How to use:
1 Closing the browser
2 Executive Un3721.bat
3 Re-execution Un3721.reg
4 Reboot the computer, basically the rubbish is deleted
5 If there is a small amount, restart the computer into Safe mode operation, or look at the help note in the. bat file,
Un3721.bat
Copy Code code as follows:
REM Cut off all rogues, let us wait for the Internet spring ~_~
REM needs to be modified according to its own requirements (some people still think a rogue is good to keep *_*)
rem If you jump out of the selection box, select Uninstall All
REM some * * need to be in Safe mode to uninstall, some bad uninstall please see the help inside
REM is now more and more super Rogue, has exceeded the capacity limit of batch processing, only with some other software, recommended to use Http://ccollomb.free.fr/unlocker together to delete super * *
rem cut off 3721 Kao messed up a lot of computers.
If exist C:\progra~1\3721\assist\asbar.dll rundll32.exe C:\progra~1\3721\assist\asbar.dll,runsettings-uninstall
If exist%windir%\downlo~1\cnsmin.dll rundll32.exe%windir%\downlo~1\cnsmin.dll,runsettings-uninstall
If exist%windir%\downlo~1\cnsmin.dll rundll32.exe%windir%\downlo~1\cnsmin.dll,controlpanel
regsvr32/u/S%windir%\downlo~1\cnsmin.dll
regsvr32/u/S C:\progra~1\3721\assist\asbar.dll
regsvr32/u/S C:\progra~1\3721\helper.dll
regsvr32/u/S C:\progra~1\yisou\yisou.dll
rem Cut Yahoo pig hands and messed up a lot of computers.
regsvr32/u/S C:\progra~1\yahoo!\assist~1\assist\yasbar.dll
regsvr32/u/S C:\progra~1\yahoo!\assist~1\assist\yphtb.dll
regsvr32/u/S C:\progra~1\yahoo!\assist~1\assist\yangling.dll
regsvr32/u/S C:\progra~1\yahoo!\assist~1\assist\ydrags~1.dll
REM new version of the pig hand can not choose to uninstall, * * *
If exist C:\progra~1\yahoo!\assist~1\assist\yasbar.dll rundll32 c:\progra~1\yahoo!\assist~1\assist\yasbar.dll, UnInstall
REM MMS through again a super * * has produced
REM Find a way to remove%windir%\system32\drivers\albus.sys this vile and unforgiving document in order to completely clean up this portal
REM recommends using DOS to boot the computer to find C disk this vile and unforgiving file deletion
REM or use Http://ccollomb.free.fr/unlocker Delete, after deletion may cause system instability, restart the computer to perform 2 batches, and then reboot
regsvr32/u/S C:\progra~1\mmsass~1\mmsass~1.dll
If exist C:\progra~1\mmsass~1\mmsass~1.dll rundll32.exe C:\progra~1\mmsass~1\mmsass~1.dll,uninstall
If exist%windir%\system32\stdup.dll rundll32.exe%windir%\system32\stdup.dll,uninstall
regsvr32/u/S%windir%\system32\stdup.dll
regsvr32/u/S%windir%\system32\stdsver. Dll
regsvr32/u/S%windir%\system\stdup.dll
regsvr32/u/S%windir%\system\stdsver. Dll
Del%windir%\system32\drivers\albus.sys/q/F
Del%windir%\system32\albus.dat/q/F
Del%windir%\system32\almms.dat/q/F
Del%windir%\system32\alsmt.exe/q/F
Del c:\progra~1\mmsass~1\mmsass~1.dll/q/F
rem Internet Explorer Helper
regsvr32/u/S%windir%\fonts\msshapi.dll
REM Strokes the word Huaci is also a super * * *
REM This * * needs to reboot the computer, execute two batch files again to be deleted
C:\progra~1\huaci\huaci\muin.exe
C:\progra~1\wsearch\muninstall.exe
%windir%\system32\msibm\uninstall.exe
%windir%\system\msibm\uninstall.exe
Del%windir%\system32\drivers\abhcop.sys/q/F
Del%windir%\system32\drivers\hcalway.sys/q/F
REM Baidu this **,** more and more super, baid* is no exception
REM needs safe mode, or try to remove%windir%\system32\drivers\bdguard.sys This file to uninstall this * *
If exist C:\progra~1\baidu\bar\baidubar.dll rundll32.exe C:\progra~1\baidu\bar\baidubar.dll,uninstall
regsvr32/u/S%windir%\downlo~1\bdsrhook.dll
regsvr32/u/S%windir%\downlo~1\bdhelper.dll
regsvr32/u/S%windir%\downlo~1\bdplugin.dll
regsvr32/u/S C:\progra~1\baidu\bar\baidubar.dll
regsvr32/u/S "C:\Program Files\Common Files\baidu\disk Search\dsie.dll"
If exist%windir%\downlo~1\bdhelper.dll rundll32.exe%windir%\downlo~1\bdhelper.dll,dllremove
Del%windir%\system32\drivers\bdguard.sys/q/F
Del%windir%\system32\bdguard.dat/q/F
Del%windir%\system32\bdguards.dat/q/F
Del C:\progra~1\baidu\bar\baidubar.dll
REM windirected Proud Wmpdrm.dll
REM This * * Uninstall needs to be done in safe mode, or terminate Explorer.exe,taskmgr.exe, the input method, and so on process only leave the basic process, in the cmd window to perform batch processing can unload
%windir%\system32\spoolsv\spoolsv.exe-uninst
regsvr32/u/S%windir%\system32\wmpdrm.dll
Del%windir%\system32\spoolsv\spoolsv.exe/q/F
REM for 98
%windir%\system\spoolsv\spoolsv.exe-uninst
regsvr32/u/S%windir%\system\wmpdrm.dll
Del%windir%\system\spoolsv\spoolsv.exe/q/F
REM Delete QQ Search this * *
regsvr32/u/S C:\progra~1\tencent\addrplus\iehelp.dll
regsvr32/u/S C:\progra~1\tencent\addrplus\iehelp1.dll
regsvr32/u/S C:\progra~1\tencent\addrplus\scrax.dll
regsvr32/u/S C:\progra~1\tencent\addrplus\tctrl.dll
C:\progra~1\tencent\adplus\stup.exe C:\progra~1\tencent\adplus\ssaddr1.dll Uninstall
C:\progra~1\tencent\adplus\stup.exe C:\progra~1\tencent\adplus\ssaddr.dll Uninstall
REM Delete Dudu Search Strip this * *
regsvr32/u/S C:\progra~1\dudu\dddclient\dddiemon.dll
regsvr32/u/S C:\progra~1\dudu\dddclient\dddmext.dll
REM Delete Accoona This * *
regsvr32/u/S C:\progra~1\accoona\atoolbarcn.dll
regsvr32/u/S C:\progra~1\accoona\atoolbar.dll
regsvr32/u/S C:\progra~1\accoona\asearchassist.dll
REM Delete Xbar
regsvr32/u/S C:\progra~1\xbar\xbarhelper.dll
regsvr32/u/S%windir%\system32\xunleibho_v8.dll
REM for 98
regsvr32/u/S%windir%\system\xunleibho_v8.dll
REM Schedule Sscli.dll
regsvr32/u/S%windir%\system32\sscli.dll
REM deletion Henbang is great * *
regsvr32/u/S C:\progra~1\pcast\hbcast.dll
regsvr32/u/S C:\progra~1\hbclient\hapast.dll
REGSVR32/S/U C:\progra~1\yehoo\hbyehoo.dll
REGSVR32/S/U C:\progra~1\yehoo\tbyehoo.dll
REGSVR32/S/U%windir%\downlo~1\hthelper.dll
REM Library station A lot QQ expression 9991.com51.com Super * *
regsvr32/u/S C:\progra~1\coolwebsite\quicklink.dll
"C:\Program Files\Common Files\update\update.exe"-kill1
C:\progra~1\coolwebsite\uninst.exe
REM is best safe mode operation, or you need to terminate a rundll32.exe%windir%\system32\wbem\irjit.dll process
Del%windir%\system32\wbem\irjit.dll/q/F
REM Cfsbho.dll
regsvr32/u/S%windir%\system32\msibm\cfsbho.dll
REM for 98
regsvr32/u/S%windir%\system\msibm\cfsbho.dll
REM Stroke Search Deskadtop\deskipn.dll
regsvr32/u/S C:\progra~1\deskad~1\deskipn.dll
C:\progra~1\deskad~1\deskun.exe
REM Delete Desktop Media ie-bar this * *
MSIEXEC.EXE/I{FE41A479-E056-40A5-982C-D149B5D6712D}
regsvr32/u/S "C:\Program files\desktop Media\cast\dmbar.dll"
regsvr32/u/S "C:\Program Files\Common Files\ie-bar\dmbar.dll"
"C:\Program Files\Common Files\ie-bar\uninstall.exe"
regsvr32/u/S%windir%\downlo~1\lund.dll
regsvr32/u/S "C:\Program Files\ie-bar\cast\dmbar.dll"
REM This * * may not be deleted, please go to process management to remove VIPTray.exe this process
regsvr32/u/S%windir%\system32\iehelper.dll
regsvr32/u/S%windir%\system32\windefendor.dll
REM is a name that keeps changing.
regsvr32/u/S%windir%\system\cb7o2470.dll
REM for 98
regsvr32/u/S%windir%\system\iehelper.dll
regsvr32/u/S%windir%\system\windefendor.dll
msiexec.exe/i{3d554c17-ed16-448a-b3ce-6fbc51ffb705}
REM Search Site This * *
regsvr32/u/S "C:\Program Files\searchnet\snhpr.dll"
"C:\Program Files\searchnet\uninstall.exe"
REM Hundred Dog * *
C:\progra~1\baigoo\mtsrv.exe-unregserver
regsvr32/u/S C:\progra~1\baigoo\bgook.dll
regsvr32/u/S C:\progra~1\baigoo\bgooex.dll
regsvr32/u/S C:\progra~1\baigoo\bgoohk.dll
regsvr32/u/S C:\progra~1\baigoo\bgoobho.dll
C:\progra~1\baigoo\uninst.exe
REM Sogou
C:\progra~1\p4p\uninstall.exe
regsvr32/u/S "C:\Program Files\scantoolbar\scanbar.dll"
C:\progra~1\scantoolbar\uninst.exe
%windir%\system32\unsocul.exe
REM for 98
%windir%\system\unsocul.exe
rem DOT-Dot Pass
if exist%windir%\downlo~1\ddtinit. DLL rundll32.exe%windir%\downlo~1\ddtinit. Dll,uninstall
REM Radiate Advertising
%windir%\system32\msipcsv. Exe-uninstall-all
REM for 98
%windir%\system\msipcsv. Exe-uninstall-all
REM ROOMSETUPCD Ads
If exist%windir%\system32\cd_clint.dll rundll32%windir%\system32\cd_clint.dll,servicerundll u_281
REM for 98
If exist%windir%\system\cd_clint.dll rundll32%windir%\system\cd_clint.dll,servicerundll u_281
REM a What Wubi
regsvr32/u/S C:\progra~1\common~1\wnwb\wnwbio.dll
REM Wmicsmgr.dll
regsvr32/u/S%windir%\system32\wmicsmgr.dll
regsvr32/u/S%windir%\system\wmicsmgr.dll
REM an advertisement Navihelper.dll
regsvr32/u/S%windir%\system32\navihelper.dll
regsvr32/u/S%windir%\system\navihelper.dll
Del%windir%\system32\host.dat/q/F
REM seems to be a Trojan
regsvr32/u/S%windir%\system32\radminl.dll
REM for 98
regsvr32/u/S%windir%\system\radminl.dll
rem Hop-Hop Pond
REM This * * may not be deleted, please go to process management to terminate Webacc.exe this process
%windir%\system32\wbauninstall.exe
regsvr32/u/S%windir%\system32\webacc.dll
regsvr32/u/S%windir%\downlo~1\c8s.dll
REM for 98
%windir%\system\wbauninstall.exe
regsvr32/u/S%windir%\system\webacc.dll
REM seems like a convenience.
