WinProtector 3.8 manual removal:
Kill processes:
AAVSetup[1].exe un[1].exe lla0.exe lla1.exe ubpr01.exe WinProtector.exe
Delete registry values:HKEY_CLASSES_ROOT\CLSID\{629340b5-8df6-4211-9245-a86563a35792}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{9034a523-d068-4be8-a284-9df278be776e}
HKEY_CLASSES_ROOT\spywarning.warningbho
HKEY_CLASSES_ROOT\spywarning.warningbho.1
HKEY_CLASSES_ROOT\CLSID\{f58ff278-2198-403b-9170-c95022a194c6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{f58ff278-2198-403b-9170-c95022a194c6}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{daed9266-8c28-4c1c-8b58-5c66eff1d302}
HKEY_CLASSES_ROOT\CLSID\{d46beaa4-a304-40b3-a9da-ec7f7f501f25}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d46beaa4-a304-40b3-a9da-ec7f7f501f25}
HKEY_CLASSES_ROOT\ascwarning32.warningbho
HKEY_CLASSES_ROOT\ascwarning32.warningbho.1
HKEY_CLASSES_ROOT\CLSID\{58472bc6-bea3-42d4-8917-7a8bcb0711b5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{58472bc6-bea3-42d4-8917-7a8bcb0711b5}
HKEY_CURRENT_USER\SOFTWARE\asc 2.1
HKEY_CURRENT_USER\SOFTWARE\ASpyC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Safety Alert
HKEY_CURRENT_USER\SOFTWARE\Web Technologies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{629340b5-8df6-4211-9245-a86563a35792}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ASC32
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ASpyC
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wblogon
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Search\searchassistant
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search\searchassistant
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\search page
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\search bar
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\searchmigrateddefaulturl
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\default_search_url
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\searchurl
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\default_search_url
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\search page
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\search bar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\searchmigrateddefaulturl
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\searchurl
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\some
Unregister DLLs:C:\\WINDOWS\\system32\\uszhv.dll C:\\WINDOWS\\system32\\219725\\219725.dll
Delete files:Files\\Content.IE5\\VN9EP3LR\\AAVSetup[1].exe Files\\Content.IE5\\A0J1286D\\AAVSetup[1].exe s\\Content.IE5\\DUTKOF9K\\un[1].exe C:\\WINDOWS\\system32\\ubpr01.exe C:\\Documents and Settings\\Schatzie94\\Local Settings\\Temp\\lla0.exe C:\\Documents and Settings\\Schatzie94\\Local Settings\\Temp\\lla1.exe C:\\WINDOWS\\system32\\ubpr01.exe WinProtector.exe
Delete directories:C:\WINDOWS\system32\219725
Post Comment: