSDIR%\recsl.exe|1 ProcessKill \Xinstall.exe|1 ProcessKill \Yinstall.exe|1 ProcessKill \update.exe|1 ProcessKill \elitepop06.exe|1 ProcessKill \PSCastor.exe|1 ProcessKill \CMIntex.exe|1 ProcessKill \rnnypbw.exe|1 ProcessKill \windows_e*.exe|1 ProcessKill \loadadv*.exe|1 ProcessKill \9129837.exe|1 ProcessKill \svcs.exe|1 ProcessKill \ipwins.exe|1 ProcessKill %WINDIR%\g4356cbvy63.exe|1 OptionUnloadShell ProcessKill \iexplore.exe|1 DllUnregister %WINDIR%\DH.dll|1 DllUnregister %PROGRAMFILES%\Deskbar\deskbar.dll|1 DllUnregister \asappsrv.dll|1 DllUnregister \MyToolBar.dll|1 DllUnregister \888Bar.dll|1 ServiceStop Network Monitor ServiceStop cmdService ServiceDisable Network Monitor ServiceDisable cmdService ServiceDelete Network Monitor ServiceDelete cmdService ProcessSuspend \command.exe|0 OptionSetStatus Resetting folder attributes FolderSetAttributes %SYSDIR%|A OptionSetStatus Cleaning registry RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|DNS RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|services32 RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableTaskMgr RegDeleteKey HKLM\SOFTWARE\Classes\CLSID\{11A4CA8C-A8B9-49c2-A6D3-3F64C9EEBAE6} RegDeleteKey HKLM\SOFTWARE\Classes\CLSID\{4F141CBA-1457-6CCA-03A7-7AA21B61EA0F} RegDeleteKey HKLM\SOFTWARE\Classes\CLSID\{6001CDF7-6F45-471b-A203-0225615E35A7} RegDeleteKey HKLM\SOFTWARE\Classes\CLSID\{8253D547-38DD-4325-B35A-F1817EDFA5F5} RegDeleteKey HKLM\SOFTWARE\Classes\CLSID\{8293D547-38DD-4325-B35A-F1817EDFA5FC} RegDeleteKey HKLM\SOFTWARE\Classes\CLSID\{FFF4E223-7019-4ce7-BE03-D7D3C8CCE884} RegDeleteKey HKCU\SOFTWARE\Classes\CLSID\{4F141CBA-1457-6CCA-03A7-7AA21B61EA0F} RegDeleteKey HKCU\SOFTWARE\Classes\CLSID\{6368D1FC-6F5C-4f1b-B164-E67214F678E9} RegDeleteKey HKLM\SOFTWARE\Classes\Interface\{31CA5C07-7F5F-4502-8C77-99A91558ADD0} RegDeleteKey HKLM\SOFTWARE\Classes\TypeLib\{223A26D8-9F91-42F6-8ED3-094B637DE020} RegDeleteKey HKLM\SOFTWARE\Classes\TypeLib\{D4C89C18-B4F3-46A9-8800-E9E7A55AFBD9} RegDeleteKey HKLM\SOFTWARE\Classes\Shorty.Gopher RegDeleteKey HKLM\SOFTWARE\Classes\Shorty.Gopher.1 RegDeleteKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11A4CA8C-A8B9-49c2-A6D3-3F64C9EEBAE6} RegDeleteKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFF4E223-7019-4ce7-BE03-D7D3C8CCE884} RegDeleteKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6001CDF7-6F45-471b-A203-0225615E35A7} RegDeleteKey HKCU\Software\DNS RegDeleteKey HKCU\Software\CAS RegDeleteKey HKLM\SOFTWARE\Classes\SYS RegDeleteKey HKLM\SOFTWARE\Classes\Main.MimeFilter RegDeleteKey HKLM\SOFTWARE\Classes\Main.MimeFilter.1 RegDeleteKey HKCU\Software\Microsoft\drsmartload RegDeleteKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Enhanced Ads by Zeno RegDeleteKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Zeno Search Assistant RegDeleteKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Enhanced Ads by Think-Adz RegDeleteKey HKLM\SOFTWARE\Classes\AppID\Main.DLL RegDeleteKey HKLM\SOFTWARE\Classes\AppID\{E0DC5CC4-25A5-4BC7-A3AA-3525733DC796} RegDelValue HKCU\System\CurrentControlSet\Control\Lsa|p2pnetwork RegDelValue HKLM\System\CurrentControlSet\Control\Lsa|p2pnetwork RegDelValue HKCU\SOFTWARE\Microsoft\OLE|p2pnetwork RegDelValue HKLM\SOFTWARE\Microsoft\OLE|p2pnetwork RegDelValue HKCU\SOFTWARE\Microsoft\OLE|winlog RegDelValue HKLM\SOFTWARE\Microsoft\OLE|winlog RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations|LowRiskFileTypes RegSetDwordValue HKLM\System\CurrentControlSet\Control\Lsa|Restrictanonymous|0 RegSetStringValue HKLM\SOFTWARE\Microsoft\OLE|EnableDCOM|Y RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler|{4F141CBA-1457-6CCA-03A7-7AA21B61EA0F} RegDeleteKey HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensSrv RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad|SysTray.Exbr RegDelValue HKCU\Microsoft\Windows\CurrentVersion\policies\Explorer\Run|WinUpdate.exe RegDeleteKey HKCU\SOFTWARE\FCHelp RegDeleteKey HKCU\SOFTWARE\FCAdvice RegDeleteKey HKCU\Software\PSHope RegDeleteKey HKCU\Software\Batty RegDeleteKey HKCU\Software\Batty2 RegDeleteKey HKCU\Software\PSCloner RegDeleteKey HKCU\Software\CMMan RegDeleteKey HKCR\TypeLib\{1B8B502E-455B-4022-BE77-FB6D9F808A18} RegDeleteKey HKCR\TypeLib\{D4C89C18-B4F3-46A9-8800-E9E7A55AFBD9} RegDeleteKey HKCR\CLSID\{724D478A-2BD0-4DB4-AE42-288B1E346EF7} RegDeleteKey HKCR\CLSID\{994D478A-45D0-4DB4-AE77-288B1E346E99} RegDeleteKey HKCR\CLSID\{994D478A-45D0-4DB4-AE27-738B1E346F99} RegDeleteKey HKCR\CLSID\{994D478A-45D0-4DB4-AE27-738B1E346E99} RegDelValueIfDataContainsText HKCR\PROTOCOLS\Filter\text/html|CLSID|{8253D547-38DD-4325-B35A-F1817EDFA5F5}|0 RegDelValueIfDataContainsText HKCR\PROTOCOLS\Filter\text/html|CLSID|{994D478A-45D0-4DB4-AE77-288B1E346E99}|0 RegDelValueIfDataContainsText HKCR\PROTOCOLS\Filter\text/html|CLSID|{994D478A-45D0-4DB4-AE27-738B1E346F99}|0 RegDelValueIfDataContainsText HKCR\PROTOCOLS\Filter\text/html|*|FCEngine|0 RegDelValueIfDataContainsText HKCR\PROTOCOLS\Filter\text/html|*|PortHope.Decoder|0 RegDelValueIfDataContainsText HKCR\PROTOCOLS\Filter\text/html|*|Batty.Filter|0 RegDeleteKey HKCR\PROTOCOLS\Filter\text/html\SDVita.MimeFilter RegDeleteKey HKCU\SOFTWARE\pecarlin RegDeleteKey HKCU\SOFTWARE\pecarlin aid RegDeleteKey HKCU\SOFTWARE\pecarlin version RegDeleteKey HKUS\S-1-5-18\Software\AdSponsor RegDeleteKey HKUS\.DEFAULT\Software\AdSponsor RegDeleteKey HKUS\S-1-5-18\Software\CMIntex RegDeleteKey HKUS\.DEFAULT\Software\CMIntex RegDeleteKey HKUS\S-1-5-18\Software\CMFibula RegDeleteKey HKUS\.DEFAULT\Software\CMFibula RegDeleteKey HKUS\S-1-5-18\Software\PSDream RegDeleteKey HKUS\.DEFAULT\Software\PSDream RegDeleteKey HKUS\S-1-5-18\Software\PSCloner RegDeleteKey HKUS\.DEFAULT\Software\PSCloner RegDeleteKey HKUS\S-1-5-18\Software\PSCastor RegDeleteKey HKUS\.DEFAULT\Software\PSCastor RegDeleteKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\g5a2 RegDeleteKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\kznbndryg RegDeleteKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S7KqHe RegDeleteKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\treewood RegDeleteKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bnZPtkioj RegDeleteKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\yVMA RegDeleteKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3877c2cd-f137-4144-bdb2-0a811492f920} RegDeleteKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A394E835-C8D6-4B4B-884B-D2709059F3BE} RegDeleteKey HKLM\SOFTWARE\Classes\CLSID\{354b7de0-515d-3eac-e2ab-f68cb54aaac1} RegDeleteKey HKLM\SOFTWARE\Classes\CLSID\{5C3E6596-C64F-48E0-AC1E-B9C6EB3A5915} RegDeleteKey HKLM\SOFTWARE\Classes\CLSID\{624A3CDB-8C0A-4902-8480-191582C8498E} RegDeleteKey HKLM\SOFTWARE\Classes\CLSID\{8711CF54-E9C5-4DB4-9B9F-7D67393CC771} RegDeleteKey HKLM\SOFTWARE\Classes\CLSID\{b5f86455-bf18-4e12-965a-6642a0ac0549} RegDeleteKey HKLM\SOFTWARE\Classes\CLSID\{D5BA18F2-FF61-465F-831D-A6850B94FC01} RegDeleteKey HKLM\SOFTWARE\Classes\CLSID\{E5E2A3E7-00FE-4D31-A030-A10799DDCA66} RegDelValueIfDataContainsText HKCR\PROTOCOLS\Filter\text/html|CLSID|{b5f86455-bf18-4e12-965a-6642a0ac0549}|0 RegDelValueIfDataContainsText HKCR\PROTOCOLS\Filter\text/html|CLSID|{D5BA18F2-FF61-465F-831D-A6850B94FC01}|0 RegDeleteKey HKLM\SOFTWARE\Classes\Interface\{47F2B86D-82A1-44F5-A78B-136AC5496094} RegDeleteKey HKLM\SOFTWARE\Classes\Interface\{522ef89b-532c-4889-b5c5-fbc80236a603} RegDeleteKey HKLM\SOFTWARE\Classes\TypeLib\{4149BDED-AFBC-4CAE-A9E7-92BAC8718D75} RegDeleteKey HKLM\SOFTWARE\Classes\TypeLib\{80c0e6bc-1228-47d7-9876-b67ad181477e} RegDeleteKey HKLM\SOFTWARE\Classes\TypeLib\{90AFF1EF-C901-4991-8D61-5BEEA455E090} RegDeleteKey HKLM\SOFTWARE\Classes\xsdu.bqok RegDeleteKey HKLM\SOFTWARE\Classes\xsdu.bqok.1 RegDeleteKey HKLM\SOFTWARE\Classes\xsdu.ozbyq RegDeleteKey HKLM\SOFTWARE\Classes\xsdu.ozbyq.1 RegDeleteKey HKLM\SOFTWARE\Fseytdc.Ariaqudok RegDeleteKey HKLM\SOFTWARE\Fseytdc.Ariaqudok.1 RegDeleteKey HKLM\SOFTWARE\Fseytdc.Yvakt RegDeleteKey HKLM\SOFTWARE\Fseytdc.Yvakt.1 RegDeleteKey