regsvr32/u/S C:\progra~1\xm\tbu3\xm.dll
REM ebay Shopping
Del%windir%\ebaylink.ico/q/F
REM Msdc32.dll a Trojan requires Safe mode to clear
Del c:\progra~1\common~1\system\msdc32.dll/q/F
Del%windir%\. exe/q/f/as/ar/ah
rem Yok Intercept Assistant
regsvr32/u/S C:\progra~1\yok.com\blockadr\yokhad.dll
regsvr32/u/S C:\progra~1\yok.com\supers~1\yok_supersearch.dll
regsvr32/u/S%windir%\system32\navsmall.dll
regsvr32/u/S%windir%\system\navsmall.dll
C:\progra~1\yok.com\blockadr\uninst.exe
REM Don't know what a rogue
regsvr32/u/S%windir%\downlo~1\vevnli.dll
REM Chajianhelper
regsvr32/u/S%windir%\system32\sysrea~1.dll
regsvr32/u/S%windir%\system\sysrea~1.dll
REM Don't know what a rogue
regsvr32/u/S%windir%\system32\helperservice.dll
regsvr32/u/S%windir%\system\helperservice.dll
regsvr32/u/S%windir%\system32\mshlp.dll
regsvr32/u/S%windir%\system\mshlp.dll
REM Mywebsearch This * *, the directory produced by this * is not possible at all
If exist rundll32 C:\progra~1\mywebs~1\bar\2.bin\mwsbar.dll rundll32 C:\progra~1\mywebs~1\bar\2.bin\mwsbar.dll,o
REM Happy Transport Express
regsvr32/u/S%windir%\system32\obwbkya.dll
REM for 98
regsvr32/u/S%windir%\system\obwbkya.dll
regsvr32/u/S%windir%\system32\shwasobj.dll
REM for 98
regsvr32/u/S%windir%\system\shwasobj.dll
C:\progra~1\sdastro\uninst.exe
REM, this file name will keep changing.
regsvr32/u/S C:\docume~1\alluse~1\applic~1\microsoft\iehelper\iehelper200631_8913.dll
REM Luobooshow
regsvr32/u/S%windir%\system32\winsc.dll
regsvr32/u/S%windir%\system\winsc.dll
REM Caishow
regsvr32/u/S "C:\Program files\caishow Tech\caishow\browerhelper.dll"
regsvr32/u/S%windir%\system32\wuwebex.dll
regsvr32/u/S%windir%\system\wuwebex.dll
REM Cool Desktop
regsvr32/u/S%windir%\system32\coolbho.dll
regsvr32/u/S%windir%\system\coolbho.dll
REM Youth Entertainment
regsvr32/u/S%windir%\system\qylwmp~1.ocx
regsvr32/u/S%windir%\system\qylrmp~1.ocx
regsvr32/u/S%windir%\system\contextmenu.dll
regsvr32/u/S C:\progra~1\qyule\\qyulep~1.ocx
regsvr32/u/S C:\PROGRA~1\QYULE\\DVFILTER.AX
C:\progra~1\qyule\unins000.exe
REM nb46.com Smflash.ocx seems to require safe mode
regsvr32/u/S "C:\Program Files\nb46.com\nb46toolbar.dll"
regsvr32/u/S%windir%\system32\smflash.ocx
regsvr32/u/S%windir%\system\smflash.ocx
REM Kuaiso Toolsbar
regsvr32/u/S "C:\Program files\micrsoft Searchbar\searchbar.dll"
REM Bbmao
regsvr32/u/S "C:\Program Files\bbmao Toolbar\bbmao_tb_v1_0.dll"
REM Delete CDN This * *
regsvr32/u/S C:\progra~1\cnnic\cdn\wmhlpr.dll
regsvr32/u/S C:\progra~1\cnnic\cdn\iesrch.dll
regsvr32/u/S C:\progra~1\cnnic\cdn\cdniehlp.dll
regsvr32/u/S C:\progra~1\cnnic\cdn\cdniehlp.dll
regsvr32/u/S C:\progra~1\cnnic\cdn\cdnforie.dll
regsvr32/u/S%windir%\system32\cdnns.dll
regsvr32/u/S%windir%\system32\jklpif.dll
REM for 98
regsvr32/u/S%windir%\system\cdnns.dll
regsvr32/u/S%windir%\system\jklpif.dll
REM CNNIC the reverse installation may not be good enough to uninstall in the Control Panel "Add/Remove" separately, or find C:\progra~1\cnnic\cdn\cdnunins.exe to perform
C:\progra~1\cnnic\cdn\cdnunins.exe
Un3721.reg
Copy Code code as follows:
REGEDIT4
REM Cut off all rogues, let us wait for the spring of the Internet ~_~
REM needs to be modified according to its own requirements (some people still think that a rogue is good to keep *_*)
; rem If you jump out of the selection box, select Uninstall All
REM some * * need to be in Safe mode to uninstall, some bad uninstall please see the help inside
REM Now the Rogue is getting super, has exceeded the capacity limit of batch processing, only with some other software, recommended to use Http://ccollomb.free.fr/unlocker together to delete super * *
rem cut off 3721 Kao messed up a lot of computers.
rem Cut Yahoo pig hands and messed up a lot of computers.
REM new version of the pig could not choose to uninstall, * * *, here can be unloaded
[-hkey_local_machine\software\classes\*\shellex\contextmenuhandlers\ Smash file]
[-hkey_local_machine\software\classes\.zschk]
[-hkey_local_machine\software\classes\angling.antifish]
[-hkey_local_machine\software\classes\angling.antifish.1]
[-hkey_local_machine\software\classes\assist.easyassist]
[-hkey_local_machine\software\classes\autolive.live]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\AUTOLIVE.LIVE.1]
[-hkey_local_machine\software\classes\clsid\{141a5e19-bdcb-4e27-a3d7-9e16503bc05b}]
[-hkey_local_machine\software\classes\adkiller.adkillerobj]
[-hkey_local_machine\software\classes\adkiller.adkillerobj.1]
[-hkey_local_machine\software\classes\clsid\{1b0e7716-898e-48cc-9690-4e338e8de1d3}]
[-hkey_local_machine\software\classes\clsid\{38928d50-8a48-44c2-945f-d2f23f771410}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{7CA83CF1-3AEA-42D0-A4E3-1594FC6E48B2}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{9EB2B422-C9EE-46C4-A471-1E79C7517B1D}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{ABEC6103-F6AC-43A3-834F-FB03FBA339A2}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}]
[-hkey_local_machine\software\classes\clsid\{bb936323-19fa-4521-ba29-eca6a121bc78}]
[-hkey_local_machine\software\classes\clsid\{d157330a-9ef3-49f8-9a67-4141ac41add4}]
[-hkey_local_machine\software\classes\cnshelper.ch]
[-hkey_local_machine\software\classes\cnsminhk.cnshook]
[-hkey_local_machine\software\classes\cnsminhk.cnshook.1]
[-hkey_local_machine\software\classes\coolbar.coolbarobj]
[-hkey_local_machine\software\classes\coolbar.coolbarobj.1]
[-hkey_local_machine\software\classes\fflash.flashobjectinterface]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\FFLASH.FLASHOBJECTINTERFACE.1]
[-hkey_local_machine\software\classes\interface\{172862cd-9d35-40e7-baf2-ba7ecf043b9c}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{1BB0ABBE-2D95-4847-B9D8-6F90DE3714C1}]
[-hkey_local_machine\software\classes\interface\{1d10645f-a553-426e-9923-c3abf846ea41}]
[-hkey_local_machine\software\classes\interface\{48e688c8-609f-4b08-944e-3c7fab99cd08}]
[-hkey_local_machine\software\classes\interface\{7436db12-1a7a-4d87-a4e0-713ec9d86050}]
[-hkey_local_machine\software\classes\interface\{924f5b3a-7a27-484a-b873-e855c9708667}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{BE08F6BC-C3E6-4149-BEB1-CB449E1B372E}]
[-hkey_local_machine\software\classes\interface\{c3a9f7f8-8862-496a-b8a4-25d4140b7dbc}]
[-hkey_local_machine\software\classes\interface\{d27cdb6d-ae6d-11cf-96b8-444553540000}]
[-hkey_local_machine\software\classes\typelib\{19069804-2cf0-4357-b696-ba6e9aad99ef}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{4158DB95-DE71-41FF-BEA1-2C3D1C679DF1}]
[-hkey_local_machine\software\classes\typelib\{7354662f-caa3-448b-bc01-04f55a2dca35}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{95A9BBCA-4EC1-4A9E-91AA-1D9633C38D0E}]
[-hkey_local_machine\software\classes\typelib\{a5adeae7-a8b4-4f94-9128-bf8d8db5e927}]
[-hkey_local_machine\software\classes\typelib\{aab6bce3-1df6-4930-9b14-9ca79dc8c267}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{D4839331-534D-4D0C-875F-D25AF6A10CCC}]
[-hkey_local_machine\software\classes\typelib\{f97e75a4-0103-4f27-a752-327b600b1130}]
[-hkey_local_machine\software\classes\zsmod.axobj]
[-hkey_local_machine\software\classes\zsmod.axobj.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{17F1C8E8-B99B-4D85-927B-A0EE7290455A}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{19CE93DE-8334-42C6-B2CA-BFE3DF5196A3}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{1C2EDD19-C2D5-4234-9339-785E5885B84D}]
[-hkey_local_machine\software\classes\clsid\{2283bb66-a15d-4ac8-ba72-9c8c9f5a1691}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{33BBE430-0E42-4F12-B075-8D21ACB10DCB}]
[-hkey_local_machine\software\classes\clsid\{38928d50-8a48-44c2-945f-d2f23f771410}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{406F94F0-504F-4A40-8DFD-58B0666ABEBD}]
[-hkey_local_machine\software\classes\clsid\{4558fa8b-c683-4bd9-bb43-90e086a4c113}]
[-hkey_local_machine\software\classes\clsid\{4b57d035-8a78-4e5a-82df-fd5dee51e578}]
[-hkey_local_machine\software\classes\clsid\{4ebcaf82-5be7-4fc5-938f-9cd284587139}]
[-hkey_local_machine\software\classes\clsid\{4f2c1a0a-622e-4d23-9870-6fb6d109c170}]
[-hkey_local_machine\software\classes\clsid\{55c32fb0-b5de-432d-b143-7ca84ea3f888}]
[-hkey_local_machine\software\classes\clsid\{57421194-58fb-49ae-9b4f-fd48869b9ad4}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{59E99ADD-E926-40E8-BD6F-1532124A4AAA}]
[-hkey_local_machine\software\classes\clsid\{62eed7c6-9f02-42f9-b634-98e2899e147b}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{6940DBA6-CEBB-46B6-8058-CB358295BCCC}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{6A915D6B-B187-4724-B753-F338D8A157C2}]
[-hkey_local_machine\software\classes\clsid\{7992e7f8-5d81-4eaa-9e5f-6211215946e4}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{8FC688E0-3F7D-4517-8C30-459C4211A8A1}]
[-hkey_local_machine\software\classes\clsid\{9c3c2c08-c494-4f52-ae94-85156a447d43}]
[-hkey_local_machine\software\classes\clsid\{a14600f7-e2ae-482d-9afc-99cd4544db4f}]
[-hkey_local_machine\software\classes\clsid\{ab9bf611-f86a-43c5-a467-625e22d7a309}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{AF53D70E-29DF-443A-92AA-9C314AF5871E}]
[-hkey_local_machine\software\classes\clsid\{b56ff3e8-b0c2-45c9-af3f-8e6c5f010b9f}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{B83FC273-3522-4CC6-92EC-75CC86678DA4}]
[-hkey_local_machine\software\classes\clsid\{c14f7681-33d8-11d3-a09b-00500402f30b}]
[-hkey_local_machine\software\classes\clsid\{c459ab59-28a5-43a3-9d22-753f4c9586e6}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{CA1E3092-BC38-4FFC-AEAE-C8E8EEC70CA1}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{CEA8FC9F-3D3F-4486-B9DF-ADCEE875FFB2}]
[-hkey_local_machine\software\classes\clsid\{d7c53e1a-7045-473c-933d-8228d1708947}]
[-hkey_local_machine\software\classes\clsid\{e3128a3a-c191-4149-8631-c632c8fc9919}]
[-hkey_local_machine\software\classes\clsid\{ef4ba0b4-a877-45b3-b0bc-ad7a3cc22811}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{F40FED3D-F813-42F4-A1AE-8E1D60472BF0}]
[-hkey_local_machine\software\classes\clsid\{fa6da3a4-87e4-4a45-9fd6-ed26089b7104}]
[-hkey_local_machine\software\classes\clsid\{fe3ecae7-0a37-4506-8a7d-3cc9a04d2ca8}]
[-hkey_local_machine\software\classes\clsid\{ff0e5df6-2375-4499-a97f-74954384d8d2}]
[-hkey_local_machine\software\classes\cnshelper.ch]
[-hkey_local_machine\software\classes\cnshelper.ch.1]
[-hkey_local_machine\software\classes\cnshelper.ch]
[-hkey_local_machine\software\classes\interface\{02db2793-f3f8-42ab-9b03-19b25485be29}]
[-hkey_local_machine\software\classes\interface\{924f5b3a-7a27-484a-b873-e855c9708667}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{BE08F6BC-C3E6-4149-BEB1-CB449E1B372E}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{C43273A6-9085-41CF-8A84-3881363A7EB9}]
[-hkey_local_machine\software\classes\interface\{d27cdb6d-ae6d-11cf-96b8-444553540000}]
[-hkey_local_machine\software\classes\interface\{dd011db1-0eaf-4d05-8650-bb99208c76b0}]
[-hkey_local_machine\software\classes\interface\{df692509-d9ef-48a0-9cd0-3aa5b81f6f68}]
[-hkey_local_machine\software\classes\jpegfile\shellex\contextmenuhandlers\yahoo!photo]
[-hkey_local_machine\software\classes\toolband.bandbutton]
[-hkey_local_machine\software\classes\toolband.bandbutton.1]
[-hkey_local_machine\software\classes\toolband.bandreg]
[-hkey_local_machine\software\classes\toolband.bandreg.1]
[-hkey_local_machine\software\classes\toolband.objectbar]
[-hkey_local_machine\software\classes\toolband.objectbar.1]
[-hkey_local_machine\software\classes\typelib\{04d0fd01-c8fa-413b-ad83-519d10b93324}]
[-hkey_local_machine\software\classes\typelib\{22242729-9ee0-4060-988d-be2a9efd8cd0}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{4158DB95-DE71-41FF-BEA1-2C3D1C679DF1}]
[-hkey_local_machine\software\classes\typelib\{51c76ab9-d876-46a8-a20d-f606eddd69ed}]
[-hkey_local_machine\software\classes\typelib\{5517390c-60d1-4ffa-bd4c-81f8278af29e}]
[-hkey_local_machine\software\classes\typelib\{58e9b715-3c97-4048-9cbe-a708e0aeb29e}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{7CFDAB57-D8CD-4465-BD15-48CFFCEE3DF2}]
[-hkey_local_machine\software\classes\typelib\{8417d3db-4004-4259-952d-a6ec64a1800e}]
[-hkey_local_machine\software\classes\typelib\{95e822b6-6b10-4e86-9603-6cecb6135867}]
[-hkey_local_machine\software\classes\typelib\{aab6bce3-1df6-4930-9b14-9ca79dc8c267}]
[-hkey_local_machine\software\classes\typelib\{ae9a3f59-e2d2-4ee8-a279-f2b6af336b8e}]
[-hkey_local_machine\software\classes\typelib\{cf67e74a-3c62-4867-9dfa-dd2374003333}]
[-hkey_local_machine\software\classes\typelib\{e816b7f9-96ab-4d4d-8da4-b9d124959da5}]
[-hkey_local_machine\software\classes\typelib\{f8cc28b5-4042-4054-99cb-8855efd0fab7}]
[-hkey_local_machine\software\classes\yahooassistbar.asnoadobj]
[-hkey_local_machine\software\classes\yahooassistbar.asnoadobj.1]
[-hkey_local_machine\software\classes\yahooassistbar.dragsearch]
[-hkey_local_machine\software\classes\yahooassistbar.dragsearch.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\YAHOOASSISTBAR.PHOTOTB]
[-hkey_local_machine\software\classes\yahooassistbar.phototb.1]
[-hkey_local_machine\software\classes\yalive.live]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\YALIVE.LIVE.1]
[-hkey_local_machine\software\classes\yassist.easyassist]
[-hkey_local_machine\software\classes\yassist.easyassist.1]
[-hkey_local_machine\software\classes\yrss.expband]
[-hkey_local_machine\software\classes\yrss.expband.1]
[-hkey_local_machine\software\classes\zschkfile]
[-hkey_local_machine\software\microsoft\internet explorer\advancedoptions\! CNS]
[-hkey_local_machine\software\microsoft\internet explorer\extensions\{00000000-0000-0001-0001-596baedd1289}]
[-hkey_local_machine\software\microsoft\internet explorer\extensions\{507f9113-cd77-4866-ba92-0e86da3d0b97}]
[-hkey_local_machine\software\microsoft\internet Explorer\extensions\{59bc54a2-56b3-44a0-93e5-432d58746e26}]
[-hkey_local_machine\software\microsoft\internet explorer\extensions\{5d73ee86-05f1-49ed-b850-e423120ec338}]
[-hkey_local_machine\software\microsoft\internet explorer\extensions\{e5d12c4e-7b4f-11d3-b5c9-0050045c3c96}]
[-hkey_local_machine\software\microsoft\internet explorer\extensions\{ecf2e268-f28c-48d2-9ab7-8f69c11ccb71}]
[-hkey_local_machine\software\microsoft\internet Explorer\extensions\{fd00d911-7529-4084-9946-a29f1bdf4fe5}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"SearchAssistant" =-
"Customizesearch" =-
"Ocustomizesearch" =-
"Osearchassistant" =-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
' {33BBE430-0E42-4F12-B075-8D21ACB10DCB} ' =-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\toolbar]
' {406f94f0-504f-4a40-8dfd-58b0666abebd} ' =-
' {bb936323-19fa-4521-ba29-eca6a121bc78} ' =-
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 33BBE430-0E42-4F12-B075-8D21ACB10DCB}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 38928D50-8A48-44C2-945F-D2F23F771410}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 62EED7C6-9F02-42F9-B634-98E2899E147B}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ BB936323-19FA-4521-BA29-ECA6A121BC78}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ D157330A-9EF3-49F8-9A67-4141AC41ADD4}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ FE3ECAE7-0A37-4506-8A7D-3CC9A04D2CA8}]
[Hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
' {d157330a-9ef3-49f8-9a67-4141ac41add4} ' =-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Helper.dll" =-
"CnsMin" =-
"Assistse" =-
"Hbpassport" =-
"YLive.exe" =-
"Yassistse" =-
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Cnsassecblk" =-
[-hkey_local_machine\software\microsoft\windows\currentversion\uninstall\cnsmin]
[-hkey_local_machine\software\microsoft\windows\currentversion\uninstall\{1b0e7716-898e-48cc-9690-4e338e8de1d3 }]
[-HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_CNSMINKP]
[-HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\CNSMINKP]
[-hkey_current_user\software\microsoft\internet explorer\menuext\! Search]
[-hkey_current_user\software\microsoft\internet explorer\menuext\ Add to Yahoo Subscriptions (&y)]
[-hkey_current_user\software\microsoft\internet explorer\menuext\ Yahoo Search]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Cnsmenu" =-
"Cnshint" =-
"Cnsreset" =-
"Cnsenable" =-
"Cnslist" =-
"Cnsautoupdate" =-
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\urlsearchhooks]
' {406f94f0-504f-4a40-8dfd-58b0666abebd} ' =-
' {bb936323-19fa-4521-ba29-eca6a121bc78} ' =-
[-hkey_local_machine\software\3721]
[-hkey_local_machine\software\yahoo]
[-hkey_current_user\software\3721]
[-hkey_current_user\software\microsoft\internet explorer\explorer BARS\{19CE93DE-8334-42C6-B2CA-BFE3DF5196A3}]
[-hkey_current_user\software\microsoft\windows\currentversion\ext\stats\{57421194-58fb-49ae-9b4f-fd48869b9ad4} ]
REM MMS through again a super * * has produced
REM Find a way to remove%windir%\system32\drivers\albus.sys this evil and unforgivable document, recommend to use Http://ccollomb.free.fr/unlocker
[-hkey_local_machine\system\controlset001\enum\root\legacy_albus]
[-hkey_local_machine\system\controlset001\services\albus]
[-hkey_local_machine\system\controlset002\services\albus]
[-hkey_local_machine\system\currentcontrolset\enum\root\legacy_albus]
[-hkey_local_machine\system\currentcontrolset\services\albus]
[-hkey_local_machine\software\classes\ad.axobj]
[-hkey_local_machine\software\classes\ad.axobj.1]
[-hkey_local_machine\software\classes\clsid\{6671a431-5c3d-463d-a7cf-5587f9b7e191}]
[-hkey_local_machine\software\classes\clsid\{6671a432-5c3d-463d-a7cf-5587f9b7e191}]
[-hkey_local_machine\software\classes\clsid\{6a512bf7-ec78-4e8d-9841-6c02e8fa9838}]
[-hkey_local_machine\software\classes\iehelper.winhelper]
[-hkey_local_machine\software\classes\iehelper.winhelper.1]
[-hkey_local_machine\software\classes\interface\{74289a79-e652-4a57-a6b9-ee64ad532a8d}]
[-hkey_local_machine\software\classes\interface\{ab45ce36-c280-4525-bcf9-1bd01d3e4b57}]
[-hkey_local_machine\software\classes\interface\{d922591d-7893-412b-b801-c3b2f31be4c9}]
[-hkey_local_machine\software\classes\mmsbho.mmsassist]
[-hkey_local_machine\software\classes\mmsbho.mmsassist.1]
