Medload manual removal:
Kill processes:
medload.exe, medload3.exe, imbuddy2.exe, hisistheurls.exe, mm[X].exe, newpop[X].exe, seeve.exe, thin-[XVS].exe, unstall.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\loads.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\seeve.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sixtysix
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\popuppers
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\popuppers64
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\(Default)=%Windir%\System32\objsafe.tlb
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\(Default)=%Windir%\Downloaded Program Files\m[X]m.ocx
HKEY_CURRENT_USER\Software\WinRAR SFX\C:\Program Files\joystick networks\setup
HKEY_CURRENT_USER\Software\WinRAR SFX\C:\Documents and Setttings\[Current User]\Desktop
HKEY_CLASSES_ROOT\IObjSafety.DemoCtl
HKEY_CLASSES_ROOT\CLSID\{7149E79C-DC19-4C5E-A53C-A54DDF75EEE9}
HKEY_CLASSES_ROOT\CLSID\{E0CE16CB-741C-4B24-8D04-A817856E07F4}
HKEY_CLASSES_ROOT\Interface\{3E4BCF50-865B-4EF4-A0BC-BF57229EA525}
HKEY_CLASSES_ROOT\Interface\{64A5BD22-8D8A-4193-9CF8-7DB5212ABB17}
HKEY_CLASSES_ROOT\Interface\{674A6BD5-317A-49CF-9647-1E085E660CE0}
HKEY_CLASSES_ROOT\Interface\{9F61CFDF-5C79-4D35-B4DA-766B28367223}
HKEY_CLASSES_ROOT\Interface\{A9136CFD-FD01-41B8-9969-0B37720ED8AB}
HKEY_CLASSES_ROOT\Interface\{AD29366C-63AA-4FF3-944F-91AD7193BCA2}
HKEY_CLASSES_ROOT\Interface\{B2EEDA99-DA99-4D0D-9F7F-143C30521388}
HKEY_CLASSES_ROOT\Interface\{E832FFDE-8ED2-47B7-BE50-729A238040A0}
HKEY_CLASSES_ROOT\TypeLib\{466C63AC-F26E-49F1-861A-E07DA768A46A}
HKEY_CLASSES_ROOT\TypeLib\{78A163D2-2358-464D-807B-0E2A078C7727}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\InternetSettings\ZoneMap\Domains\media-motor.net
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\InternetSettings\ZoneMap\Domains\popuppers.com
HKEY_LOCAL_MACHINE\SOFTWARE\mm
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7149E79C-DC19-4C5E-A53C-A54DDF75EEE9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/Windows/System32/objsafe.tlb
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/Windows/Downloaded Program Files/m[X]m.ocx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\media-motor
Delete files:medload.exe, medload3.exe, imbuddy2.exe, hisistheurls.exe, mm[X].exe, newpop[X].exe, seeve.exe, thin-[X].exe, unstall.exe, mm[X].ocx, m[X]m.ocx, objsafe.tlb, ubber60.ini
Delete directories:C:\Program Files\joystick networks
Misc:[X] is a number. [XVS] is the version number and name.
Exact file location:
medload.exe, hisistheurls.exe, seeve.exe, thin-[XVS].exe, mm[X].ocx, ubber60.ini, unstall.exe - C:\Windows or C:\Winnt
mm[X].ocx, m[X]m.ocx - C:\Windows\Downloaded Program Files
objsafe.tlb - C:\Windows\System32