HKLM\SOFTWARE\Iyrruaq.Givymmqxm RegDeleteKey HKLM\SOFTWARE\Iyrruaq.Givymmqxm.1 RegDeleteKey HKLM\SOFTWARE\Iyrruaq.Vdrw RegDeleteKey HKLM\SOFTWARE\Iyrruaq.Vdrw.1 RegDeleteKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{354b7de0-515d-3eac-e2ab-f68cb54aaac1} RegDeleteKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8711CF54-E9C5-4DB4-9B9F-7D67393CC771} RegDeleteKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d623bc2f-a58d-4a75-a10d-cc244a702a35} RegDeleteKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e5e2a3e7-00fe-4d31-a030-a10799ddca66} RegDeleteKey HKCR\DBTB00001.DBTB00001 RegDeleteKey HKCR\DBTB00001.DBTB00001.1 RegDeleteKey HKCR\DBTB00001.DeskBar RegDeleteKey HKCR\DBTB00001.DeskBar.1 RegDeleteKey HKCR\DBTB00001.deskbarBHO RegDeleteKey HKCR\DBTB00001.deskbarBHO.1 RegDeleteKey HKCR\DBTB00001.DeskbarEnabler RegDeleteKey HKCR\DBTB00001.DeskbarEnabler.1 RegDeleteKey HKCR\CLSID\{A8B28872-3324-4CD2-8AA3-7D555C872D96} RegDeleteKey HKCR\CLSID\{D7CC80D4-376C-4586-B023-4F35C2CEB28E} RegDeleteKey HKCR\CLSID\{D8C2D4B4-EEAF-4EC4-B1F8-9B6ED15D5A38} RegDeleteKey HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D} RegDeleteKey HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C} RegDeleteKey HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108} RegDeleteKey HKCR\TypeLib\{A4C8F181-6CDB-4DCC-9FC9-BB9933C81E1F} RegDeleteKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A8B28872-3324-4CD2-8AA3-7D555C872D96} RegDeleteKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DBTB00001.DBTB00001Deskbar RegDeleteKey HKCU\Software\DBTB00001 RegDelValue HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{A8B28872-3324-4CD2-8AA3-7D555C872D96} RegSetDwordValue HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN|iexplore.exe|1 RegDeleteKey HKCR\AMNotifier.HUBAWindow RegDeleteKey HKCR\AMNotifier.HUBAWindow.1 RegDeleteKey HKCR\MediaPipe.GUI RegDeleteKey HKCR\MediaPipe.GUI.1 RegDeleteKey HKCR\SP2P.SP2P RegDeleteKey HKCR\SP2P.SP2P.1 RegDeleteKey HKCR\MPAgent.Agent RegDeleteKey HKCR\MPAgent.Agent.1 RegDeleteKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\itbill RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\p2pnetworks RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\MediaPipe RegDeleteKey HKLM\SOFTWARE\itbill RegDeleteKey HKLM\SOFTWARE\MediaPipe RegDeleteKey HKCR\AppID\MediaPipe.EXE RegDeleteKey HKCR\AppID\{9236268D-8B29-49E5-96D9-DAF5FE76941C} RegDeleteKey HKCR\AppID\DownloadManager.EXE RegDeleteKey HKCR\AppID\{99C4F93D-42A7-478D-8746-4AFB6C10BC26} RegDeleteKey HKCR\AppID\SP2P.EXE RegDeleteKey HKCR\AppID\{626873AC-27F3-4D48-BE81-535CF2360071} RegDeleteKey HKCR\AppID\TrayIcon.EXE RegDeleteKey HKCR\AppID\{4C0B0548-AE0B-4008-999D-DB33B8B2EB90} RegDeleteKey HKCR\AppID\MPAgent.DLL RegDeleteKey HKCR\AppID\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D} RegDeleteKey HKCR\CLSID\{1E9ADAF2-4EDA-4074-96CE-C9972E675C88} RegDeleteKey HKCR\CLSID\{48BB16AA-3F6C-4B28-9884-1FCEC1C5DA65} RegDeleteKey HKCR\CLSID\{7BF58804-E672-4B96-8EEC-BFCCE6492C9A} RegDeleteKey HKCR\CLSID\{B3E19860-0CD5-4991-A066-4FCA2704DE59} RegDeleteKey HKCR\CLSID\{DFE95408-FD86-4818-A30A-BC859D9658E1} RegDeleteKey HKCR\Interface\{1A7BCC8E-B65D-409A-BB67-57E8226D1780} RegDeleteKey HKCR\Interface\{8E33F539-11BC-44E5-80BF-057FA1E511A6} RegDeleteKey HKCR\Interface\{9A395C6C-E42E-4777-B8EF-FDDEB705F3FB} RegDeleteKey HKCR\Interface\{AFE46CDD-00CE-45EE-BB73-8349D624F7AF} RegDeleteKey HKCR\Interface\{DE2BF8DA-A159-4758-8199-0B2435268212} RegDeleteKey HKCR\TypeLib\{45C2360E-BFDF-439B-A3EA-65E8383F9353} RegDeleteKey HKCR\TypeLib\{555FB512-9F3B-4359-9D2A-3C10E750CE5E} RegDeleteKey HKCR\TypeLib\{97D860C4-F072-477B-B241-409F7CFFB954} RegDeleteKey HKCR\TypeLib\{AB3B59A5-8BB4-46AB-A878-DFDB237D5BD5} RegDeleteKey HKCR\TypeLib\{CCEBBEB5-D011-41B5-9F92-01F88A38DC0D} RegDeleteKey HKCR\clsid\{E055C02E-6258-40FF-80A7-3BDA52FACAD7} RegDeleteKey HKCR\clsid\{cbcc61fa-0221-4ccc-b409-cee865caca3a} RegDeleteKey HKCR\clsid\{C004DEC2-2623-438E-9CA2-C9043AB28508} RegDeleteKey HKCR\interface\{c6f2214e-0b54-45a9-b90d-7dd4ba45ed0b} RegDeleteKey HKCR\typelib\{569304ba-83ed-4cff-ac26-be3e482f7208} RegDelValue HKCU\software\microsoft\internet explorer\toolbar\webbrowser|{cbcc61fa-0221-4ccc-b409-cee865caca3a} RegDelValue HKCU\software\microsoft\windows\currentversion\policies\explorer\run|{84c4d3ae-0bb0-1033-0729-050001} RegDelValue HKLM\software\microsoft\internet explorer\toolbar|{cbcc61fa-0221-4ccc-b409-cee865caca3a} RegDelValue HKLM\software\microsoft\internet explorer\toolbar|{C004DEC2-2623-438e-9CA2-C9043AB28508} RegDelValue HKLM\software\microsoft\internet explorer\toolbar|{77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} RegDelValue HKLM\software\microsoft\internet explorer\toolbar|{0E1230F8-EA50-42A9-983C-D22ABC2EED3B} RegDeleteKey HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\{cbcc61fa-0221-4ccc-b409-cee865caca3a} RegDeleteKey HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\{C004DEC2-2623-438e-9CA2-C9043AB28508} RegDeleteKey HKLM\software\microsoft\windows\currentversion\uninstall\toolbar888 RegDeleteKey HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\888Bar RegDeleteKey HKCU\Software\Microsoft\Internet Explorer\MenuExt\&MyToolBar Search RegDeleteKey HKCR\MyToolBar.MyToolBarObj.1 RegDeleteKey HKCR\MyToolBar.MyToolBarObj RegDeleteKey HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1EB17D1C-141D-4D9D-91CB-24D99215851D} RegSetDwordValue HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1EB17D1C-141D-4D9D-91CB-24D99215851D}|Compatibility Flags|1024 RegDeleteKey HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\{04CDB16C-AB38-43CD-A86A-6FEB90290939} RegDeleteKey HKCR\clsid\{04CDB16C-AB38-43CD-A86A-6FEB90290939} RegDeleteKey HKCR\Bho_html.edit_html.1 RegDeleteKey HKCR\Bho_html.edit_html RegDeleteKey HKCR\CLSID\{14D1A72D-8705-11D8-B120-0040F46CB696} RegDeleteKey HKCR\TypeLib\{14D1A720-8705-11D8-B120-0040F46CB696} RegDeleteKey HKCR\Interface\{14D1A72C-8705-11D8-B120-0040F46CB696} RegDeleteKey HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\{14D1A720-8705-11D8-B120-0040F46CB696} RegDeleteKey HKCU\Software\fid\keys RegDeleteKey HKCU\Software\fid\vars OptionSetStatus Deleting Runkeys RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|MsConfigs RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|p2pnetwork RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|winupdates RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|winupdate RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|winsupdater RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|MsUpdate RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|ms-update RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|MsMovies RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|p2pnetworking RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|virtual-ie RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|MS DATABASE RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|xp RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|wmplayer RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|winlog RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|outlook RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|winsysupd RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|gimmygames RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|winsysban RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|TheMonitor RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|gimmysmileys RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|keyboard RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|mousepad RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|newname RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|IpNetwork RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|CU1 RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|CU2 RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|NewFrn RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|BrowserUpdateSched RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Command RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|xp_system RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|errorhandler RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|sysvx RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|PayTime RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|q8lg RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|WinTask driver RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|expload.exe RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|tetriz3 RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Microsoft standard protector RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|rmalt RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|eventwvr RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Keygen RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|IpWins RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|defender RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Configuration Manager RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|WinSys RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|pop06apelt RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|winrnt.exe RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|ad8rIU3s RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|k6mmN5IOU RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|wGzyM6F48 RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|epy9J RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|truetype RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|0mcamcap RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|ACTX1 RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|xload RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|ExploreUpdSched RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|septpop06apsept RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|MediaPipe P2P Loader RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Notification Utility RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|mysvcig38 RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|explorer RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|1pop06apelt2 RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|adstart RegDelValue HKLM\software\microsoft\windows\currentversion\Run|psdream RegDelValue HKLM\software\microsoft\windows\currentversion\Run|psguard RegDelValue HKLM\software\microsoft\windows\currentversion\Run|windows RegDelValue HKLM\software\microsoft\windows\currentversion\Run|csrss RegDelValue HKLM\software\microsoft\windows\currentversion\Run|snapbanner RegDelValue HKLM\software\microsoft\windows\currentversion\Run|timessquare RegDelValue HKLM\software\microsoft\windows\currentversion\Run|sixtysix RegDelValue HKLM\software\microsoft\windows\currentversion\Run|{ZN} RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|g4356cbvy63 RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|p2p networking RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices|CU1 RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices|CU2 RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices|services32 RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|CU1 RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|CU2 RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|newfrn.exe RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|services32 RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|xp_system RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|EQAdvice RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Windows installer RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|tetriz3 RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Windows update loader RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Abrada WIN32 RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|eventwvr RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|EQBranch RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|pecarlin RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|AXVenore RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|EQArticle RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|truetype RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|0mcamcap RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|PSHope RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|AXFibula RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|CMFibula RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|PSLister RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|PSCloner RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|cprocsvc RegDelValue HKCU\software\microsoft\windows\currentversion\Run|psdream RegDelValue HKCU\software\microsoft\windows\currentversion\Run|PSCastor RegDelValue HKCU\software\microsoft\windows\currentversion\Run|CMIntex RegDelValue HKCU\software\microsoft\windows\currentversion\Run|ttool RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices|p2pnetwork RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices|ms-update RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices|p2pnetworking RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices|p2p networking RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices|virtual-ie RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices|MS DATABASE RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices|xp RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices|winlog RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices|wmplayer RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices|tetriz3 RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices|CQ4d6 RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices|SystemTools RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices|eventwvr RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices|truetype RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices|0mcamcap RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices|mysvcig38 RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices|drpXPd RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|CQ4d6 RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|gjZC2XV RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|ula0U RegDelValue HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|System RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|MsConfigs RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|p2pnetwork RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|winupdates RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|winupdate RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|MS DATABASE RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|xp RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|WinMedia RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Shell RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Key RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|CAS Client RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|CAS2 RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|sys_up1 OptionSetStatus Deleting files FileDelete %PROGRAMFILES%\Deskbar\deskbar.dll FileDelete %WINDIR%\DH.dll OptionPauseBetweenCmds 300 FileDelete %SYSDIR%\p2pnetwork.exe FileDelete %SYSDIR%\scvhost.exe FileDelete %SYSDIR%\winlog.exe FileDelete %SYSDIR%\p2pnetworking.exe FileDelete %SYSDIR%\winlogi.exe FileDelete %SYSDIR%\MSDATA32.EXE FileDelete %WINDIR%\scvhost.exe FileDelete %SYSDIR%\mc-*-*.exe FileDelete %ALLUSERSSTARTUP%\wmplayer.exe FileDelete %ALLUSERSSTARTUP%\svchost.ex* FileDelete %ALLUSERSSTARTUP%\msconfig.ex* FileDelete %ALLUSERSSTARTUP%\taskmgr.ex* FileDelete %ALLUSERSSTARTUP%\dllhost.ex* OptionPauseBetweenCmds 50 FolderDelete %PROGRAMFILES%\MsConfigs FolderDelete %PROGRAMFILES%\winupdates FolderDelete %PROGRAMFILES%\winupdate FolderDelete %PROGRAMFILES%\winsupdater FolderDelete %PROGRAMFILES%\MsUpdate FolderDelete %PROGRAMFILES%\MsMovies FolderDelete %PROGRAMFILES%\wmplayer FolderDelete %PROGRAMFILES%\outlook FileDelete %SYSTEMDRIVE%\temp.zip FileDelete %SYSTEMDRIVE%\a.zip FileDelete %SYSTEMDRIVE%\x.txt FileDelete %SYSTEMDRIVE%\z.txt FileDelete %SYSTEMDRIVE%\s.tmp FileDelete %SYSTEMDRIVE%\z.tmp FileDelete %SYSTEMDRIVE%\xz.exe FileDelete %SYSTEMDRIVE%\cmon.exe FileDelete %SYSTEMDRIVE%\at.exe OptionSetStatus Deleting files Adware.Agent FileDelete %PROGRAMFILES%\Common Files\Windows\services32.exe FileDelete %PROGRAMFILES%\Common Files\services.exe FileDelete %PROGRAMFILES%\Common Files\mc-*-*.exe FileDelete %PROGRAMFILES%\Common Files\Windows\mc-*-*.exe FileDelete %PROGRAMFILES%\Common Files\Download\mc-*-*.exe FileDelete %WINDIR%\mc-*-*.exe FileDelete %PROGRAMFILES%\Windows\WinUpdate.exe FileDelete %PROGRAMFILES%\Windows\wWinUpdate.exe FileDelete %MYDOCUMENTS%\mc-*-*.exe FileDelete %SYSTEMDRIVE%\mc-*-*.exe FileDelete %WINDIR%\csvhost.exe FileDelete %MYDOCUMENTS%\Xinstall.exe FileDelete %MYDOCUMENTS%\Yinstall.exe FileDelete %UserProfile%\winstall.exe FileDelete %USERPROFILE%\Xinstall.exe FileDelete %USERPROFILE%\Yinstall.exe FileDelete %PROGRAMFILES%\Common Files\Download\freeprodtb.exe FileDelete %PROGRAMFILES%\Common Files\system32.dll FileDelete %PROGRAMFILES%\paytime.exe FileDelete %UserProfile%\local settings\temp\dxcupdater3.exe FileDelete %UserProfile%\local settings\temp\dxcupdater3*.exe FileDelete %PROGRAMFILES%\Common Files\Yazzle1670OinAdmin.exe FileDelete %PROGRAMFILES%\Common Files\Yazzle*Admin.exe FolderDelete %SYSDIR%\nstlr OptionSetStatus Deleting files Toolbar888 FileDelete %PROGRAMFILES%\common files\{*-*-1033-*-*}\update.exe FileDelete %PROGRAMFILES%\common files\{*-*-1033-*-*}\services.dll FileDelete %PROGRAMFILES%\common files\{*-*-1033-*-*}\activate.exe FileDelete %PROGRAMFILES%\common files\{*-*-1033-*-*}\MyToolBar.dll FileDelete %PROGRAMFILES%\common files\{*-*-2057-*-*}\update.exe FileDelete %PROGRAMFILES%\common files\{*-*-2057-*-*}\services.dll FileDelete %PROGRAMFILES%\common files\{*-*-2057-*-*}\activate.exe FileDelete %PROGRAMFILES%\common files\{*-*-2057-*-*}\MyToolBar.dll FolderDelete %PROGRAMFILES%\toolbar888 FolderDelete %PROGRAMFILES%\e-mailpaysu toolbar FolderDelete %PROGRAMFILES%\EMUSIC TOOLBAR FolderDelete %PROGRAMFILES%\find dvd toolbar FolderDelete %PROGRAMFILES%\GULESIDER VERKTøYLINJE FolderDelete %PROGRAMFILES%\sesam-p4 toolbar FolderDelete %PROGRAMFILES%\slownik ling OptionSetStatus Deleting files drsmartload windir FileDelete %WINDIR%\newfrn.exe FileDelete %WINDIR%\errorhandler.exe FileDelete %WINDIR%\wallpap.exe FileDelete %WINDIR%\eee2.exe FileDelete %WINDIR%\DH.dll_ FileDelete %WINDIR%\dh.ini FileDelete %WINDIR%\SYSC00.exe FileDelete %WINDIR%\SYSC0*.exe FileDelete %WINDIR%\CheckS00.exe FileDelete %WINDIR%\CheckS01.exe FileDelete %WINDIR%\CheckS02.exe FileDelete %WINDIR%\CheckS0*.exe FileDelete %WINDIR%\drsmartload*.dat FileDelete %WINDIR%\sysvx_.exe FileDelete %WINDIR%\newname.dat FileDelete %WINDIR%\newname*.dat FileDelete %WINDIR%\newname.exe FileDelete %WINDIR%\newname4.exe FileDelete %WINDIR%\newname5.exe FileDelete %WINDIR%\newname6.exe FileDelete %WINDIR%\newname7.exe FileDelete %WINDIR%\newname8.exe FileDelete %WINDIR%\newname9.exe FileDelete %WINDIR%\newname10.exe FileDelete %WINDIR%\newname11.exe FileDelete %WINDIR%\newname12.exe FileDelete %WINDIR%\newname13.exe FileDelete %WINDIR%\newname14.exe FileDelete %WINDIR%\newname15.exe FileDelete %WINDIR%\newname16.exe FileDelete %WINDIR%\newname17.exe FileDelete %WINDIR%\newname18.exe FileDelete %WINDIR%\newname*.exe FileDelete %WINDIR%\keyboard.dat FileDelete %WINDIR%\keyboard*.dat FileDelete %WINDIR%\keyboard3.exe FileDelete %WINDIR%\keyboard4.exe FileDelete %WINDIR%\keyboard5.exe FileDelete %WINDIR%\keyboard6.exe FileDelete %WINDIR%\keyboard7.exe FileDelete %WINDIR%\keyboard8.exe FileDelete %WINDIR%\keyboard9.exe FileDelete %WINDIR%\keyboard10.exe FileDelete %WINDIR%\keyboard11.exe FileDelete %WINDIR%\keyboard12.exe FileDelete %WINDIR%\keyboard13.exe FileDelete %WINDIR%\keyboard14.exe FileDelete %WINDIR%\keyboard15.exe FileDelete %WINDIR%\keyboard16.exe FileDelete %WINDIR%\keyboard17.exe FileDelete %WINDIR%\keyboard18.exe FileDelete %WINDIR%\keyboard*.exe FileDelete %WINDIR%\mousepad.dat FileDelete %WINDIR%\mousepad*.dat FileDelete %WINDIR%\mousepad3.exe FileDelete %WINDIR%\mousepad4.exe FileDelete %WINDIR%\mousepad5.exe FileDelete %WINDIR%\mousepad6.exe FileDelete %WINDIR%\mousepad7.exe FileDelete %WINDIR%\mousepad8.exe FileDelete %WINDIR%\mousepad9.exe FileDelete %WINDIR%\mousepad10.exe FileDelete %WINDIR%\mousepad11.exe FileDelete %WINDIR%\mousepad12.exe FileDelete %WINDIR%\mousepad13.exe FileDelete %WINDIR%\mousepad14.exe FileDelete %WINDIR%\mousepad15.exe FileDelete %WINDIR%\mousepad16.exe FileDelete %WINDIR%\mousepad17.exe FileDelete %WINDIR%\mousepad18.exe FileDelete %WINDIR%\mousepad*.exe FileDelete %WINDIR%\winsysupd*.exe FileDelete %WINDIR%\winsysupd*.dat FileDelete %WINDIR%\winsysban*.exe FileDelete %WINDIR%\gimmygames.exe FileDelete %WINDIR%\gimmygames*.exe FileDelete %WINDIR%\gimmygames.dat FileDelete %WINDIR%\uninstall_nmon.vbs FileDelete %WINDIR%\xpupdate.exe FileDelete %WINDIR%\system.exe FileDelete %WINDIR%\cfg32.exe FileDelete %WINDIR%\cfg32a.exe FileDelete %WINDIR%\thiselt.exe FileDelete %WINDIR%\drsmartload*.exe FileDelete %WINDIR%\system32bez6n4r21.exe FileDelete %WINDIR%\system32ghynf.exe FileDelete %WINDIR%\system32n9nyb.exe FileDelete %WINDIR%\system32ftuninst.exe FileDelete %WINDIR%\system32ssec.exe FileDelete %WINDIR%\system32tfthot.exe FileDelete %WINDIR%\system32afdaqd3.exe FileDelete %WINDIR%\system32cymmh.exe FileDelete %WINDIR%\system32y3aqsoepa.exe FileDelete %WINDIR%\CCZoop05.exe FileDelete %WINDIR%\v1201.exe FileDelete %WINDIR%\Duce6.exe FileDelete %WINDIR%\xload.exe FileDelete %WINDIR%\elitepop06.exe FileDelete %WINDIR%\ac3_00*.exe FileDelete %WINDIR%\uni_e6h.exe FileDelete %WINDIR%\svcs.exe FileDelete %WINDIR%\9129837.exe FileDelete %WINDIR%\teller2.chk FileDelete %WINDIR%\offun.exe FileDelete %WINDIR%\tielt001.exe FileDelete %WINDIR%\timessquare.exe FileDelete %WINDIR%\adtech2005.exe FileDelete %WINDIR%\adtech2006.exe FileDelete %WINDIR%\sixtypopsix.exe FileDelete %WINDIR%\g4356cbvy63.exe FileDelete %WINDIR%\TISKY00*.exe OptionSetStatus Deleting files drsmartload rootdir FileDelete %SYSTEMDRIVE%\drsmartload.exe FileDelete %SYSTEMDRIVE%\drsmartload1.exe FileDelete %SYSTEMDRIVE%\drsmartload46a.exe FileDelete %SYSTEMDRIVE%\drsmartload45a.exe FileDelete %SYSTEMDRIVE%\drsmartload1135a.exe FileDelete %SYSTEMDRIVE%\drsmartload618a.exe FileDelete %SYSTEMDRIVE%\drsmartload117a.exe FileDelete %SYSTEMDRIVE%\drsmartload849a.exe FileDelete %SYSTEMDRIVE%\drsmartload45a45a45s.exe FileDelete %SYSTEMDRIVE%\drsmartload44a.exe FileDelete %SYSTEMDRIVE%\drsmartload*.exe FileDelete %SYSTEMDRIVE%\mte3ndi6odoxng.exe FileDelete %SYSTEMDRIVE%\stub_113_*.exe FileDelete %SYSTEMDRIVE%\winstall.exe FileDelete %SYSTEMDRIVE%\Veracruz.exe FileDelete %SYSTEMDRIVE%\WHCC2.exe FileDelete %SYSTEMDRIVE%\winsysban.exe FileDelete %SYSTEMDRIVE%\winsysban1.exe FileDelete %SYSTEMDRIVE%\winsysban2.exe FileDelete %SYSTEMDRIVE%\winsysban3.exe FileDelete %SYSTEMDRIVE%\winsysban4.exe FileDelete %SYSTEMDRIVE%\winsysban5.exe FileDelete %SYSTEMDRIVE%\winsysban6.exe FileDelete %SYSTEMDRIVE%\winsysban7.exe FileDelete %SYSTEMDRIVE%\winsysban8.exe FileDelete %SYSTEMDRIVE%\winsysban9.exe FileDelete %SYSTEMDRIVE%\winsysban10.exe FileDelete %SYSTEMDRIVE%\winsysban11.exe FileDelete %SYSTEMDRIVE%\winsysban12.exe FileDelete %SYSTEMDRIVE%\winsysban*.exe FileDelete %SYSTEMDRIVE%\winsysupd.exe FileDelete %SYSTEMDRIVE%\winsysupd1.exe FileDelete %SYSTEMDRIVE%\winsysupd2.exe FileDelete %SYSTEMDRIVE%\winsysupd3.exe FileDelete %SYSTEMDRIVE%\winsysupd4.exe FileDelete %SYSTEMDRIVE%\winsysupd5.exe FileDelete %SYSTEMDRIVE%\winsysupd6.exe FileDelete %SYSTEMDRIVE%\winsysupd7.exe FileDelete %SYSTEMDRIVE%\winsysupd8.exe FileDelete %SYSTEMDRIVE%\winsysupd9.exe FileDelete %SYSTEMDRIVE%\winsysupd10.exe FileDelete %SYSTEMDRIVE%\winsysupd11.exe FileDelete %SYSTEMDRIVE%\winsysupd12.exe FileDelete %SYSTEMDRIVE%\winsysupd*.exe FileDelete %SYSTEMDRIVE%\enewsletterpro.exe FileDelete %SYSTEMDRIVE%\gimmygames.exe FileDelete %SYSTEMDRIVE%\gimmygames1.exe FileDelete %SYSTEMDRIVE%\gimmygames2.exe FileDelete %SYSTEMDRIVE%\gimmygames3.exe FileDelete %SYSTEMDRIVE%\gimmygames4.exe FileDelete %SYSTEMDRIVE%\gimmygames5.exe FileDelete %SYSTEMDRIVE%\gimmygames6.exe FileDelete %SYSTEMDRIVE%\gimmygames7.exe FileDelete %SYSTEMDRIVE%\gimmygames8.exe FileDelete %SYSTEMDRIVE%\gimmygames9.exe FileDelete %SYSTEMDRIVE%\gimmygames10.exe FileDelete %SYSTEMDRIVE%\gimmygames11.exe FileDelete %SYSTEMDRIVE%\gimmygames12.exe FileDelete %SYSTEMDRIVE%\gimmygames*.exe FileDelete %SYSTEMDRIVE%\gimmysmileys.exe FileDelete %SYSTEMDRIVE%\gimmysmileys1.exe FileDelete %SYSTEMDRIVE%\gimmysmileys2.exe FileDelete %SYSTEMDRIVE%\gimmysmileys*.exe FileDelete %SYSTEMDRIVE%\myupdates.exe FileDelete %SYSTEMDRIVE%\keyboard.exe FileDelete %SYSTEMDRIVE%\keyboard1.exe FileDelete %SYSTEMDRIVE%\keyboard2.exe FileDelete %SYSTEMDRIVE%\keyboard3.exe FileDelete %SYSTEMDRIVE%\keyboard17.exe FileDelete %SYSTEMDRIVE%\keyboard18.exe FileDelete %SYSTEMDRIVE%\keyboard19.exe FileDelete %SYSTEMDRIVE%\keyboard20.exe FileDelete %SYSTEMDRIVE%\keyboard21.exe FileDelete %SYSTEMDRIVE%\keyboard22.exe FileDelete %SYSTEMDRIVE%\keyboard23.exe FileDelete %SYSTEMDRIVE%\keyboard24.exe FileDelete %SYSTEMDRIVE%\keyboard25.exe FileDelete %SYSTEMDRIVE%\keyboard*.exe FileDelete %SYSTEMDRIVE%\mousepad.exe FileDelete %SYSTEMDRIVE%\mousepad1.exe FileDelete %SYSTEMDRIVE%\mousepad2.exe FileDelete %SYSTEMDRIVE%\mousepad3.exe FileDelete %SYSTEMDRIVE%\mousepad17.exe FileDelete %SYSTEMDRIVE%\mousepad18.exe FileDelete %SYSTEMDRIVE%\mousepad*.exe FileDelete %SYSTEMDRIVE%\newname.exe FileDelete %SYSTEMDRIVE%\newname1.exe FileDelete %SYSTEMDRIVE%\newname2.exe FileDelete %SYSTEMDRIVE%\newname3.exe FileDelete %SYSTEMDRIVE%\newname17.exe FileDelete %SYSTEMDRIVE%\newname18.exe FileDelete %SYSTEMDRIVE%\newname19.exe FileDelete %SYSTEMDRIVE%\newname20.exe FileDelete %SYSTEMDRIVE%\newname21.exe FileDelete %SYSTEMDRIVE%\newname22.exe FileDelete %SYSTEMDRIVE%\newname23.exe FileDelete %SYSTEMDRIVE%\newname24.exe FileDelete %SYSTEMDRIVE%\newname25.exe FileDelete %SYSTEMDRIVE%\newname*.exe FileDelete %SYSTEMDRIVE%\defender1.exe FileDelete %SYSTEMDRIVE%\defender19a.exe FileDelete %SYSTEMDRIVE%\defender20.exe FileDelete %SYSTEMDRIVE%\defender21.exe FileDelete %SYSTEMDRIVE%\defender22.exe FileDelete %SYSTEMDRIVE%\defender23.exe FileDelete %SYSTEMDRIVE%\defender23a.exe FileDelete %SYSTEMDRIVE%\defender24.exe FileDelete %SYSTEMDRIVE%\defender25.exe FileDelete %SYSTEMDRIVE%\defender26.exe FileDelete %SYSTEMDRIVE%\defender*.exe FileDelete %SYSTEMDRIVE%\dfndrff_e_uit.exe FileDelete %SYSTEMDRIVE%\nwnm*.exe FileDelete %SYSTEMDRIVE%\kybrd*.exe FileDelete %SYSTEMDRIVE%\dfndr*.exe FileDelete %SYSTEMDRIVE%\tool.exe FileDelete %SYSTEMDRIVE%\tool1.exe FileDelete %SYSTEMDRIVE%\tool2.exe FileDelete %SYSTEMDRIVE%\tool3.exe FileDelete %SYSTEMDRIVE%\tool4.exe FileDelete %SYSTEMDRIVE%\tool5.exe FileDelete %SYSTEMDRIVE%\toolbar.exe FileDelete %SYSTEMDRIVE%\country.exe FileDelete %SYSTEMDRIVE%\WindowsOS.exe FileDelete %SYSTEMDRIVE%\kl1.exe FileDelete %SYSTEMDRIVE%\ms1.exe FileDelete %SYSTEMDRIVE%\kl02.exe FileDelete %SYSTEMDRIVE%\sk02.exe FileDelete %SYSTEMDRIVE%\SnowballWarsInstaller.exe FileDelete %SYSTEMDRIVE%\warebundle.exe FileDelete %SYSTEMDRIVE%\warebundlenewer.exe FileDelete %SYSTEMDRIVE%\MTE3NDI6ODoxNgnew.exe FileDelete %SYSTEMDRIVE%\deskbar*.exe FileDelete %SYSTEMDRIVE%\ac2_00*.exe FileDelete %SYSTEMDRIVE%\ac3_00*.exe FileDelete %SYSTEMDRIVE%\Installer3.exe FileDelete %SYSTEMDRIVE%\Installer4.exe FileDelete %SYSTEMDRIVE%\ucmoreiex.exe FileDelete %SYSTEMDRIVE%\Xinstall.exe FileDelete %SYSTEMDRIVE%\Yinstall.exe FileDelete %SYSTEMDRIVE%\mt-uninstaller.exe FileDelete %SYSTEMDRIVE%\doc.exe FileDelete %SYSTEMDRIVE%\installerwnusnewer.exe FileDelete %SYSTEMDRIVE%\DXC9.exe FileDelete %SYSTEMDRIVE%\RDFX4.exe FileDelete %SYSTEMDRIVE%\yz02.exe FileDelete %SYSTEMDRIVE%\mpnaaq7.exe FileDelete %SYSTEMDRIVE%\jsetup.exe FileDelete %SYSTEMDRIVE%\wsetup.exe FileDelete %SYSTEMDRIVE%\vsetup.exe FileDelete %SYSTEMDRIVE%\TIGEN001.exe FileDelete %SYSTEMDRIVE%\sudoku_setup.exe FileDeleteIfMD5Match %SYSTEMDRIVE%\Installer.exe|242A20BAE9CF9CB816A447150378C02D FileDeleteIfMD5Match %SYSTEMDRIVE%\se.exe|f564eefb837fa523ab90a13c2636a9b4 OptionSetStatus Deleting files Trojan.Abrada sysdir FileDelete %SYSDIR%\winserver.exe FileDelete %SYSDIR%\winserv.dll FileDelete %SYSDIR%\winserv32.dll FileDelete %SYSDIR%\winserv.ini FileDelete %SYSDIR%\winserv.dat FileDelete %SYSDIR%\perflibs_.dat FileDelete %SYSDIR%\abrada.exe FileDelete %SYSDIR%\abrada*.exe FileDelete %SYSDIR%\abrada.dat FileDelete %SYSDIR%\abrada*.dat FileDelete %SYSDIR%\abrada.ini FileDelete %SYSDIR%\abrada*.ini FileDelete %SYSDIR%\abradal.dll FileDelete %SYSDIR%\abrada*.dll FileDelete %SYSDIR%\abradaload.dll OptionSetStatus Deleting files Movieland FolderDelete %PROGRAMFILES%\MediaPipe FolderDelete %PROGRAMFILES%\p2pnetworks FileDelete %ProgramFiles%\DownloadManager\Agent.dll FileDelete %ProgramFiles%\DownloadManager\MPUpdate.exe FileDelete %ProgramFiles%\DownloadManager\api.exe FileDelete %ProgramFiles%\DownloadManager\insdl.dll FileDelete %ProgramFiles%\DownloadManager\MPTray.exe FileDelete %ProgramFiles%\DownloadManager\p2pinst.exe FileDelete %ProgramFiles%\DownloadManager\p2pl.exe FileDelete %DESKTOP%\MovieLand Terms.lnk FileDelete %DESKTOP%\Movieland.url FileDelete %PROGRAMS%\DownloadManager.lnk OptionSetStatus Deleting files drsmartload sysdir FileDelete %SYSDIR%\rjdsrego.exe FileDelete %SYSDIR%\qwinksap.exe FileDelete %SYSDIR%\qwinkrag.exe FileDelete %SYSDIR%\qwinsrag.exe FileDelete %SYSDIR%\dwdsregt.exe FileDelete %SYSDIR%\swinmsap.exe FileDelete %SYSDIR%\ysys*.exe FileDelete %SYSDIR%\child.dll FileDelete %SYSDIR%\sysvx.exe FileDelete %SYSDIR%\comdlg64.dll FileDelete %SYSDIR%\whitevx.lst FileDelete %SYSDIR%\paytime.exe FileDelete %SYSDIR%\vxgame1.exe FileDelete %SYSDIR%\vxgame2.exe FileDelete %SYSDIR%\vxgame3.exe FileDelete %SYSDIR%\vxgame4.exe FileDelete %SYSDIR%\vxgame6.exe FileDelete %SYSDIR%\vxgamet1.exe FileDelete %SYSDIR%\vxgamet2.exe FileDelete %SYSDIR%\vxgamet3.exe FileDelete %SYSDIR%\vxgamet4.exe FileDelete %SYSDIR%\mssearchnet.exe FileDelete %SYSDIR%\wintask.exe FileDelete %SYSDIR%\tetriz3.exe FileDelete %SYSDIR%\ad.html FileDelete %SYSDIR%\slk8x2peu.exe FileDelete %SYSDIR%\e6tw76cpw.exe FileDelete %SYSDIR%\parad.raw.exe FileDelete %SYSDIR%\SudokuInstaller.exe FileDelete %SYSDIR%\kernels*.exe FileDelete %SYSDIR%\bin29a.log FileDelete %SYSDIR%\WinSys.exe FileDelete %SYSDIR%\drsmartload815a.exe FileDelete %SYSDIR%\drsmartload*.exe FileDelete %SYSDIR%\Setup94.exe FileDelete %SYSDIR%\FT_SilentSudokuInstaller.exe FileDelete %SYSDIR%\winrnt.exe FileDelete %SYSDIR%\cvn0.exe FileDelete %SYSDIR%\wfxqhv.exe FileDelete %SYSDIR%\zqskw.exe FileDelete %SYSDIR%\bez6n4r21.exe FileDelete %SYSDIR%\ghynf.exe FileDelete %SYSDIR%\iqqr.exe FileDelete %SYSDIR%\n9nyb.exe FileDelete %SYSDIR%\pixk5gp2.phy FileDelete %SYSDIR%\xeymi.dll FileDelete %SYSDIR%\hfkpmu.dll FileDelete %SYSDIR%\ftuninst.exe FileDelete %SYSDIR%\gbe90qs.exe FileDelete %SYSDIR%\jiub5f27y.hhy FileDelete %SYSDIR%\mptft.exe FileDelete %SYSDIR%\nr1rnqm8.exe FileDelete %SYSDIR%\ssec.exe FileDelete %SYSDIR%\ssn6tuu.exe FileDelete %SYSDIR%\tfthot.exe FileDelete %SYSDIR%\x3cqp0.dll FileDelete %SYSDIR%\afdaqd3.exe FileDelete %SYSDIR%\apbzk.exe FileDelete %SYSDIR%\cymmh.exe FileDelete %SYSDIR%\jphaxyap.byv FileDelete %SYSDIR%\l3jdfs.exe FileDelete %SYSDIR%\vf1v62x.dll FileDelete %SYSDIR%\vp1i4.exe FileDelete %SYSDIR%\whcixm7.exe FileDelete %SYSDIR%\y3aqsoepa.exe FileDelete %SYSDIR%\TheMatrixHasYou.exe FileDelete %SYSDIR%\truetype.exe FileDelete %SYSDIR%\win.ini.t00 FileDelete %SYSDIR%\ImaS3r FileDelete %SYSDIR%\0mcamcap.exe FileDelete %SYSDIR%\BattyRun.dll FileDelete %SYSDIR%\loadadv455.exe FileDelete %SYSDIR%\loadadv559.exe