[-hkey_local_machine\software\classes\mmsbho.mmsassistmenu]
[-hkey_local_machine\software\classes\mmsbho.mmsassistmenu.1]
[-hkey_local_machine\software\classes\typelib\{077525ac-c681-4139-8c3e-b582bdd375c7}]
[-hkey_local_machine\software\classes\typelib\{22f87d75-7dd1-4545-94b3-ca80c0f462c6}]
[-hkey_local_machine\software\classes\typelib\{964ddeff-b16c-4113-8ff7-8e83b53c8ed8}]
[-hkey_local_machine\software\microsoft\internet explorer\extensions\{6671a433-5c3d-463d-a7cf-5587f9b7e191}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 6671A431-5C3D-463D-A7CF-5587F9B7E191}]
[-hkey_local_machine\software\mmsassist]
[-hkey_local_machine\software\stdup]
[-hkey_current_user\software\microsoft\internet explorer\menuext\>> MMS send <<]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Alsmt.exe" =-
; rem Internet Explorer Helper Msshapi.dll
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{02C9B9AB-6372-46C5-B356-773FAF3B6B1E}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 02C9B9AB-6372-46C5-B356-773FAF3B6B1E}]
Delete the word Huaci is also a super * * * *
[-hkey_local_machine\software\classes\clsid\{594be7b2-23b0-4fae-a2b9-0c21cc1417ce}]
[-hkey_local_machine\software\classes\interface\{4e1ace40-f681-4cc4-a7c0-ad1e6c9ad86f}]
[-hkey_local_machine\software\classes\searchm.search]
[-hkey_local_machine\software\classes\searchm.search.1]
[-hkey_local_machine\software\classes\typelib\{fd536575-73f7-42a3-9e9f-11688f1a006a}]
[-hkey_local_machine\system\controlset001\enum\root\legacy_abhcop]
[-hkey_local_machine\system\controlset001\enum\root\legacy_hcalway]
[-hkey_local_machine\system\controlset001\services\abhcop]
[-hkey_local_machine\system\controlset001\services\hcalway]
[-hkey_local_machine\system\currentcontrolset\enum\root\legacy_abhcop]
[-hkey_local_machine\system\currentcontrolset\enum\root\legacy_hcalway]
[-hkey_local_machine\system\currentcontrolset\services\abhcop]
[-hkey_local_machine\system\currentcontrolset\services\hcalway]
[-hkey_current_user\software\pig move Search]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Movesearch" =-
; CDN This * *
[-hkey_local_machine\software\classes\cdn.cdnobj]
[-hkey_local_machine\software\classes\cdn.cdnobj.1]
[-hkey_local_machine\software\classes\cdnforie.iehlprobj]
[-hkey_local_machine\software\classes\cdnforie.iehlprobj.1]
[-hkey_local_machine\software\classes\clsid\{5c3853cf-c7e0-4946-b3fa-1abdb6f48108}]
[-hkey_local_machine\software\classes\clsid\{8cdcbba0-4be1-4199-8389-1b19ed41d3e8}]
[-hkey_local_machine\software\classes\clsid\{9a578c98-3c2f-4630-890b-fc04196ef420}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{F5824EFB-728A-4726-A5A5-85A68B20EDC3}]
[-hkey_local_machine\software\classes\interface\{5c3853cd-c7e0-4946-b3fa-1abdb6f48108}]
[-hkey_local_machine\software\classes\interface\{951a869a-1003-4897-948f-d55e570871db}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{9C991F1E-D6FE-4B74-B6EC-763FF528FAE1}]
[-hkey_local_machine\software\classes\interface\{f248ebab-d894-4682-80e3-f48aabf4b12d}]
[-hkey_local_machine\software\classes\typelib\{5c3853ce-c7e0-4946-b3fa-1abdb6f48108}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{C24A5A5C-0874-4386-85C7-E669F90997A9}]
[-hkey_local_machine\software\classes\typelib\{df571585-070d-4eb1-8b0e-99023f934fd4}]
[-hkey_local_machine\software\classes\wmhlpr.wmevtsink]
[-hkey_local_machine\software\cnnic]
[-hkey_local_machine\software\microsoft\internet Explorer\advancedoptions\cdnclient]
[-hkey_local_machine\software\microsoft\internet explorer\extensions\{5c3853cf-c7e0-4946-b3fa-1abdb6f48108}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 5C3853CF-C7E0-4946-B3FA-1ABDB6F48108}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ F5824EFB-728A-4726-A5A5-85A68B20EDC3}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 35980F6E-A137-4E50-953D-813BB8556899}]
[-hkey_local_machine\system\currentcontrolset\services\cdnprot]
[-hkey_local_machine\system\currentcontrolset\services\cdntran]
[-hkey_current_user\software\cnnic]
[-hkey_classes_root\clsid\{eed92a43-cfce-4548-bd73-b0a405470ed5}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cdnctr" =-
"Renewup" =-
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\extensions\cmdmapping]
' {5c3853cf-c7e0-4946-b3fa-1abdb6f48108} ' =-
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\urlsearchhooks]
' {Eed92a43-cfce-4548-bd73-b0a405470ed5} ' =-
[-hkey_current_user\software\microsoft\internet explorer\menuext\ access to the general website]
; Remove Stdup.dll This * *
[-hkey_local_machine\system\currentcontrolset\services\stdservice]
REM Baidu This is more and more ruthless, baid* is no exception
REM needs safe Mode or try to remove%windir%\system32\drivers\bdguard.sys this file to uninstall
[-hkey_local_machine\software\classes\baidubar.baidu]
[-hkey_local_machine\software\classes\baidubar.baidu.1]
[-hkey_local_machine\software\classes\baidubar.tool]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\BAIDUBAR.TOOL.1]
[-hkey_local_machine\software\classes\baidubarex.bandie]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\BAIDUBAREX.BANDIE.1]
[-hkey_local_machine\software\classes\baidubarex.droptarget]
[-hkey_local_machine\software\classes\baidubarex.droptarget.1]
[-hkey_local_machine\software\classes\clsid\{77fef28e-eb96-44ff-b511-3185dea48697}]
[-hkey_local_machine\software\classes\clsid\{7c76c055-ed6e-4535-a70f-cd476e727f67}]
[-hkey_local_machine\software\classes\clsid\{a7f05ee4-0426-454f-8013-c41e3596e9e9}]
[-hkey_local_machine\software\classes\clsid\{b580cf65-e151-49c3-b73f-70b13fca8e86}]
[-hkey_local_machine\software\classes\clsid\{fe14f22e-be14-4f08-a80f-f27bc3a67b2d}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{464C8A26-31E9-411C-9583-5B858E631DCC}]
[-hkey_local_machine\software\classes\interface\{89fdcc4b-8d91-49b0-81a6-18bcff582735}]
[-hkey_local_machine\software\classes\interface\{96249369-d3dc-4ae6-8a3b-e7109d46e98d}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{A294F8EB-86D9-4C4A-8B3E-909253761C64}]
[-hkey_local_machine\software\classes\mimefilter.adfilter]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{6AFC2761-1253-427C-9A56-385B4609BE1D}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\toolbar]
' {b580cf65-e151-49c3-b73f-70b13fca8e86} ' =-
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 77fef28e-eb96-44ff-b511-3185dea48697}]
[-hkey_local_machine\software\baidu]
[-hkey_current_user\software\microsoft\windows\currentversion\ext\stats\{b580cf65-e151-49c3-b73f-70b13fca8e86} ]
[-hkey_current_user\software\baidu]
[-hkey_current_user\software\microsoft\internet explorer\menuext\ Baidu--web search]
[-hkey_current_user\software\microsoft\internet explorer\menuext\ Baidu-Search MP3]
[-hkey_current_user\software\microsoft\internet explorer\menuext\ Baidu-Search pictures]
[-hkey_current_user\software\microsoft\internet explorer\menuext\ Baidu-Search News]
[-hkey_current_user\software\microsoft\internet explorer\menuext\ Baidu-Search lyrics]
[-hkey_current_user\software\microsoft\internet explorer\menuext\ Baidu-Search page]
[-hkey_current_user\software\microsoft\internet explorer\menuext\ Baidu-Search paste]
[-hkey_current_user\software\microsoft\internet explorer\menuext\ Baidu-Dictionary Search]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BIE" =-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Baiduds" =-
[-hkey_local_machine\system\controlset001\enum\root\legacy_bdguard]
[-hkey_local_machine\system\controlset001\services\bdguard]
[-hkey_local_machine\system\controlset002\enum\root\legacy_bdguard]
[-hkey_local_machine\system\controlset002\services\bdguard]
[-hkey_local_machine\system\currentcontrolset\enum\root\legacy_bdguard]
[-hkey_local_machine\system\currentcontrolset\services\bdguard]
; Delete SSAddr.dll Tencent address search bar
[-hkey_local_machine\software\classes\clsid\{0c7c23ef-a848-485b-873c-0ed954731014}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{90B1ECB2-FC3B-49AE-A6BD-F5F11BF5C4AD}]
[-hkey_local_machine\software\classes\clsid\{a57e074f-56d8-4a33-8112-aac9693aa909}]
[-hkey_local_machine\software\classes\clsid\{db8b2393-7a6c-4c76-88ce-6b1f6ff6ffe9}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{B1A7C2CF-BF40-4597-8142-7615D74D0CC3}]
[-hkey_local_machine\software\microsoft\internet EXPLORER\ADVANCEDOPTIONS\TBH]
[-hkey_local_machine\software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157b}]
[-hkey_local_machine\software\microsoft\internet Explorer\extensions\{dedeb80d-fa35-45d9-9460-4983e5a8afe6}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 0C7C23EF-A848-485B-873C-0ED954731014}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
' {db8b2393-7a6c-4c76-88ce-6b1f6ff6ffe9} ' =-
[-hkey_local_machine\software\microsoft\internet Explorer\urlsearchhooks]
' {db8b2393-7a6c-4c76-88ce-6b1f6ff6ffe9} ' =-
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\urlsearchhooks]
' {db8b2393-7a6c-4c76-88ce-6b1f6ff6ffe9} ' =-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AddrPlus3" =-
[-HKEY_LOCAL_MACHINE\SOFTWARE\TENCENT\TBH]
[-hkey_current_user\software\microsoft\internet explorer\menuext\ upload to QQ network hard disk]
