Agent BN manual removal:
Kill processes:
kthemup.exe, evwr.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2106BEDE-F5E8-4DE8-A081-A7E5EAD1529B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2106BEDE-F5E8-4DE8-A081-A7E5EAD1529B}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2106BEDE-F5E8-4DE8-A081-A7E5EAD1529B}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2106BEDE-F5E8-4DE8-A081-A7E5EAD1529B}\Programmable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2106BEDE-F5E8-4DE8-A081-A7E5EAD1529B}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2106BEDE-F5E8-4DE8-A081-A7E5EAD1529B}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64DE95E5-0A25-4DD9-A472-97BC1D419101}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64DE95E5-0A25-4DD9-A472-97BC1D419101}\InprocServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64DE95E5-0A25-4DD9-A472-97BC1D419101}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64DE95E5-0A25-4DD9-A472-97BC1D419101}\Programmable
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64DE95E5-0A25-4DD9-A472-97BC1D419101}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64DE95E5-0A25-4DD9-A472-97BC1D419101}\VersionIndependentProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{75F78888-8FA5-4F93-9354-8B256E0B2CD3}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{75F78888-8FA5-4F93-9354-8B256E0B2CD3}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A55D8DC0-5A3C-430E-B1AD-2CBDBA3126CF}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A55D8DC0-5A3C-430E-B1AD-2CBDBA3126CF}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{94089F18-F67B-46BC-8393-E65B3727FFFA}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D585A96E-6899-465A-9485-3E6A194DB664}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\ProxyStubClsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\ProxyStubClsid32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DF1CEDBD-E8D8-4490-B5ED-17377B36CCAD}\TypeLib
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\FLAGS
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3090402E-B1CE-43D1-8950-20FE0E88ADD9}\1.0\HELPDIR
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\0\win32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\FLAGS
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F1D3D0FE-0453-43F6-AD98-D252E41E84A7}\1.0\HELPDIR
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSVPS.MSVPSApp
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSVPS.MSVPSApp\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSVPS.MSVPSApp\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\nssfrch.StockBar
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\nssfrch.StockBar\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\nssfrch.StockBar\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\nssfrch.ToolBar.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\nssfrch.ToolBar.1\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64DE95E5-0A25-4DD9-A472-97BC1D419101}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebVideo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VideoPlugin
Unregister DLLs:bxsbang.dll, movctrlswd.dll, nssfrch.dll, ocgrep.dll
Delete files:bxsbang.dll, movctrlswd.dll, nssfrch.dll, ocgrep.dll, kthemup.exe, evwr.exe