FileDelete %SYSDIR%\loadadv642.exe FileDelete %SYSDIR%\recsl.exe FileDelete %SYSDIR%\mysvcc.exe FileDelete %SYSDIR%\Xinstall.exe FileDelete %SYSDIR%\Yinstall.exe FileDelete %SYSDIR%\rnnypbw.exe OptionSetStatus Deleting files Zeno FileDelete %SYSTEMDRIVE%\ZICORN00.exe FileDelete %SYSTEMDRIVE%\ZICORN001.exe FileDelete %SYSTEMDRIVE%\ZICORN00*.exe FileDelete %STARTUP%\wmplayer.exe FileDelete %STARTUP%\Z_Start.lnk FileDelete %STARTUP%\Zstart.lnk FileDelete %STARTUP%\Zeno.lnk FileDelete %STARTUP%\Think-Adz.lnk FileDelete %STARTUP%\TA_Start.lnk FileDeleteIfContainsText %SYSDIR%\*.exe|ZStart.lnk FileDeleteIfContainsText %SYSDIR%\*.exe|TA_Start.lnk OptionSetStatus Deleting files drsmartload Program Files FileDelete %PROGRAMFILES%\Common Files\system32.dll FileDelete %PROGRAMFILES%\Catcher.dll FileDelete %PROGRAMFILES%\gui.exe FileDelete %PROGRAMFILES%\cwebpage.dll FileDelete %PROGRAMFILES%\version.txt FileDelete %PROGRAMFILES%\x.bmp FileDelete %PROGRAMFILES%\Network\network.exe FileDelete %PROGRAMFILES%\Network\ipnetwork.exe FileDelete %SYSTEMDRIVE%\Documents and Settings\%USERNAME%\LOADADV455.EXE FileDelete %SYSTEMDRIVE%\Documents and Settings\%USERNAME%\loadadv642.exe FileDelete %SYSTEMDRIVE%\Documents and Settings\%USERNAME%\LOADADV*.EXE OptionSetStatus Deleting desktop shortcuts FileDelete %DESKTOP%\Free Plasma TV.lnk FileDelete %DESKTOP%\Weather.lnk FileDelete %DESKTOP%\Poker Shortcut.lnk FileDelete %DESKTOP%\chat now.lnk FileDelete %DESKTOP%\Play Poker Online.lnk FileDelete %DESKTOP%\Xinstall.exe FileDelete %DESKTOP%\Yinstall.exe FileDelete %DESKTOP%\loadadv642.exe FileDelete %DESKTOP%\loadadv64*.exe OptionSetStatus Deleting Alcan files SystemEmptyTempFolder SystemEmptyInternetCache FileDelete %SYSDIR%\CMD.COM FileDelete %SYSDIR%\netstat.com FileDelete %SYSDIR%\ping.com FileDelete %SYSDIR%\regedit.com FileDelete %SYSDIR%\tasklist.com FileDelete %SYSDIR%\taskkill.com FileDelete %SYSDIR%\taskmgr.com FileDelete %SYSDIR%\tracert.com FileDelete %SYSDIR%\winlogi.ex OptionSetStatus Deleting Program Files folders FolderDelete %PROGRAMFILES%\Maxifiles FolderDelete %PROGRAMFILES%\DNS FolderDelete %PROGRAMFILES%\EQAdvice FolderDelete %PROGRAMFILES%\FCAdvice FolderDelete %PROGRAMFILES%\PSCastor FolderDelete %PROGRAMFILES%\CMIntex FolderDelete %PROGRAMFILES%\PadsysAssistant FolderDelete %PROGRAMFILES%\Common Files\FreeProd1 FolderDelete %PROGRAMFILES%\Common Files\FreeProd2 FolderDelete %PROGRAMFILES%\Common Files\InetGet FolderDelete %PROGRAMFILES%\Common Files\InetGet2 FolderDelete %PROGRAMFILES%\Common Files\svchostsys FolderDelete %PROGRAMFILES%\Common Files\simtest FolderDelete %PROGRAMFILES%\Common Files\misc001 FolderDelete %PROGRAMFILES%\InetGet2 FolderDelete %PROGRAMFILES%\Common Files\VCClient FolderDelete %PROGRAMFILES%\Network Monitor FolderDelete %WINDIR%\inet20001 FolderDelete %WINDIR%\inet20000 FolderDelete %PROGRAMFILES%\Update06 FolderDelete %PROGRAMFILES%\Update03 FolderDelete %PROGRAMFILES%\Update04 FolderDelete %PROGRAMFILES%\Update08 FolderDelete %PROGRAMFILES%\W-Update FileDelete %PROGRAMFILES%\Updates\Keygen.exe FileDelete %PROGRAMFILES%\Internet Explorer\keygen.exe FileDelete %PROGRAMFILES%\Internet Explorer\Setup.exe FileDelete %PROGRAMFILES%\Deskbar\about.html FileDelete %PROGRAMFILES%\Deskbar\basis.xml FileDelete %PROGRAMFILES%\Deskbar\deskbar.crc FileDelete %PROGRAMFILES%\Deskbar\deskbar.inf FileDelete %PROGRAMFILES%\Deskbar\icons.bmp FileDelete %PROGRAMFILES%\Deskbar\inst.bat FileDelete %PROGRAMFILES%\Deskbar\mbback.bmp FileDelete %PROGRAMFILES%\Deskbar\mbbigopen.bmp FileDelete %PROGRAMFILES%\Deskbar\mbclose.bmp FileDelete %PROGRAMFILES%\Deskbar\mbfwd.bmp FileDelete %PROGRAMFILES%\Deskbar\mblogo.bmp FileDelete %PROGRAMFILES%\Deskbar\mbsep.bmp FileDelete %PROGRAMFILES%\Deskbar\options.html FileDelete %PROGRAMFILES%\Deskbar\softomate.gif FileDelete %PROGRAMFILES%\Deskbar\version.txt FileDelete %PROGRAMFILES%\Common Files\Y1324OU.exe FolderDelete %PROGRAMFILES%\Yazzle Sudoku FolderDelete %ProgramFiles%\Cas FolderDelete %ProgramFiles%\CasStub FolderDelete %ProgramFiles%\Cas2Stub FolderDelete %ProgramFiles%\ipwins FolderDelete %ProgramFiles%\Ipwindows FolderDelete %ProgramFiles%\Common Files\Snowball Wars FolderDelete %ProgramFiles%\folder.js FolderDelete %ProgramFiles%\ini.ini OptionSetStatus Deleting hardcoded c-drive files and folders FolderDelete C:\temp FileDelete C:\nwnm.exe FileDelete C:\nwnm_1.exe FileDelete C:\nwnmb_2.exe FileDelete C:\nwnmc_2.exe FileDelete C:\nwnmb_3.exe FileDelete C:\nwnmc_4.exe FileDelete C:\nwnmd_4.exe FileDelete C:\nwnmd_5.exe FileDelete C:\nwnme_5.exe FileDelete C:\nwnmad_5.exe FileDelete C:\nwnmac_6.exe FileDelete C:\nwnmdd_6.exe FileDelete C:\nwnmed_7.exe FileDelete C:\nwnmef_7.exe FileDelete C:\nwnmfg_7.exe FileDelete C:\nwnmff_7.exe FileDelete C:\nwnmfg_8.exe FileDelete C:\nwnmff_8.exe FileDelete C:\nwnmff_9.exe FileDelete C:\nwnmfh_10.exe FileDelete C:\nwnmff_11.exe FileDelete C:\nwnmff_12.exe FileDelete C:\nwnmff_13.exe FileDelete C:\nwnmff_14.exe FileDelete C:\nwnmff_15.exe FileDelete C:\nwnmff_16.exe FileDelete C:\nwnmff_17.exe FileDelete C:\nwnmff_18.exe FileDelete c:\nwnmff_e.exe FileDelete c:\nwnmff_e1.exe FileDelete c:\nwnmff_e2.exe FileDelete c:\nwnmff_e3.exe FileDelete c:\nwnmff_e4.exe FileDelete c:\nwnmff_e5.exe FileDelete c:\nwnmff_e6.exe FileDelete c:\nwnmff_e7.exe FileDelete c:\nwnmff_e8.exe FileDelete c:\nwnmff_e9.exe FileDelete c:\nwnmff_e10.exe FileDelete c:\nwnmff_e11.exe FileDelete c:\nwnmff_e12.exe FileDelete c:\nwnmff_e13.exe FileDelete c:\nwnmff_e14.exe FileDelete c:\nwnmff_e15.exe FileDelete c:\nwnmff_e16.exe FileDelete c:\nwnmff_e17.exe FileDelete c:\nwnmff_e18.exe FileDelete c:\nwnmff_e19.exe FileDelete c:\nwnmff_e20.exe FileDelete c:\nwnmff_e21.exe FileDelete c:\nwnmff_e22.exe FileDelete c:\nwnmff_e23.exe FileDelete c:\nwnmff_e24.exe FileDelete c:\nwnmff_e25.exe FileDelete c:\nwnmff_e26.exe FileDelete c:\nwnmff_e27.exe FileDelete c:\nwnmff_e28.exe FileDelete c:\nwnmff_e29.exe FileDelete c:\nwnmff_e30.exe FileDelete c:\nwnmff_e31.exe FileDelete c:\nwnmff_e32.exe FileDelete c:\nwnmff_e33.exe FileDelete c:\nwnmff_e34.exe FileDelete c:\nwnmff_e35.exe FileDelete c:\nwnmff_e36.exe FileDelete c:\nwnmff_e37.exe FileDelete c:\nwnmff_e38.exe FileDelete c:\nwnmff_e40.exe FileDelete c:\nwnmff_e41.exe FileDelete c:\nwnmff_e42.exe FileDelete c:\nwnmff_e43.exe FileDelete c:\nwnmff_e44.exe FileDelete c:\nwnmff_e45.exe FileDelete c:\nwnmff_e46.exe FileDelete c:\nwnmff_e47.exe FileDelete c:\nwnmff_e48.exe FileDelete c:\nwnmff_e49.exe FileDelete c:\nwnmff_e50.exe FileDelete c:\nwnmff_e54.exe FileDelete C:\nwnmff_e56.exe FileDelete C:\nwnmff_e57.exe FileDelete C:\nwnm*.exe FileDelete C:\kybrd.exe FileDelete C:\kybrd_1.exe FileDelete C:\kybrdb_2.exe FileDelete C:\kybrdc_2.exe FileDelete C:\kybrdb_3.exe FileDelete C:\kybrdc_4.exe FileDelete C:\kybrdd_4.exe FileDelete C:\kybrdd_5.exe FileDelete C:\kybrde_5.exe FileDelete C:\kybrdad_5.exe FileDelete C:\kybrdaca_6.exe FileDelete C:\kybrddd_6.exe FileDelete C:\kybrded_7.exe FileDelete C:\kybrdef_7.exe FileDelete C:\kybrdfg_7.exe FileDelete C:\kybrdff_7.exe FileDelete C:\kybrdfg_8.exe FileDelete C:\kybrdff_8.exe FileDelete C:\kybrdff_9.exe FileDelete C:\kybrdfh_10.exe FileDelete C:\kybrdff_11.exe FileDelete C:\kybrdff_11a.exe FileDelete C:\kybrdff_12.exe FileDelete C:\kybrdff_13.exe FileDelete C:\kybrdff_14.exe FileDelete C:\kybrdff_15.exe FileDelete C:\kybrdff_16.exe FileDelete C:\kybrdff_17.exe FileDelete C:\kybrdff_18.exe FileDelete c:\kybrdff_e.exe FileDelete c:\kybrdff_e1.exe FileDelete c:\kybrdff_e2.exe FileDelete c:\kybrdff_e3.exe FileDelete c:\kybrdff_e4.exe FileDelete c:\kybrdff_e5.exe FileDelete c:\kybrdff_e6.exe FileDelete c:\kybrdff_e7.exe FileDelete c:\kybrdff_e8.exe FileDelete c:\kybrdff_e9.exe FileDelete c:\kybrdff_e10.exe FileDelete c:\kybrdff_e11.exe FileDelete c:\kybrdff_e12.exe FileDelete c:\kybrdff_e13.exe FileDelete c:\kybrdff_e14.exe FileDelete c:\kybrdff_e15.exe FileDelete c:\kybrdff_e16.exe FileDelete c:\kybrdff_e17.exe FileDelete