[-hkey_current_user\software\microsoft\internet Explorer\menuext\ added to QQ custom Panel]
[-hkey_current_user\software\microsoft\internet Explorer\menuext\ added to QQ expression]
[-hkey_current_user\software\microsoft\internet explorer\menuext\ send the picture with QQ MMS]
[-hkey_current_user\software\microsoft\windows\currentversion\ext\stats\{0c7c23ef-a848-485b-873c-0ed954731014} ]
; Delete QQIEHelper.dll
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 54EBD53A-9BC1-480B-966A-843A333CA162}]
; remove virus Irjit. DLL Library Station MORE QQ expression * *
[-hkey_local_machine\software\classes\clsid\{d1bb7cf4-4463-4e91-88d7-ecc3ce0a13b7}]
[-hkey_local_machine\software\classes\interface\{0083de51-eb2e-4521-a95c-735d8e563373}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\QUICKBUTTON.QUICKBTN]
[-hkey_local_machine\software\classes\sss1.sss2.1]
[-hkey_local_machine\software\classes\typelib\{933db9d6-9447-4efe-aba2-eaf3b309b44c}]
[-hkey_local_machine\software\microsoft\internet EXPLORER\EXTENSIONS\{1D901067-2529-4A9B-9B6B-7A1DB3A44CB5}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ D1BB7CF4-4463-4E91-88D7-ECC3CE0A13B7}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Update" =-
[-hkey_local_machine\system\controlset001\services\bness]
[-hkey_local_machine\system\controlset001\services\eventlog\application\bness]
[-hkey_local_machine\system\currentcontrolset\services\bness]
[-hkey_local_machine\system\currentcontrolset\services\eventlog\application\bness]
[-hkey_local_machine\software\lamp]
[-hkey_current_user\software\microsoft\windows\currentversion\ext\stats\{d1bb7cf4-4463-4e91-88d7-ecc3ce0a13b7} ]
[-hkey_local_machine\system\currentcontrolset\services\universal Disk Manager]
[-hkey_local_machine\system\currentcontrolset\services\mobill]
; Delete Kugoo
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ A9930D97-9CF0-42A0-A10D-4F28836579D5}]
[-hkey_current_user\software\microsoft\internet explorer\menuext\ use KuGoo3 download (&k)]
; Delete network this is stupid.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Pigupdate" =-
; rem deletion Henbang is great * *
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\APPID\{8AB6C00E-A068-44E9-953F-1BCFEEA2BB6A}]
[-hkey_local_machine\software\classes\clsid\{21dad172-d8c3-40ca-b7d3-e28ae7a5db22}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{8AB6C00E-A068-44E9-953F-1BCFEEA2BB6A}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{BE0B5843-553A-48C2-9A42-258A1D791AFC}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{7C7E302E-B015-4E6E-A761-C28D78F3BC5A}]
[-hkey_local_machine\software\classes\interface\{9aed6826-a68c-4aa0-a370-de54c0d40788}]
[-hkey_local_machine\software\classes\typelib\{aac356cf-178b-4612-b1db-ee153846bf58}]
[-hkey_local_machine\software\classes\hbhelper.hbactivex]
[-hkey_local_machine\software\classes\hbhelper.hbactivex.1]
[-hkey_local_machine\software\classes\richmedia.bhoobject]
[-hkey_local_machine\software\classes\richmedia.bhoobject.1]
[-hkey_local_machine\software\classes\appid\{b6773538-228e-4d2f-9599-70dd9bbd2cb0}]
[-hkey_local_machine\software\classes\clsid\{b6773538-228e-4d2f-9599-70dd9bbd2cb0}]
[-hkey_local_machine\software\classes\interface\{bc8f8692-d345-44e0-93ff-efb1ba6aa962}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{9660E66E-AF14-4946-8249-1A640BBABFCC}]
[-hkey_local_machine\software\classes\hapspy.hapclientspy]
[-hkey_local_machine\software\classes\hapspy.hapclientspy.1]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 21DAD172-D8C3-40CA-B7D3-E28AE7A5DB22}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ BE0B5843-553A-48C2-9A42-258A1D791AFC}]
[-hkey_local_machine\software\richmedia]
[-hkey_current_user\software\microsoft\windows\currentversion\ext\stats\{21dad172-d8c3-40ca-b7d3-e28ae7a5db22} ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HDP" =-
"Hbpassport" =-
"Richmedia" =-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Mscfs" =-
"Iehelper" =-
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 1A199C20-DE2B-4838-AE3F-B5257ECE2B7E}]
; REM Sogou
[-hkey_local_machine\software\classes\. $p 4p$]
[-hkey_local_machine\software\classes\autolink. AUTOLINKBHO]
[-hkey_local_machine\software\classes\autolink. Autolinkbho.1]
[-hkey_local_machine\software\classes\clsid\{083863f1-70de-11d0-bd40-00a0c911ce86}\instance\{ 238D0F23-5DC9-45A6-9BE2-666160C324DD}]
[-hkey_local_machine\software\classes\clsid\{083863f1-70de-11d0-bd40-00a0c911ce86}\instance\{ 765035B3-5944-4A94-806B-20EE3415F26F}]
[-hkey_local_machine\software\classes\clsid\{083863f1-70de-11d0-bd40-00a0c911ce86}\instance\{ 941A4793-A705-4312-8DFC-C11CA05F397E}]
[-hkey_local_machine\software\classes\clsid\{083863f1-70de-11d0-bd40-00a0c911ce86}\instance\{ e21be468-5c18-43eb-b0cc-db93a847d769}]
[-hkey_local_machine\software\classes\clsid\{083863f1-70de-11d0-bd40-00a0c911ce86}\instance\{ F1CDA468-8A08-449F-9FB8-461C3DED0E03}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{08B13A8E-EB71-4421-B417-4EC0995D5BFC}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{0CA51D02-7739-43EA-8D9A-1E8AD4327B03}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{238D0F23-5DC9-45A6-9BE2-666160C324DD}]
[-hkey_local_machine\software\classes\clsid\{5aa23b9d-99c0-4a41-a25d-58e806766680}]
[-hkey_local_machine\software\classes\clsid\{765035b3-5944-4a94-806b-20ee3415f26f}]
[-hkey_local_machine\software\classes\clsid\{7fd094e7-c8b9-40bd-9f80-f20a7194d2e6}]
[-hkey_local_machine\software\classes\clsid\{81b9a3d6-d79f-403e-939b-4f2be8fd2a34}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{8755CE6E-0BF7-4441-8751-FB728941B0B4}]
[-hkey_local_machine\software\classes\clsid\{8ab8528f-ac8b-416d-9b84-92d97729c195}]
[-hkey_local_machine\software\classes\clsid\{941a4793-a705-4312-8dfc-c11ca05f397e}]
[-hkey_local_machine\software\classes\clsid\{acbf9eb9-48c5-4226-9967-2e3247a04510}]
[-hkey_local_machine\software\classes\clsid\{bab1ac41-6ff7-4f2e-a04e-5c592ccfea7d}]
[-hkey_local_machine\software\classes\clsid\{d977d6a9-be13-496d-9be4-175dfac12628}]
[-hkey_local_machine\software\classes\clsid\{dbbb7978-af21-4ef4-9ad1-b2f4bc75696c}]
[-hkey_local_machine\software\classes\clsid\{deee7fe9-3e06-43ee-b04d-18866cd0ad9c}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{E03667BC-5EDA-4FD8-992C-ED73265AFAA0}]
[-hkey_local_machine\software\classes\clsid\{e21be468-5c18-43eb-b0cc-db93a847d769}]
[-hkey_local_machine\software\classes\clsid\{f1cda468-8a08-449f-9fb8-461c3ded0e03}]
[-hkey_local_machine\software\classes\clsid\{f20a9999-11dc-4071-87a9-35191dfddaa6}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{F4FB516E-8F16-44FD-AB1D-260C32B7CF9A}]
[-hkey_local_machine\software\classes\comploader.loader]
[-hkey_local_machine\software\classes\media type\{e436eb83-524f-11ce-9f53-0020af0ba770}\{ 57428EC6-C2B2-44A2-AA9C-28F0B6A5C48E}]
[-hkey_local_machine\software\classes\sgsearchhook.sgurlsearhook]
[-hkey_local_machine\software\classes\sodaiehelper.catch]
[-hkey_local_machine\software\classes\sogoutb. Detector]
[-hkey_local_machine\software\classes\toolbar.bhoobj]
[-hkey_local_machine\software\microsoft\internet EXPLORER\EXTENSIONS\{8755CE6E-0BF7-4441-8751-FB728941B0B4}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 0CA51D02-7739-43EA-8D9A-1E8AD4327B03}]
[-hkey_local_machine\software\sohu R&d]
[-HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\P4P Service]
[-HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\P4P Service]
[-hkey_current_user\software\sohu R&d]
;
[-hkey_current_user\software\microsoft\internet explorer\menuext\ use MMS to send to mobile phone with super self write
[-hkey_current_user\software\microsoft\internet explorer\menuext\ use sina download assistant DOWNLOAD]
[-hkey_current_user\software\microsoft\internet explorer\menuext\ Send pictures to mobile phone (&m)]
[-hkey_current_user\software\microsoft\internet explorer\menuext\ Collection This page to Sina Vivi]
[-hkey_current_user\software\microsoft\internet explorer\menuext\ Sina Search]
; Search addresses in
[-hkey_local_machine\software\classes\clsid\{2a0176fe-008b-4706-90f5-bba532a49731}]
[-hkey_local_machine\software\classes\interface\{d1afed83-9133-4660-8c8f-daf1b4a3d5a8}]
[-hkey_local_machine\software\classes\typelib\{e8d3778f-47d3-4f1f-9245-3d46856936e4}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\SNHPR.CSNHPR]
[-hkey_local_machine\software\classes\snhpr.csnhpr.1]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 2a0176fe-008b-4706-90f5-bba532a49731}]
[-hkey_local_machine\software\searchnet]
[-HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_ANFAD]
[-HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET001\ENUM\ROOT\LEGACY_FAD]
[-hkey_local_machine\system\controlset001\enum\root\legacy_jmediaservice]
[-HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET001\SERVICES\ANFAD]
[-hkey_local_machine\system\controlset001\services\eventlog\application\remote Log]
[-HKEY_LOCAL_MACHINE\SYSTEM\CONTROLSET001\SERVICES\FAD]
[-hkey_local_machine\system\controlset001\services\jmediaservice]
[-hkey_local_machine\system\controlset001\services\remote Log]
