Rewardnet manual removal:
Kill processes:
isgooddayi.exe, update.exe, wslgooddayi.exe
Delete registry values:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\websv
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\websv
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\dkbLauncher.coLauncher
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\dkbLauncher.coLauncher.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\LiteX.LiteConnection
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\LiteX.LiteConnection.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\LiteX.LiteStatement
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\LiteX.LiteStatement.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RewardNet.Utility
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RewardNet.Utility.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RewardNetwork.WebGuide
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RewardNetwork.WebGuide.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RewardNetwork.coHelper
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RewardNetwork.coHelper.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RewardNetwork.coLauncher
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RewardNetwork.coLauncher.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RewardNetwork.IEToolbar
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RewardNetwork.IEToolbar.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RewardNetwork.InfoBand
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RewardNetwork.InfoBand.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RewardNetwork.InfoBandObj
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RewardNetwork.InfoBandObj.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RewardNetwork.InHelper
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RewardNetwork.InHelper.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RewardNetwork.XLToolbar
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RewardNetwork.XLToolbar.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RewardNetwork.ShopGuide
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\RewardNetwork.ShopGuide.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CB0CF42-DA54-47d2-8999-23928A2DEA42}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3E22694D-7B92-42A1-89A7-668E2F7AA107}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3F0771CC-458C-369F-AD08-E555A5C2E2E3}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{453A51CC-F944-4643-9540-A78253B8019C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{462CE774-9B41-4C5B-BE01-17ABB60E688F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{654A13EB-86F4-4592-B138-81986C4A08E2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{688F6649-8FFB-4E76-8924-74C0EC0827A4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7732E3A4-AB48-33A9-9AB8-443C710E09A3}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{86BA3446-BCC4-323B-9EC5-EEE4D1EB8DB1}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9519BB86-28B6-4a0e-A5F7-FD81C56BC505}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0B73C9D-78A6-36C7-B365-104FE04FD373}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0B73C9D-78A6-36C7-B365-104FE04FD375}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AB8A4FC4-6523-4180-A8DC-21A2E227EDA2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AD13FFC0-BA5D-4B6C-ACBF-D1C44D0DA9B5}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D6112BF8-8F9F-4b42-AC9C-9900EBB895C3}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DF301EBA-70DE-376D-A3CE-777429C9D703}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DF301EBA-70DE-376D-A3CE-777429C9D705}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F382D9F9-25D5-4f44-A6FF-33DACB2851A3}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F90BB714-01B6-438B-8993-F6E46ACBFA24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3CB0CF42-DA54-47d2-8999-23928A2DEA42}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3F0771CC-458C-369F-AD08-E555A5C2E2E1}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{462CE774-9B41-4C5B-BE01-17ABB60E688F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7ADFDFCF-8B4E-42A2-B458-3CA6F2DB7FE4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7732E3A4-AB48-33A9-9AB8-443C710E09A1}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{688F6649-8FFB-4E76-8924-74C0EC0827A4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{86BA3446-BCC4-323B-9EC5-EEE4D1EB8DB1}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{92851AEF-6984-4087-A0AC-804FE71DFD87}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A0B73C9D-78A6-36C7-B365-104FE04FD371}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A0B73C9D-78A6-36C7-B365-104FE04FD376}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A9E460E9-23EE-4BA8-B3D8-F1FBC88BE462}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D6112BF8-8F9F-4B42-AC9C-9900EBB895C1}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DF301EBA-70DE-376D-A3CE-777429C9D701}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DF301EBA-70DE-376D-A3CE-777429C9D704}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F8635DDA-650D-44F2-AB42-7A096A4FD507}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F90BB714-01B6-438B-8993-F6E46ACBFA24}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{10770BEB-5AFA-4851-B68E-EE891F3DEE7F}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3CB0CF42-DA54-47d2-8999-23928A2DEA42}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{3F0771CC-458C-369F-AD08-E555A5C2E2E2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{4F4BC58D-B12A-411F-B55E-A9A2D8269F77}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{7732E3A4-AB48-33A9-9AB8-443C710E09A2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{7F699F81-05D3-4958-8E00-D2E5AD4F02F4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{86BA3446-BCC4-323B-9EC5-EEE4D1EB8DB2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A0B73C9D-78A6-36C7-B365-104FE04FD372}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C36A6F17-1909-45D5-AA32-DD2AD66AB482}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D6112BF8-8F9F-4B42-AC9C-9900EBB895C2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{DF301EBA-70DE-376D-A3CE-777429C9D702}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{EF95B826-3798-4ED0-86A4-06F292EF68A8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F90BB714-01B6-438B-8993-F6E46ACBFA24}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{86BA3446-BCC4-323B-9EC5-EEE4D1EB8DB3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{A0B73C9D-78A6-36C7-B365-104FE04FD373}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F90BB714-01B6-438B-8993-F6E46ACBFA24}
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{A0B73C9D-78A6-36C7-B365-104FE04FD373}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{20ECA797-B523-4e89-8210-FFFD3CD0F696}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{2DDC6074-A97A-43c5-903C-5095972A18F6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EC9679F6-42B7-4593-9E1C-AF421066C123}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost
HKEY_LOCAL_MACHINE\SOFTWARE\RewardNet
HKEY_LOCAL_MACHINE\SOFTWARE\RewardNetwork
HKEY_LOCAL_MACHINE\SOFTWARE\ShopGuide
HKEY_LOCAL_MACHINE\SOFTWARE\WebGuide
HKEY_LOCAL_MACHINE\SOFTWARE\XlToolBar
Unregister DLLs:rnutil.dll, webguide.dll, websv.dll
Delete files:isgooddayi.exe, update.exe, wslgooddayi.exe, rnutil.dll, webguide.dll, websv.dll
Delete directories:C:\Program Files\RewardNet
C:\Program Files\RewardNetwork
C:\Program Files\WebGuide
Misc:Exact file location:
rnutil.dll - C:\Program Files\RewardNet
webguide.dll, websv.dll - C:\Program Files\WebGuide
update.exe - C:\Program Files\RewardNetwork and C:\Program Files\WebGuide
wslgooddayi.exe - C:\Documents and Settings\[Current User]\Local Settings\Temp
isgooddayi.exe - C:\Documents and Settings\[Current User]\Local Settings\Temporary Internet Files
Comments from visitors:
1. by Guest. 2008-01-08 17:01:25
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionSvcHost
is not good. Windows doesn't work well if services aren't running...
A better idea would be to delete the "rewardnet" variable under the SvcHost key.