c:\kybrdff_e18.exe FileDelete c:\kybrdff_e19.exe FileDelete c:\kybrdff_e20.exe FileDelete c:\kybrdff_e21.exe FileDelete c:\kybrdff_e22.exe FileDelete c:\kybrdff_e23.exe FileDelete c:\kybrdff_e24.exe FileDelete c:\kybrdff_e25.exe FileDelete c:\kybrdff_e26.exe FileDelete c:\kybrdff_e27.exe FileDelete c:\kybrdff_e28.exe FileDelete c:\kybrdff_e29.exe FileDelete c:\kybrdff_e30.exe FileDelete c:\kybrdff_e31.exe FileDelete c:\kybrdff_e32.exe FileDelete c:\kybrdff_e33.exe FileDelete c:\kybrdff_e34.exe FileDelete c:\kybrdff_e35.exe FileDelete c:\kybrdff_e36.exe FileDelete c:\kybrdff_e37.exe FileDelete c:\kybrdff_e38.exe FileDelete c:\kybrdff_e40.exe FileDelete c:\kybrdff_e41.exe FileDelete c:\kybrdff_e42.exe FileDelete c:\kybrdff_e43.exe FileDelete c:\kybrdff_e44.exe FileDelete c:\kybrdff_e45.exe FileDelete c:\kybrdff_e46.exe FileDelete c:\kybrdff_e47.exe FileDelete c:\kybrdff_e48.exe FileDelete c:\kybrdff_e49.exe FileDelete c:\kybrdff_e50.exe FileDelete c:\kybrdff_e51.exe FileDelete c:\kybrdff_e52.exe FileDelete c:\kybrdff_e53.exe FileDelete c:\kybrdff_e54.exe FileDelete c:\kybrdff_e55.exe FileDelete c:\kybrdff_e56.exe FileDelete c:\kybrdff_e57.exe FileDelete c:\kybrdff_e58.exe FileDelete c:\kybrdff_e59.exe FileDelete c:\kybrdff_e60.exe FileDelete c:\kybrdff_e61.exe FileDelete c:\kybrdff_e62.exe FileDelete c:\kybrdff_e63.exe FileDelete c:\kybrdff_e64.exe FileDelete c:\kybrdff_e65.exe FileDelete c:\kybrdff_e66.exe FileDelete c:\kybrdff_e67.exe FileDelete c:\kybrdff_e68.exe FileDelete c:\kybrdff_e71.exe FileDelete c:\kybrdff_e72.exe FileDelete c:\kybrdff_e73.exe FileDelete c:\kybrdff_e74.exe FileDelete c:\kybrdff_e75.exe FileDelete c:\kybrdff_e90.exe FileDelete c:\kybrdff_e92.exe FileDelete c:\kybrdff_e93.exe FileDelete c:\kybrdff_e96.exe FileDelete c:\kybrdff_e98.exe FileDelete c:\kybrdff_e101.exe FileDelete c:\kybrdff_e102.exe FileDelete c:\kybrdff_e103.exe FileDelete c:\kybrdff_e104.exe FileDelete c:\kybrdff_e105.exe FileDelete c:\kybrdff_e106.exe FileDelete c:\kybrdff_e109.exe FileDelete c:\kybrdff_e110.exe FileDelete c:\kybrdff_e111.exe FileDelete c:\kybrdff_e113.exe FileDelete c:\kybrdff_e115.exe FileDelete c:\kybrdff_e116.exe FileDelete c:\kybrdff_e118.exe FileDelete c:\kybrdff_e119.exe FileDelete c:\kybrdff_e121.exe FileDelete c:\kybrdff_e122.exe FileDelete c:\kybrdff_e123.exe FileDelete c:\kybrdff_e124.exe FileDelete c:\kybrdff_e125.exe FileDelete c:\kybrdff_e127.exe FileDelete c:\kybrdff_e128.exe FileDelete c:\kybrdff_e129.exe FileDelete c:\kybrdff_e130.exe FileDelete c:\kybrdff_e132.exe FileDelete c:\kybrdff_e133.exe FileDelete c:\kybrdff_e134.exe FileDelete c:\kybrdff_e136.exe FileDelete c:\kybrdff_e139.exe FileDelete c:\kybrdff_e140.exe FileDelete c:\kybrdff_e141.exe FileDelete C:\kybrdff_e142.exe FileDelete C:\kybrdff_e144.exe FileDelete c:\kybrdff_e145.exe FileDelete c:\kybrdff_e147.exe FileDelete c:\kybrdff_e148.exe FileDelete c:\kybrdff_e150.exe FileDelete c:\kybrdff_e152.exe FileDelete c:\kybrdff_e154.exe FileDelete c:\kybrdff_e157.exe FileDelete c:\kybrdff_e158.exe FileDelete c:\kybrdff_e159.exe FileDelete c:\kybrdff_e161.exe FileDelete c:\kybrdff_e162.exe FileDelete c:\kybrdff_e163.exe FileDelete c:\kybrdff_e166.exe FileDelete c:\kybrdff_e167.exe FileDelete c:\kybrdff_e169.exe FileDelete c:\kybrdff_e171.exe FileDelete c:\kybrdff_e173.exe FileDelete C:\kybrdff_e174.exe FileDelete c:\kybrdff_e175.exe FileDelete c:\kybrdff_e177.exe FileDelete c:\kybrdff_e178.exe FileDelete c:\kybrdff_e179.exe FileDelete c:\kybrdff_e180.exe FileDelete c:\kybrdff_e182.exe FileDelete c:\kybrdff_e183.exe FileDelete c:\kybrdff_e184.exe FileDelete c:\kybrdff_e185.exe FileDelete c:\kybrdff_e186.exe FileDelete c:\kybrd*.exe FileDelete c:\kybrdff_e.exe FileDelete C:\dfndr.exe FileDelete C:\dfndra.exe FileDelete C:\dfndra_1.exe FileDelete C:\dfndrb_2.exe FileDelete C:\dfndrc_2.exe FileDelete C:\dfndrb_3.exe FileDelete C:\dfndrc_4.exe FileDelete C:\dfndrd_4.exe FileDelete C:\dfndrc_4a.exe FileDelete C:\dfndrd_5.exe FileDelete C:\dfndre_5.exe FileDelete C:\dfndrad_5.exe FileDelete C:\dfndrac_6.exe FileDelete C:\dfndrdd_6.exe FileDelete C:\dfndred_7.exe FileDelete C:\dfndref_7.exe FileDelete C:\dfndrfg_7.exe FileDelete C:\dfndrff_7.exe FileDelete C:\dfndrfg_8.exe FileDelete C:\dfndrff_8.exe FileDelete C:\dfndrff_9.exe FileDelete C:\dfndrfh_10.exe FileDelete C:\dfndrff_11.exe FileDelete C:\dfndrff_11a.exe FileDelete C:\dfndrff_12.exe FileDelete C:\dfndrff_13.exe FileDelete C:\dfndrff_14.exe FileDelete C:\dfndrff_15.exe FileDelete C:\dfndrff_16.exe FileDelete C:\dfndrff_17.exe FileDelete C:\dfndrff_18.exe FileDelete C:\dfndrff_e.exe FileDelete C:\dfndrff_e1.exe FileDelete C:\dfndrff_e2.exe FileDelete c:\dfndrff_e3.exe FileDelete c:\dfndrff_e4.exe FileDelete c:\dfndrff_e5.exe FileDelete c:\dfndrff_e6.exe FileDelete c:\dfndrff_e7.exe FileDelete c:\dfndrff_e8.exe FileDelete c:\dfndrff_e9.exe FileDelete c:\dfndrff_e10.exe FileDelete c:\dfndrff_e11.exe FileDelete c:\dfndrff_e12.exe FileDelete c:\dfndrff_e13.exe FileDelete c:\dfndrff_e14.exe FileDelete c:\dfndrff_e15.exe FileDelete c:\dfndrff_e16.exe FileDelete c:\dfndrff_e17.exe FileDelete c:\dfndrff_e18.exe FileDelete c:\dfndrff_e19.exe FileDelete c:\dfndrff_e20.exe FileDelete c:\dfndrff_e21.exe FileDelete c:\dfndrff_e22.exe FileDelete c:\dfndrff_e23.exe FileDelete c:\dfndrff_e24.exe FileDelete c:\dfndrff_e25.exe FileDelete c:\dfndrff_e26.exe FileDelete c:\dfndrff_e27.exe FileDelete c:\dfndrff_e28.exe FileDelete c:\dfndrff_e29.exe FileDelete c:\dfndrff_e30.exe FileDelete c:\dfndrff_e31.exe FileDelete c:\dfndrff_e32.exe FileDelete c:\dfndrff_e33.exe FileDelete c:\dfndrff_e34.exe FileDelete c:\dfndrff_e35.exe FileDelete c:\dfndrff_e36.exe FileDelete c:\dfndrff_e37.exe FileDelete c:\dfndrff_e38.exe FileDelete c:\dfndrff_e40.exe FileDelete c:\dfndrff_e41.exe FileDelete c:\dfndrff_e42.exe FileDelete c:\dfndrff_e43.exe FileDelete c:\dfndrff_e44a.exe FileDelete c:\dfndrff_e45.exe FileDelete c:\dfndrff_e46a.exe FileDelete c:\dfndrff_e47.exe FileDelete c:\dfndrff_e48.exe FileDelete c:\dfndrff_e49.exe FileDelete c:\dfndrff_e50.exe FileDelete c:\dfndrff_e51.exe FileDelete c:\dfndrff_e52.exe FileDelete c:\dfndrff_e53.exe FileDelete c:\dfndrff_e54.exe FileDelete c:\dfndrff_e55.exe FileDelete c:\dfndrff_e56.exe FileDelete c:\dfndrff_e57.exe FileDelete c:\dfndrff_e58.exe FileDelete c:\dfndrff_e59.exe FileDelete c:\dfndrff_e60.exe FileDelete c:\dfndrff_e61.exe FileDelete c:\dfndrff_e62.exe FileDelete c:\dfndrff_e63.exe FileDelete c:\dfndrff_e64.exe FileDelete c:\dfndrff_e65.exe FileDelete c:\dfndrff_e66.exe FileDelete c:\dfndrff_e67.exe FileDelete c:\dfndrff_e68.exe FileDelete c:\dfndrff_e71.exe FileDelete c:\dfndrff_e72.exe FileDelete c:\dfndrff_e73.exe FileDelete c:\dfndrff_e74.exe FileDelete c:\dfndrff_e75.exe FileDelete c:\dfndrff_e90.exe FileDelete c:\dfndrff_e92.exe FileDelete c:\dfndrff_e93.exe FileDelete c:\dfndrff_e96.exe FileDelete c:\dfndrff_e98.exe FileDelete c:\dfndrff_101.exe FileDelete c:\dfndrff_102.exe FileDelete c:\dfndrff_103.exe FileDelete c:\dfndrff_104.exe FileDelete c:\dfndrff_105.exe FileDelete c:\dfndrff_106.exe FileDelete c:\dfndrff_109.exe FileDelete c:\dfndrff_110.exe FileDelete c:\dfndrff_111.exe FileDelete c:\dfndrff_113.exe FileDelete c:\dfndrff_115.exe FileDelete c:\dfndrff_116.exe FileDelete c:\dfndrff_118.exe FileDelete c:\dfndrff_119.exe FileDelete c:\dfndrff_121.exe FileDelete c:\dfndrff_122.exe FileDelete c:\dfndrff_123.exe FileDelete c:\dfndrff_124.exe FileDelete c:\dfndrff_125.exe FileDelete c:\dfndrff_127.exe FileDelete c:\dfndrff_128.exe FileDelete c:\dfndrff_129.exe FileDelete c:\dfndrff_130.exe FileDelete c:\dfndrff_132.exe FileDelete c:\dfndrff_133.exe FileDelete c:\dfndrff_134.exe FileDelete c:\dfndrff_136.exe FileDelete c:\dfndrff_139.exe FileDelete c:\dfndrff_140.exe FileDelete c:\dfndrff_141.exe FileDelete C:\dfndrff_142.exe FileDelete c:\dfndrff_144.exe FileDelete c:\dfndrff_145.exe FileDelete c:\dfndrff_147.exe FileDelete c:\dfndrff_148.exe FileDelete c:\dfndrff_150.exe FileDelete c:\dfndrff_152.exe FileDelete