[-HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_ANFAD]
[-HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_FAD]
[-hkey_local_machine\system\currentcontrolset\enum\root\legacy_jmediaservice]
[-HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\ANFAD]
[-hkey_local_machine\system\currentcontrolset\services\eventlog\application\remote Log]
[-HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\FAD]
[-hkey_local_machine\system\currentcontrolset\services\jmediaservice]
[-hkey_local_machine\system\currentcontrolset\services\remote Log]
[-hkey_current_user\software\microsoft\windows\currentversion\ext\stats\{6a512bf7-ec78-4e8d-9841-6c02e8fa9838} ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Searchnet_up" =-
REM seems to be the happy journey this * *
[-hkey_local_machine\system\currentcontrolset\services\sdagentservice]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoftredirectionprogram" =-
"Res" =-
; REM ebay Shopping
[-hkey_local_machine\software\microsoft\internet explorer\extensions\{ee60714f-ac17-427e-861a-fd60cbdf119a}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\extensions\cmdmapping]
' {ee60714f-ac17-427e-861a-fd60cbdf119a} ' =-
REM Msdc32.dll a Trojan requires Safe mode to clear
[Hkey_local_machine\software\microsoft\windows\currentversion\policies\explorer\run]
"Ip_sec" =-
; Rem an advertisement Navihelper.dll
[-hkey_current_user\appid\navihelper.dll]
[-hkey_current_user\navihelper.navihelperobj]
[-hkey_current_user\navihelper.navihelperobj.1]
[-HKEY_CURRENT_USER\CLSID\{3E422F49-1566-40D3-B43D-077EF739AC32}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 3E422F49-1566-40D3-B43D-077EF739AC32}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Supdate2.dll" =-
[-hkey_classes_root\update2.update2]
[-hkey_classes_root\update2.update2.1]
[-hkey_classes_root\clsid\{ecf9c696-8018-41b4-8dad-cfd1c732dc61}]
[-HKEY_CLASSES_ROOT\TYPELIB\{752C3608-0BD6-4035-83D5-6CE383AED6B4}]
[-hkey_classes_root\interface\{c6aad6fd-08d3-47f7-a8a2-1d7ef923dad1}]
; rem Hop-hop-pond This * *
REM This * * may not be deleted, please go to process management to remove Webacc.exe this process
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Webacc" =-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Webacc" =-
"Mu071c" =-
; REM Baigoo this * * BG
[-hkey_local_machine\software\baigoo]
[-hkey_local_machine\software\classes\appid\{40ef7ccc-71fe-4615-a0ca-d373f8c2ac88}]
[-hkey_local_machine\software\classes\appid\mtsrv.exe]
[-hkey_local_machine\software\classes\baigooex.update]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\BAIGOOEX.UPDATE.1]
[-hkey_local_machine\software\classes\baigoopm.bhohelper]
[-hkey_local_machine\software\classes\baigoopm.bhohelper.1]
[-hkey_local_machine\software\classes\baigoopm.browserobject]
[-hkey_local_machine\software\classes\baigoopm.browserobject.1]
[-hkey_local_machine\software\classes\bgoobho.status]
[-hkey_local_machine\software\classes\bgoobho.status.1]
[-hkey_local_machine\software\classes\bgoosrv.htmlpaser]
[-hkey_local_machine\software\classes\clsid\{7905958a-18c2-4139-9957-ae6f2b754818}]
[-hkey_local_machine\software\classes\clsid\{7bdaf75a-0d6f-4f50-afe9-333d08df4005}]
[-hkey_local_machine\software\classes\clsid\{808eaf87-61b8-4eea-8b85-27480d1bdbee}]
[-hkey_local_machine\software\classes\clsid\{8816ea7a-5944-4277-b98e-2c0a46fb36e9}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{4A8976FE-144E-4742-8E49-D6CD3B140FD1}]
[-hkey_local_machine\software\classes\typelib\{690e010b-042a-4973-87a8-485deb8bdf68}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{9DC44A38-B772-47F8-A406-054F842EC7C5}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 7BDAF75A-0D6F-4F50-AFE9-333D08DF4005}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Bgoomain.exe" =-
; REM Yok interception assistant
; Navsmall.dll
[-hkey_local_machine\software\classes\clsid\{1bc02872-bc5e-46be-ba76-6b0170fe6bfe}]
[-hkey_local_machine\software\classes\protocols\filter\text/html]
[-hkey_local_machine\software\classes\clsid\{972566b2-93bf-41aa-b06d-5f81db7e38e1}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{C3E2C12D-FACF-43BB-BE10-B1CDD497BFC9}]
[-hkey_local_machine\software\classes\clsid\{c7fa2a99-d9af-4112-b197-436016c2f72f}]
[-hkey_local_machine\software\classes\clsid\{f869bb38-ffef-4589-b986-610b7ad0ada2}]
[-hkey_local_machine\software\classes\interface\{1a1798cc-9120-40b1-ba68-1d1415973232}]
[-hkey_local_machine\software\classes\interface\{1e69a80b-b19a-49ad-805e-98447883bed3}]
[-hkey_local_machine\software\classes\interface\{3e42acd2-b79d-4495-a6e5-9d972b19d815}]
[-hkey_local_machine\software\classes\interface\{871385f0-7e91-42d4-9b91-cd5611274531}]
[-hkey_local_machine\software\classes\typelib\{261ee951-024f-4903-b880-ada965e72885}]
[-hkey_local_machine\software\classes\typelib\{628508ec-44ab-4990-b751-a3005d28053f}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 972566B2-93BF-41AA-B06D-5F81DB7E38E1}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ F869BB38-FFEF-4589-B986-610B7AD0ADA2}]
[-hkey_local_machine\software\classes\sms. Smsobject]
[-hkey_local_machine\software\classes\sms. Smsobject.1]
[-hkey_local_machine\software\classes\yokhookadr.httpfilter]
[-hkey_local_machine\software\classes\yokhookadr.httpfilter.1]
[-hkey_local_machine\software\classes\yokhookadr.yokbho]
[-hkey_local_machine\software\classes\yokhookadr.yokbho.1]
[-hkey_local_machine\software\classes\yokhookadr.yokblockadr]
[-hkey_local_machine\software\classes\yokhookadr.yokblockadr.1]
[-hkey_local_machine\software\navsmall]
[-hkey_local_machine\software\yok]
[-hkey_current_user\software\yok]
[-hkey_current_user\software\microsoft\internet Explorer\toolbar]
' {1e796980-9cc5-11d1-a83f-00c04fc99d61} ' =-
[-hkey_current_user\software\microsoft\windows\currentversion\ext\stats\{972566b2-93bf-41aa-b06d-5f81db7e38e1} ]
; rem don't know what a rogue
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{8D 515F39-EBD0-0B9E-6719-2F8D8869AA61}]
[-hkey_classes_root\clsid\{8d515f39-ebd0-0b9e-6719-2f8d8869aa61}]
; rem don't know what a rogue
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ ce7c3cf0-4b15-11d1-abed-709549c10000}]
[-hkey_classes_root\clsid\{ce7c3cf0-4b15-11d1-abed-709549c10000}]
; rem VIPTray.exe Thousand Oaks This * * Ie-bar Desktop Media
[-hkey_local_machine\software\classes\appid\bhorun.dll]
[-hkey_local_machine\software\classes\appid\delayload.dll]
[-hkey_local_machine\software\classes\appid\{65ef7ad4-1340-4a36-a097-95ff17e243e1}]
[-hkey_local_machine\software\classes\appid\{84d34084-4e38-4683-a4db-ca00646fee8b}]
[-hkey_local_machine\software\classes\bhorun.bhelper]
[-hkey_local_machine\software\classes\bhorun.bhelper.1]
[-hkey_local_machine\software\classes\delayload.loadrun]
[-hkey_local_machine\software\classes\delayload.loadrun.1]
[-hkey_local_machine\software\classes\dmbar.dmbar]
[-hkey_local_machine\software\classes\dmbar.dmbar.1]
[-hkey_local_machine\software\classes\dmbho.browserhelper]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{16358834-52FC-4981-9A79-BFECE7C08CD3}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{1FCA37BA-7259-4BF1-878B-A39FA83BFBBB}]
[-hkey_local_machine\software\classes\clsid\{2d99e8f4-56b7-457b-9a92-61b5d247d263}]
[-hkey_local_machine\software\classes\clsid\{5a6f2f95-3191-433b-8533-eb0b596a7bac}]
[-hkey_local_machine\software\classes\clsid\{f2e37336-bfdb-409b-8d0e-6f013c438b20}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{265379DB-90F0-45DB-9B10-640DCB1145FD}]
[-hkey_local_machine\software\classes\interface\{7eb718dd-e41f-446a-9c1e-757f921168a0}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{8C9377D3-D823-46A6-A8AC-B3913F9B6CA2}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{25649A6A-637D-4416-9D03-98146330492A}]
[-hkey_local_machine\software\classes\typelib\{292d202f-e519-45f4-8d50-de8513b87ce9}]
[-hkey_local_machine\software\classes\typelib\{86645afc-0b33-4275-bfe6-fae9fcd886d1}]
[-hkey_local_machine\software\ie-bar]
[-hkey_local_machine\software\microsoft\internet explorer\explorer BARS\{1FCA37BA-7259-4BF1-878B-A39FA83BFBBB}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 2d99e8f4-56b7-457b-9a92-61b5d247d263}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ F2E37336-BFDB-409B-8D0E-6F013C438B20}]
[-hkey_local_machine\software\sharehelper]
[-hkey_current_user\software\sharehelper]
[-hkey_local_machine\software\sharehelper]
[-hkey_local_machine\system\currentcontrolset\services\viptray]
[-hkey_local_machine\system\currentcontrolset\services\te1net]
[-hkey_current_user\software\microsoft\internet explorer\explorer BARS\{1FCA37BA-7259-4BF1-878B-A39FA83BFBBB}]
[Hkey_local_machine\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"Delayrun" =-
; REM Chajianhelper
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 0CB66BA8-5E1F-4963-93D1-E1D6B78FE9A2}]
; REM HelperService.dll
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 9E1E1371-9D8F-4421-81B9-F8D2E1773A59}]
; REM Wmicsmgr.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Wmicsmgr" =-
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 333872c4-92d6-4396-8542-64ab96518950}]
; Smartlinkservice (slservice)-Slmdmsr.exe
[-hkey_local_machine\system\currentcontrolset\services\slservice]
REM a What Wubi
[-hkey_local_machine\software\classes\clsid\{ed8dfc5c-10ef-45ab-9dc2-0639aff5a270}]
[-hkey_local_machine\software\classes\interface\{cbc67cd5-855c-4a69-b450-a0508fda5234}]
[-hkey_local_machine\software\classes\typelib\{c0cdc83c-fea7-499f-9be7-a9ab4eaed292}]
[-hkey_local_machine\software\classes\update.bho]
[-hkey_local_machine\software\classes\update.bho.1]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ ED8DFC5C-10EF-45AB-9DC2-0639AFF5A270}]
; REM Mywebsearch
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{00A6FAF1-072E-44CF-8957-5838F569A31D}]
[-hkey_local_machine\software\classes\clsid\{07b18ea1-a523-4961-b6bb-170de4475cca}]
[-hkey_local_machine\software\classes\clsid\{0f8ecf4f-3646-4c3a-8881-8e138ffcaf70}]
[-hkey_local_machine\software\classes\clsid\{147a976f-eee1-4377-8ea7-4716e4cdd239}]
[-hkey_local_machine\software\classes\clsid\{25560540-9571-4d7b-9389-0f166788785a}]
[-hkey_local_machine\software\classes\clsid\{2eff3cf7-99c1-4c29-bc2b-68e057e22340}]
[-hkey_local_machine\software\classes\clsid\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8}]
[-hkey_local_machine\software\classes\clsid\{3e720452-b472-4954-b7aa-33069eb53906}]
[-hkey_local_machine\software\classes\clsid\{53ced2d0-5e9a-4761-9005-648404e6f7e5}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{7473D292-B7BB-4F24-AE82-7E2CE94BB6A9}]
[-hkey_local_machine\software\classes\clsid\{84da4fdf-a1cf-4195-8688-3e961f505983}]
[-hkey_local_machine\software\classes\clsid\{8e6f1832-9607-4440-8530-13be7c4b1d14}]
[-hkey_local_machine\software\classes\clsid\{938aa51a-996c-4884-98ce-80dd16a5c9da}]
[-hkey_local_machine\software\classes\clsid\{98d9753d-d73b-42d5-8c85-4469cda897ab}]
[-hkey_local_machine\software\classes\clsid\{9afb8248-617f-460d-9366-d71cdeda3179}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}]
[-hkey_local_machine\software\classes\clsid\{a9571378-68a1-443d-b082-284f960c6d17}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}]
[-hkey_local_machine\software\classes\clsid\{b813095c-81c0-4e40-aa14-67520372b987}]
[-hkey_local_machine\software\classes\clsid\{c9d7be3e-141a-4c85-8cd6-32461f3df2c7}]
[-hkey_local_machine\software\classes\clsid\{cff4ce82-3aa2-451f-9b77-7165605fb835}]
[-hkey_local_machine\software\classes\clsid\{d9fffb27-d62a-4d64-8cec-1ff006528805}]
[-hkey_local_machine\software\classes\funwebproducts.datacontrol]
[Hkey_local_machine\software\focusinteractive]
' {07b18ea9-a523-4961-b6bb-170de4475cca} ' =-
[-hkey_local_machine\software\microsoft\office\outlook\addins\mywebsearch.outlookaddin]
[-hkey_local_machine\software\microsoft\office\word\addins\mywebsearch.outlookaddin]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 00A6FAF1-072E-44CF-8957-5838F569A31D}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 07B18EA1-A523-4961-B6BB-170DE4475CCA}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Mywebsearch Email Plugin" =-
[-hkey_local_machine\software\mywebsearch]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\urlsearchhooks]
' {00a6faf6-072e-44cf-8957-5838f569a31d} ' =-
; REM Happy Transport Express MEOBJECTSDT Shwasobj.dll
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 4136C3F6-7636-49BF-A122-D4DA53B1ADDF}]
REM myiehelper Iehelper_****.dll This file name will change constantly.
[-hkey_local_machine\software\classes\clsid\{16a770a0-0e87-4278-b748-2460d64a8386}]
[-hkey_local_machine\software\classes\iehelper.myiehelper]
[-hkey_local_machine\software\classes\iehelper.myiehelper.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{A4BC2506-C00C-4D2E-B47F-0BB4C2C74CCF}]
[-hkey_local_machine\software\classes\typelib\{2511de40-34a3-4c6a-b1b2-c5c92a2f00be}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 16A770A0-0E87-4278-B748-2460D64A8386}]
; REM windirected Proud Wmpdrm.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SPOOLSV" =-
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\APPID\WMPDRM. DLL]
[-hkey_local_machine\software\classes\clsid\{0e674588-66b7-4e19-9d0e-2053b800f69f}]
[-hkey_local_machine\software\classes\interface\{4a775183-9517-420e-9a13-d3da47bb8a84}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{8B200623-3FC5-4493-8B49-DC2AD4830AF4}]
[-hkey_local_machine\software\classes\wmpdrm.cfsbho]
[-hkey_local_machine\software\classes\wmpdrm.cfsbho.1]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 0E674588-66B7-4E19-9D0E-2053B800F69F}]
; REM ActiveBandObject.dll
[-hkey_local_machine\software\classes\activebandobject.activebho]
[-hkey_local_machine\software\classes\activebandobject.activebho.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{63C55A7F-6E29-8D4F-5C76-4F850F28D13A}]
[-hkey_local_machine\software\classes\interface\{ab6ec1fc-83b0-4ef2-a128-785bafc2a2b5}]
[-hkey_local_machine\software\classes\typelib\{2f80a49b-9fa3-4fa0-a964-4689b0c1b30b}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 63C55A7F-6E29-8D4F-5C76-4F850F28D13A}]
; rem Stroke Search Deskipn.dll
[-hkey_local_machine\software\classes\clsid\{08a312bb-5409-49fc-9347-54bb7d069ac6}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{9C1CE329-606F-4C0F-8A85-9C2818878AF3}]
[-hkey_local_machine\software\classes\monitorie.monitorurl]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\MONITORIE.MONITORURL.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{647BB013-E900-473E-BC10-99CF3AC365AD}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 08A312BB-5409-49FC-9347-54BB7D069AC6}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Desktop" =-
[-hkey_current_user\software\deskadtop]
; WinSC.dll Luobooshow
[-hkey_local_machine\software\classes\appid\scintruder.dll]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\APPID\{35A69597-0E2A-4100-A394-C6F6FC2535B9}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{0D8CA512-282E-4E3F-8970-F5EE879AF7FC}]
[-hkey_local_machine\software\classes\clsid\{566cb5f7-d9fa-4b01-8a1a-168f706cbe41}]
[-hkey_local_machine\software\classes\clsid\{86dc8694-aacc-4ce6-b8ec-a75deeda698d}]
[-hkey_local_machine\software\classes\clsid\{9aceee30-143f-471a-aa45-72b061fe7d60}]
[-hkey_local_machine\software\classes\clsid\{c5668031-4bde-43d4-8766-8e9aac16c56e}]
[-hkey_local_machine\software\classes\clsid\{ded96f80-2b97-407c-8e09-d7233448753f}]
[-hkey_local_machine\software\classes\interface\{172754b5-06e9-49d4-b1e0-7d821e23c5e8}]
[-hkey_local_machine\software\classes\interface\{1b631ef9-ebd4-4828-abb2-1afb96e2ea4e}]
[-hkey_local_machine\software\classes\interface\{36f305a9-4451-4fdf-9274-28f21e2a2f14}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{B513A7FC-BC53-4077-ABE3-5BD321AF651D}]
[-hkey_local_machine\software\classes\interface\{bcc53a8c-67a7-4e8f-b971-d4668d1a7423}]
[-hkey_local_machine\software\classes\interface\{c88fd25f-8d53-4e99-aea0-18f22801ce8c}]
[-hkey_local_machine\software\classes\interface\{d1f6e94e-8ea1-4ec8-914c-138bc55ae104}]
[-hkey_local_machine\software\classes\newwebcontroller.intruder]
[-hkey_local_machine\software\classes\newwebcontroller.intruder.1]
[-hkey_local_machine\software\classes\scintruder.documenteventshandler]
[-hkey_local_machine\software\classes\scintruder.documenteventshandler.1]
[-hkey_local_machine\software\classes\scintruder.magazines]
[-hkey_local_machine\software\classes\scintruder.magazines.1]
[-hkey_local_machine\software\classes\scintruder.service]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\SCINTRUDER.SERVICE.1]
[-hkey_local_machine\software\classes\scintruder.settings]
[-hkey_local_machine\software\classes\scintruder.settings.1]
[-hkey_local_machine\software\classes\scintruder.windoweventshandler]
[-hkey_local_machine\software\classes\scintruder.windoweventshandler.1]
[-hkey_local_machine\software\classes\typelib\{5cd75223-e010-4be9-9027-7a53533ea4f6}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 9ACEEE30-143F-471A-AA45-72B061FE7D60}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Msservice_v1.0" =-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Luobooshow" =-
[-hkey_local_machine\software\scintruder]
; REM Caishow
[-hkey_local_machine\software\caishow]
[-hkey_local_machine\software\classes\appid\browerhelpermfc.dll]
[-hkey_local_machine\software\classes\appid\download.dll]
[-hkey_local_machine\software\classes\appid\mmsfactory.dll]
[-hkey_local_machine\software\classes\appid\mmssend.dll]
[-hkey_local_machine\software\classes\appid\ssoaddionalindical. DLL]
[-hkey_local_machine\software\classes\appid\{18e8c855-ff2e-4beb-b9d2-e7b25af92a48}]
[-hkey_local_machine\software\classes\appid\{22a36e6e-07cb-4851-aa84-5fc1ca73a1de}]
[-hkey_local_machine\software\classes\appid\{37bc804e-e26b-4d09-836f-ac15fc0c253e}]
[-hkey_local_machine\software\classes\appid\{88abd365-12ae-44e7-8450-da5c3653325b}]
[-hkey_local_machine\software\classes\appid\{f375f726-23d3-4179-9ca2-54fe6e490879}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\APPID\{FBB4D7BA-CCD3-457D-BEFF-F3B1757BD6B1}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\BROWERHELPERMFC.CAISHOWBH]