c:\dfndrff_154.exe FileDelete c:\dfndrff_157.exe FileDelete c:\dfndrff_158.exe FileDelete c:\dfndrff_159.exe FileDelete c:\dfndrff_161.exe FileDelete c:\dfndrff_162.exe FileDelete c:\dfndrff_163.exe FileDelete c:\dfndrff_166.exe FileDelete c:\dfndrff_167.exe FileDelete c:\dfndrff_169.exe FileDelete c:\dfndrff_171.exe FileDelete c:\dfndrff_173.exe FileDelete C:\dfndrff_174.exe FileDelete c:\dfndrff_175.exe FileDelete c:\dfndrff_177.exe FileDelete c:\dfndrff_178.exe FileDelete c:\dfndrff_179.exe FileDelete c:\dfndrff_180.exe FileDelete c:\dfndrff_182.exe FileDelete c:\dfndrff_183.exe FileDelete c:\dfndrff_184.exe FileDelete c:\dfndrff_185.exe FileDelete c:\dfndrff_186.exe FileDelete c:\dfndrff_187.exe FileDelete c:\dfndrff_188.exe FileDelete c:\dfndr*.exe FileDelete c:\dfndrff_e_uit.exe FileDelete c:\dfndrff_e.exe FileDelete c:\dfndrff_a.exe FileDelete c:\topaff.exe FileDelete c:\vv44.exe FileDelete C:\ac2_0010.exe FileDelete C:\ac2_0003.exe FileDelete C:\ac2_00*.exe FileDelete C:\ac3_00*.exe FileDelete c:\mc44a2.exe FileDelete c:\mc44a3.exe FileDelete c:\mc44a34.exe FileDelete c:\mc44a35.exe FileDelete c:\mc44a36.exe FileDelete c:\mc44a37.exe FileDelete c:\mc44a38.exe FileDelete c:\mc44a39.exe FileDelete c:\mc44a41.exe FileDelete c:\mc44a42.exe FileDelete c:\mc44a43.exe FileDelete c:\mc44a44.exe FileDelete c:\mc44a45.exe FileDelete c:\mc44a46.exe FileDelete c:\mc44a47.exe FileDelete c:\mc44a48.exe FileDelete c:\mc44a49.exe FileDelete c:\mc44a50.exe FileDelete c:\mc44a51.exe FileDelete c:\mc44a52.exe FileDelete c:\mc44a53.exe FileDelete c:\mc44a54.exe FileDelete c:\mc44a55.exe FileDelete c:\mc44a56.exe FileDelete c:\mc44a57.exe FileDelete c:\mc44a58.exe FileDelete c:\mc44a*.exe FileDelete C:\deskbar.exe FileDelete C:\deskbar2.exe FileDelete C:\deskbar3.exe FileDelete c:\deskbar4.exe FileDelete c:\deskbar7.exe FileDelete c:\deskbar8.exe FileDelete c:\deskbar_e9.exe FileDelete c:\deskbar_e10.exe FileDelete c:\deskbar_e11.exe FileDelete c:\deskbar_e12.exe FileDelete c:\deskbar_e13.exe FileDelete c:\deskbar_e14.exe FileDelete c:\deskbar_e15.exe FileDelete c:\deskbar_e17.exe FileDelete c:\deskbar_e18.exe FileDelete c:\deskbar_e19.exe FileDelete c:\deskbar_e20.exe FileDelete c:\deskbar_e21.exe FileDelete c:\deskbar_e25.exe FileDelete c:\deskbar_e26.exe FileDelete c:\deskbar_e29.exe FileDelete c:\deskbar_e31.exe FileDelete c:\deskbar_e34.exe FileDelete c:\deskbar_e37.exe FileDelete c:\deskbar_e39.exe FileDelete c:\deskbar_e41.exe FileDelete c:\deskbar_e42.exe FileDelete c:\deskbar_e44.exe FileDelete c:\deskbar_e45.exe FileDelete c:\deskbar_e46.exe FileDelete c:\deskbar_e47.exe FileDelete c:\deskbar_e48.exe FileDelete c:\deskbar_e49.exe FileDelete c:\deskbar_e50.exe FileDelete c:\deskbar_e51.exe FileDelete c:\deskbar_e52.exe FileDelete c:\deskbar_e53.exe FileDelete c:\deskbar_e55.exe FileDelete c:\deskbar_e58.exe FileDelete c:\deskbar_e59.exe FileDelete c:\deskbar_e60.exe FileDelete c:\deskbar_e61.exe FileDelete c:\deskbar_e62.exe FileDelete c:\deskbar_e64.exe FileDelete c:\deskbar_e65.exe FileDelete c:\deskbar_e66.exe FileDelete c:\deskbar_e67.exe FileDelete c:\deskbar_e68.exe FileDelete c:\deskbar_e71.exe FileDelete c:\deskbar_e72.exe FileDelete c:\deskbar_e73.exe FileDelete c:\deskbar_e74.exe FileDelete c:\deskbar_e75.exe FileDelete c:\deskbar_e90.exe FileDelete c:\deskbar_e92.exe FileDelete c:\deskbar_e93.exe FileDelete c:\deskbar_e96.exe FileDelete c:\deskbar_e98.exe FileDelete c:\deskbar_e101.exe FileDelete c:\deskbar_e102.exe FileDelete c:\deskbar_e103.exe FileDelete c:\deskbar_e104.exe FileDelete c:\deskbar_e105.exe FileDelete c:\deskbar_e106.exe FileDelete c:\deskbar_e109.exe FileDelete c:\deskbar_e110.exe FileDelete c:\deskbar_e111.exe FileDelete c:\deskbar_e113.exe FileDelete c:\deskbar_e115.exe FileDelete c:\deskbar_e116.exe FileDelete c:\deskbar_e118.exe FileDelete c:\deskbar_e119.exe FileDelete c:\deskbar_e121.exe FileDelete c:\deskbar_e122.exe FileDelete c:\deskbar_e123.exe FileDelete c:\deskbar_e124.exe FileDelete c:\deskbar_e125.exe FileDelete c:\deskbar_e127.exe FileDelete c:\deskbar_e128.exe FileDelete c:\deskbar_e129.exe FileDelete c:\deskbar_e130.exe FileDelete c:\deskbar_e132.exe FileDelete c:\deskbar_e133.exe FileDelete c:\deskbar_e134.exe FileDelete c:\deskbar_e136.exe FileDelete c:\deskbar_e139.exe FileDelete c:\deskbar_e140.exe FileDelete c:\deskbar_e141.exe FileDelete c:\deskbar_e142.exe FileDelete c:\deskbar_e144.exe FileDelete c:\deskbar_e145.exe FileDelete c:\deskbar_e147.exe FileDelete c:\deskbar_e148.exe FileDelete c:\deskbar_e150.exe FileDelete c:\deskbar_e152.exe FileDelete c:\deskbar_e154.exe FileDelete c:\deskbar_e157.exe FileDelete c:\deskbar_e158.exe FileDelete c:\deskbar_e159.exe FileDelete c:\deskbar_e161.exe FileDelete c:\deskbar_e162.exe FileDelete c:\deskbar_e163.exe FileDelete c:\deskbar_e166.exe FileDelete c:\deskbar_e167.exe FileDelete c:\deskbar_e169.exe FileDelete c:\deskbar_e171.exe FileDelete C:\deskbar*.exe FileDelete C:\deskbar_e.exe FileDelete c:\windows_e51.exe FileDelete c:\windows_e52.exe FileDelete c:\windows_e53.exe FileDelete c:\windows_e55.exe FileDelete c:\windows_e56.exe FileDelete c:\windows_e57.exe FileDelete c:\windows_e58.exe FileDelete c:\windows_e*.exe FileDelete c:\ClientApp1057.exe FileDelete c:\1.exe FileDelete c:\2.exe FileDelete c:\3.exe FileDelete c:\4.exe FileDelete c:\5.exe FileDelete c:\6.exe FileDelete c:\7.exe FileDelete c:\8.exe FileDelete c:\9.exe FileDelete c:\10.exe FileDelete c:\ie_ban.exe FileDelete c:\waverevenue.exe FileDelete c:\evmacash.exe FileDelete c:\retadpu*.exe OptionSetStatus Deleting special folders FolderDelete %WINDIR%\mdrive FolderDelete %SYSDIR%\crunner FolderDelete %PROGRAMFILES%\PECarlin FolderDelete %PROGRAMFILES%\AXVenore FolderDelete %PROGRAMFILES%\SDVita FolderDelete %PROGRAMFILES%\EQBranch FolderDelete %PROGRAMFILES%\EQArticle FolderDelete %PROGRAMFILES%\PSHope FolderDelete %PROGRAMFILES%\Batty FolderDelete %PROGRAMFILES%\Batty2 FolderDelete %PROGRAMFILES%\AXFibula FolderDelete %PROGRAMFILES%\CMFibula FolderDelete %PROGRAMFILES%\PSLister FolderDelete %PROGRAMFILES%\PSCloner FolderDelete %PROGRAMFILES%\PSDream FolderDelete %PROGRAMFILES%\cmapp FolderDelete %PROGRAMFILES%\cmman FolderDelete %PROGRAMFILES%\cmsystem FolderDelete %PROGRAMFILES%\fcengine FolderDelete %PROGRAMFILES%\wincmapp FolderDelete %PROGRAMFILES%\Deskbar\Cache FolderDelete %PROGRAMFILES%\popupwithcast FolderDelete %PROGRAMFILES%\Common Files\cloader FolderDelete %ProgramFiles%\Common Files\misc001 FolderDelete %ProgramFiles%\Web Buying OptionSetStatus Trying heuristics FolderCreate %SYSTEMDRIVE%\bintheredunthat FileMove %WINDIR%\win*-*.exe|%SYSTEMDRIVE%\bintheredunthat FileMoveIfContainsHex %SYSTEMDRIVE%\*.exe|%SYSTEMDRIVE%\bintheredunthat|2E,00,6E,00,6F,00,00,00,08,00,00,00,6E,00,61,00,6D,00,65,00,00,00,00,00,0A,00,00,00,66,00,6F,00 FileMoveIfContainsHex %SYSTEMDRIVE%\*.exe|%SYSTEMDRIVE%\bintheredunthat|2E,00,6E,00,6F,00,00,00,06,00,00,00,6E,00,61,00,6D,00,00,00,0A,00,00,00,65,00,66,00,6F,00 FileMoveIfContainsHex %SYSTEMDRIVE%\*.exe|%SYSTEMDRIVE%\bintheredunthat|2E,00,6E,00,00,00,10,00,00,00,6F,00,6E,00,61,00,6D,00,65,00,66,00,6F,00,72,00,00,00,00,00,10,00 FileMoveIfContainsHex %WINDIR%\*.exe|%SYSTEMDRIVE%\bintheredunthat|53,00,79,00,73,00,4D,00,6F,00,6E,00,2E,00,65,00,78,00,65 FileMoveIfContainsText %SYSTEMDRIVE%\*.exe|%SYSTEMDRIVE%\bintheredunthat|WebBrowser1 FileMoveIfContainsText %SYSTEMDRIVE%\*.exe|%SYSTEMDRIVE%\bintheredunthat|Project1 FileMoveIfContainsText %SYSTEMDRIVE%\*.exe|%SYSTEMDRIVE%\bintheredunthat|NSISu_.exe FileMoveIfContainsHex %SYSTEMDRIVE%\w*.dll|%SYSTEMDRIVE%\bintheredunthat|61,63,32,2E,64,6C,6C,00,49,31,00,49,32 FileMoveIfContainsHex %SYSDIR%\w*.dll|%SYSTEMDRIVE%\bintheredunthat|61,63,32,2E,64,6C,6C,00,49,31,00,49,32 FileDeleteIfMD5Match %SYSDIR%\eventwvr.exe|E665EEFEEBEFE3177CA1551E75EFCBBB FileMoveIfContainsText %WINDIR%\sys0*.exe|%SYSTEMDRIVE%\bintheredunthat|Zombie_GetTypeInfo FileMoveIfContainsText %WINDIR%\ms0*.exe|%SYSTEMDRIVE%\bintheredunthat|Zombie_GetTypeInfo