[-hkey_local_machine\software\classes\browerhelpermfc.caishowbh.1]
[-hkey_local_machine\software\classes\clsid\{083863f1-70de-11d0-bd40-00a0c911ce86}\instance\{ 3C78B8E2-6C4D-11D1-ADE2-0000F8754B99}]
[-hkey_local_machine\software\classes\clsid\{0e6e0b51-0300-4ae2-b6c4-f4efe33a33b2}]
[-hkey_local_machine\software\classes\clsid\{32f64094-a155-4554-8753-e5e267a8c002}]
[-hkey_local_machine\software\classes\clsid\{3af40cb8-b3ba-4e2d-8968-4bf8db172997}]
[-hkey_local_machine\software\classes\clsid\{3c78b8e2-6c4d-11d1-ade2-0000f8754b99}]
[-hkey_local_machine\software\classes\clsid\{5673a7c0-95cc-4646-bb07-3bd71234cef9}]
[-hkey_local_machine\software\classes\clsid\{6abb6c58-feb7-43ae-946a-af05d074f493}]
[-hkey_local_machine\software\classes\clsid\{dd6c4862-4bf9-48ce-bd27-9838e30d3dd5}]
[-hkey_local_machine\software\classes\download.download]
[-hkey_local_machine\software\classes\download.download.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{315420B2-E5C8-4E7B-B812-6676BA4F30CE}]
[-hkey_local_machine\software\classes\interface\{6ca6de10-8705-4e1b-9117-bcfa5bece14b}]
[-hkey_local_machine\software\classes\interface\{ce98ad53-16f1-48d3-9208-1203aa19f77e}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{D32D8A55-A21A-4237-B8BB-5A5EBEE6746D}]
[-hkey_local_machine\software\classes\interface\{dbd14208-5f2f-40b8-8d97-6de44c1d2e3d}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{F6CE85C8-99E7-49F5-A1A2-03FFC4FF09A5}]
[-hkey_local_machine\software\classes\mmsfactory.send]
[-hkey_local_machine\software\classes\mmsfactory.send.1]
[-hkey_local_machine\software\classes\mmssend.send]
[-hkey_local_machine\software\classes\mmssend.send.1]
[-hkey_local_machine\software\classes\my.netaccelerate]
[-hkey_local_machine\software\classes\ssoaddionalindical. Identify]
[-hkey_local_machine\software\classes\ssoaddionalindical. Identify.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{1F805A43-0E95-4245-8EAF-9271D520722A}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{73D53D7B-66DF-419B-9B44-CF3F42ADF5C9}]
[-hkey_local_machine\software\classes\typelib\{864f198d-6568-4686-b4f5-4a970b85e58b}]
[-hkey_local_machine\software\classes\typelib\{89a99589-82b0-4983-a882-e8d8db3da5c7}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{CEBE027D-5423-41B8-AF51-9F1C22557CC6}]
[-hkey_local_machine\software\classes\typelib\{d0581d47-e3cb-402d-b8a6-5f8561b2a36c}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 3af40cb8-b3ba-4e2d-8968-4bf8db172997}]
[-hkey_current_user\software\microsoft\internet explorer\menuext\ send the picture with a bright color)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Caishowmanage" =-
; rem Cool Desktop Letscool.exe CoolBho.dll
[-hkey_local_machine\software\letscool]
[-hkey_local_machine\software\microsoft\windows\currentversion\app Paths\letscool.exe]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Letscool" =-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Letscool" =-
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ F0C15012-7DBD-4068-95A2-0A82DB03AC35}]
; REM Schedule Sscli.dll
[-hkey_local_machine\software\classes\at.helper]
[-hkey_local_machine\software\classes\at.helper.1]
[-hkey_local_machine\software\classes\clsid\{8b316da1-9950-4926-b9ea-1aec124afa45}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 8B316DA1-9950-4926-B9EA-1AEC124AFA45}]
; REM Youth Entertainment
[-hkey_local_machine\software\classes\*\shellex\contextmenuhandlers\qylupload]
[-hkey_local_machine\software\classes\clsid\{083863f1-70de-11d0-bd40-00a0c911ce86}\instance\{ EB86A239-96D9-4F34-BCCD-E1E13D09577B}]
[-hkey_local_machine\software\classes\clsid\{2236fab7-7bdd-4187-831b-c7d809ca2e24}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{53AE3F49-4985-4245-9AFE-2D3A14DCF7CD}]
[-hkey_local_machine\software\classes\clsid\{81b5c8fe-07bd-4020-b299-79c0be1a3946}]
[-hkey_local_machine\software\classes\clsid\{e70fe57a-19aa-4a4c-b39a-408d49d73851}]
[-hkey_local_machine\software\classes\clsid\{eb86a239-96d9-4f34-bccd-e1e13d09577b}]
[-hkey_local_machine\software\classes\clsid\{ec987c58-81a2-4d2c-993d-d0e1945d7e7c}]
[-hkey_local_machine\software\classes\clsid\{f349a88e-33cf-46e7-8091-6ef28491168d}]
[-hkey_local_machine\software\classes\contextmenu.upload]
[-hkey_local_machine\software\classes\contextmenu.upload.1]
[-hkey_local_machine\software\classes\interface\{0775f38b-6cf8-40b1-9a9d-43e6bff4660d}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{60F02175-7F65-4F3B-AC6B-CB842B921ECD}]
[-hkey_local_machine\software\classes\interface\{82044df3-e304-4034-b16d-2d5a83979744}]
[-hkey_local_machine\software\classes\interface\{a188d411-8ed2-487e-9d25-2eaca8330956}]
[-hkey_local_machine\software\classes\interface\{a32c5a11-aa68-4d61-8217-0953f704d3ca}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\INTERFACE\{BDD8A4E1-B6EE-4C4E-B6DA-0A1E627477DD}]
[-hkey_local_machine\software\classes\interface\{e9dc930a-4ac3-4eed-98ab-e2097edbace9}]
[-hkey_local_machine\software\classes\qyule. Rmplayer]
[-hkey_local_machine\software\classes\qyule. WMPLAYER.9]
[-hkey_local_machine\software\classes\qyuleplayer. QYULEPLAYERCTRL.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{72DB4BF2-6C70-4297-857C-4B2D9E1F452C}]
[-hkey_local_machine\software\classes\typelib\{8f3b47e6-31ba-4089-8c23-683526e67984}]
[-hkey_local_machine\software\classes\typelib\{905aa0ba-a402-4f56-9e39-3817edd89786}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TYPELIB\{9AD54178-E7AE-4528-A79D-48D7E79202EE}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Clientqyule" =-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Clientqyule" =-
[-hkey_current_user\software\qyule]
[-hkey_current_user\software\smartclient]
; Kuaiso Toolsbar
[-hkey_local_machine\software\classes\clsid\{6d53adb7-6ad5-4a59-bfe4-7b57d2f4aa89}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{B07D1F6B-6B8C-4904-8EE8-5E5A2B4624B3}]
[-hkey_local_machine\software\classes\typelib\{d57df8cf-66b7-412c-a7d1-64b5f5f7fe27}]
[-hkey_local_machine\software\classes\toolband.xbtp03129]
[-hkey_local_machine\software\classes\toolband.xbtp03129.1]
[-hkey_local_machine\software\classes\xbtb03129. Ietoolbar]
[-hkey_local_machine\software\classes\xbtb03129. Ietoolbar.1]
[-hkey_local_machine\software\classes\xbtb03129. XBTB03129]
[-hkey_local_machine\software\classes\xbtb03129. XBTB03129.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\toolbar]
' {6d53adb7-6ad5-4a59-bfe4-7b57d2f4aa89} ' =-
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ B07D1F6B-6B8C-4904-8EE8-5E5A2B4624B3}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\toolbar\webbrowser]
' {6d53adb7-6ad5-4a59-bfe4-7b57d2f4aa89} ' =-
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\urlsearchhooks]
' {6d53adb7-6ad5-4a59-bfe4-7b57d2f4aa89} ' =-
[-hkey_current_user\software\microsoft\windows\currentversion\ext\stats\{6d53adb7-6ad5-4a59-bfe4-7b57d2f4aa89} ]
[-hkey_current_user\software\microsoft\windows\currentversion\ext\stats\{b07d1f6b-6b8c-4904-8ee8-5e5a2b4624b3} ]
[-hkey_current_user\software\xbtb03129]
; REM Bbmao
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{6AE02E1C-8859-4F57-9097-5A55A56A4CAF}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{72BA415A-AE03-4279-ACAB-39A3DF73FD4E}]
[-hkey_local_machine\software\classes\typelib\{68a7c985-87d6-4635-b498-3290613c718e}]
[-hkey_local_machine\software\classes\toolband.xbtp05676]
[-hkey_local_machine\software\classes\toolband.xbtp05676.1]
[-hkey_local_machine\software\classes\xbtb05676. Ietoolbar]
[-hkey_local_machine\software\classes\xbtb05676. Ietoolbar.1]
[-hkey_local_machine\software\classes\xbtb05676. XBTB05676]
[-hkey_local_machine\software\classes\xbtb05676. XBTB05676.1]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\toolbar]
' {6AE02E1C-8859-4F57-9097-5A55A56A4CAF} ' =-
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 72BA415A-AE03-4279-ACAB-39A3DF73FD4E}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\user Agent\Post Platform]
"Bbmao Toolbar" =-
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\toolbar\webbrowser]
' {6AE02E1C-8859-4F57-9097-5A55A56A4CAF} ' =-
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{6AE02E1C-8859-4F57-9097-5A55A56A4CAF} ]
[-HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{72BA415A-AE03-4279-ACAB-39A3DF73FD4E} ]
[-hkey_current_user\software\bbmao]
[-hkey_current_user\software\xbtb05676]
REM NB46 Smflash.ocx seems to require safe mode.
[-hkey_local_machine\software\classes\clsid\{1a50bdd0-01a6-4d58-958b-b9bc66789327}]
[-hkey_local_machine\software\classes\clsid\{56e88004-7af8-474c-bb30-76e0b7b2b003}]
[-hkey_local_machine\software\classes\interface\{a09b9056-f52e-413f-ae1d-5371dfe0d7b9}]
[-hkey_local_machine\software\classes\nb46toolbar.conb46bho]
[-hkey_local_machine\software\classes\typelib\{f3e2c17e-e43f-4ad8-9232-15f33f95e044}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 1a50bdd0-01a6-4d58-958b-b9bc66789327}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{14A21378-5BB1-4BC4-95D5-5D3F51527F6F}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser Helper Objects\{ 14A21378-5BB1-4BC4-95D5-5D3F51527F6F}]
Download this file