Security Stronghold security made easy

Lop.com Removal: Remove Lop.com Easily


* What is Lop.com

* Download WiperSoft Antispyware Malware Remediation Tool

* Remove Lop.com manually

* Get Professional Support

* Read Comments


Threat indicator: HIGH

Threat's profile

Name of the threat:

Command or file name:

Threat type:

Affected OS:

Lop.com

sed.exe

Spyware

Win32 (Windows XP, Vista, Seven, 8)


Many Lop.com advertising treat cartoon banners which can be visually annoying for buyers creating a absolute necessity of Lop.com removal tools or at the least Lop.com removal scan. Wheen Lop.com violate anti-porn movies legislation when offsprings are the consumers. Unsanctioned accession to a PC is illegal under PC crime laws making Lop.com outlaw. Expanding of Lop.com is counted as a criminal action but that doesn't connote that you don't ought to to setup Lop.com removal tools because judicial proceedings will save you. Lop.com removal tools can remove Lop.com by protecting this time installation of Lop.com on PC. Lop.com can be scanned by Lop.com removal tools when performing Lop.com removal stopping any trys of it to penetrate in the computer.


Lop.com intrusion method

Lop.com copies its file(s) to your hard disk. Its typical file name is sed.exe. Then it creates new startup key with name Lop.com and value sed.exe. You can also find it in your processes list with name sed.exe or Lop.com. Also, it can create folder with name Lop.com under C:\Program Files\ or C:\ProgramData.

If you have further questions about Lop.com, please call us on the phone below. It is toll free. Or you can use programs to remove Lop.com automatically below.


Download Spyhunter by Enigma Software

Download this advanced removal tool and solve problems with Lop.com and sed.exe (download of fix will start immediately):

Download WiperSoft Antispyware to remove Lop.com

* WiperSoft Antispyware was developed to remove threats like Lop.com in automatic mode. Remover has active module to protect PC from hijackers, trojans, ransomware and other viruses. Trial version of SpyHunter provides detection of computer viruses for FREE. To remove malware, you have to purchase the full version of Spyhunter.

Features of WiperSoft Antispyware

* Removes all files created by viruses.

* Removes all registry entries created by viruses.

* You can activate System and Network Guards and forget about malware.

* Can fix browser problems and protect browser settings.

* Removal is guaranteed - if SpyHunter fails ask for FREE support.

* 24/7 Spyware Helpdesk Support included into the package.


Download Spyhunter Remediation Tool by Enigma Software

Download antimalware designed specifically to remove threats like Lop.com and sed.exe (download of fix will start immediately):

Download AntiMalware to remove Lop.com

Features of Spyhunter Remediation Tool

* Removes all files created by Lop.com.

* Removes all registry entries created by Lop.com.

* Fixes browser redirection and hijack if needed.

* "Toolbar Remover" tool will help you get rid of unwanted browser extensions.

* Removal is guaranteed - if Spyhunter Remediation Tool fails ask for FREE support.

* 24/7 Helpdesk Support and 5 hours of Remote Support via GoToAssist included into the package.

Let our support team solve your problem with Lop.com and repair Lop.com right now!

support person

Call us using the number below and describe your problem with Lop.com. Support team will offer you solution in several minutes and give a step-by-step instruction on how to remove Lop.com. Trouble-free tech support with over 10 years experience removing malware.


1-877-219-8984


Software Industry Professionals Member
Threat's description and solution are developed by Security Stronghold security team.

Here you can also learn:

* Technical details of Lop.com threat.

* Manual Lop.com removal.

* Download Lop.com Removal Tool.


How to remove Lop.com manually?

This problem can be solved manually by deleting all registry keys and files connected with Lop.com, removing it from starup list and unregistering all corresponding DLLs. Additionally missing DLL's should be restored from distribution in case they are corrupted by Lop.com.

To get rid of Lop.com, you should:

file logo

1. Kill the following processes and delete the appropriate files:

  • 1111.exe
  • 2443.exe
  • 24701.exe
  • 2dimensionofexploits.asm
  • 2dimensionofexploitsenc.hta
  • 2dimensionofexploitsenc.php
  • activeonce.exe
  • afa6d429.exe
  • agreement-.htm
  • ahlrfsoy.exe
  • ante.exe
  • antedefault.dll
  • aswnk.exe
  • aswwxs.reg
  • atiupdate2.exe
  • backup.reg
  • bags more bold.exe
  • bash second cast.exe
  • bendaceproc.exe
  • bike poke.dll
  • bind funk inside.exe
  • binsect.exe
  • bitsplaygrid.exe
  • bore2mags.exe
  • bytemess.exe
  • campglueflap.exe
  • cash remote.exe
  • cast idle.dll
  • ckouvcrcgcea.dll
  • corn bold media.exe
  • cyd1.exe
  • debug anti anti.exe
  • debugregs.exe
  • defy view.exe
  • does admin.exe
  • download_plugin.exe
  • each cdrom memo.exe
  • eshglkfvcr.dll
  • etu1.exe
  • exploit1.htm
  • femguyse.exe
  • film.exe
  • filmpeak.dll
  • fmtah.exe
  • frag drv first boob.exe
  • freemp3z.exe
  • fullscreenbar.htm
  • funktypebinfffccc.exe
  • glzchtb.lib
  • great 1.exe
  • great each close.exe
  • greyplan.exe
  • header (1).htm
  • header (2).htm
  • header (3).htm
  • header.htm
  • heart setup inside.bin
  • heartflaw.exe
  • help support.exe
  • hope1media.exe
  • hoxujhed.exe
  • hpt1.exe
  • install.htm
  • installation report download_plugin.htm
  • interarmy.exe
  • jumpnoundate.exe
  • keep comp.exe
  • khzc256.tmp
  • kind joy bib.exe
  • ktbxbllyth.dll
  • kvgpmfiv.exe
  • lejytfqx.exe
  • liesbagslist.exe
  • links.txt
  • lite cake loud.exe
  • lniegfer.exe
  • loadcashmeet.exe
  • logo vc.exe
  • longonlineplay.exe
  • lop notes.txt
  • lrgluoot.exe
  • lyzkisnf.dll
  • mail mess.exe
  • mp3.exe
  • mp3serch.exe
  • mp3_plugin.exe
  • nxfbmzqu.exe
  • onlinecontent.lnk
  • passthrough[1].htm
  • pile default.exe
  • pkajulyt.exe
  • plus size.exe
  • popupbaropener[1].htm
  • refslow.exe
  • removelop.exe
  • rgg1.exe
  • rpzgnwux.exe
  • rvimsmkf.exe
  • sect name.exe
  • sekkzgif.exe
  • setup time.dll
  • sfx71e4.tmp
  • sfxbe.tmp
  • sign support mags.exe
  • sizewaitgrim.exe
  • soft team.exe
  • software grim.dll
  • software_plugin.exe
  • ssaxstxoaieoagrh.reg
  • sta1f.exe
  • sta2.exe
  • tchstlmmdrm.htm
  • tfsuxbtg.exe
  • time funk aim.exe
  • toolbar_uninstall.exe
  • twunk001.mtx
  • ulyfchcrcrdcr.htm
  • waybait.exe
  • web default one.exe
  • winactivej.exe
  • winactivej_unpacked.exe
  • wshbrybr.exe
  • xlj1.exe
  • xxeoxiqu.exe
  • xyq.exe
  • ystck32.exe
  • yxogltoo.exe
  • ckcoofrunea.exe
  • adult.lnk
  • gambling and online casinos.lnk
  • mp3 music search.lnk
  • news and sports.lnk
  • online movies.lnk
  • aybgwarn.htm
  • aybwarn.htm
  • brsswthg.exe
  • chblgrstd.lib
  • ddinxmdb.exe
  • deskicon.lib
  • dgpxzhtb.exe
  • djgxsbcl.exe
  • drstesprpee.dll
  • efjwxjsl.exe
  • eneqckap.exe
  • flmgvmas.exe
  • fqbhyhjh.exe
  • frlyjeebtrn.dll
  • frlyjeebtru.dll
  • frsezaeaast.dll
  • frsezaeaav.dll
  • gchmfrea.exe
  • glckqksdr.dll
  • gqlfiqii.exe
  • gzxqpghe.exe
  • hlsctpay.exe
  • hlyvjncf.exe
  • idixbdmf.exe
  • ieeblostqly.dll
  • kmigeuhh.exe
  • lckqdcvd.exe
  • lkxelvrg.exe
  • llssalycshh.dll
  • lopsearch.exe
  • mspuztbg.exe
  • muqhatod.exe
  • muxibdom.exe
  • mycvbdqu.exe
  • nimylprv.exe
  • nshelstpgl.dll
  • oostshthptrv.dll
  • ovnolxvi.exe
  • pbgqwhoj.exe
  • plg_ie0.dll
  • prnshgrdssb.dll
  • qhiqikdr.exe
  • qtufbghm.exe
  • qwxgxlrv.exe
  • sefiqovd.exe
  • srytuikb.exe
  • taecoidy.exe
  • trmugnsu.exe
  • trstlskb.exe
  • uljpmexe.exe
  • vlluafrq.exe
  • vygaeifz.exe
  • wa_inst.exe
  • xxdfwvli.exe
  • ysaebwco.exe
  • zaeoxdiu.exe
  • zdmlfhmh.exe
  • zvpkxxtu.exe
  • zvxcypnh.exe
  • zxenmgrbl.dll
  • objnew.exe
  • roam info.exe
  • once each.exe
  • junk pure.exe
  • puretrust.exe
  • loudmove.exe
  • vga admin.exe
  • cam-6415[1].exe
  • ayw17f.exe
  • bae1.exe
  • bvj13.exe
  • den1.exe
  • fbf1.exe
  • hqe1.exe
  • now1.exe
  • pfn1.exe
  • pnt1.exe
  • prab.exe
  • pyo25.exe
  • qhy81.exe
  • rem15.exe
  • rem24.exe
  • rem25.exe
  • rem2ea.exe
  • rny1.exe
  • sml1.exe
  • sta3.exe
  • szwe.exe
  • txo1.exe
  • uqg1.exe
  • vyz1.exe
  • wry1.exe
  • znp1.exe
  • rem18c.exe
  • adult entertainment.url
  • gambling.url
  • games.url
  • mp3 music.url
  • news.url
  • adult chat.url
  • amateur photo.url
  • asian sex.url
  • ebony.url
  • fetish.url
  • gay and lesbian.url
  • hardcore.url
  • live video feeds.url
  • matchmaking.url
  • xxx cartoons.url
  • b to b.url
  • banking.url
  • business.url
  • careers.url
  • credit cards.url
  • finance.url
  • insurance.url
  • office.url
  • printing.url
  • computer games.url
  • computer stores.url
  • dedicated server.url
  • domain names.url
  • hardware.url
  • laptops.url
  • software.url
  • web design.url
  • web hosting.url
  • mobile phones.url
  • telecommunication.url
  • telephone.url
  • text sms messaging.url
  • auction.url
  • classifieds.url
  • free emails.url
  • free homepages.url
  • free services.url
  • school essays and homework.url
  • services.url
  • automotive.url
  • dvd.url
  • entertainment.url
  • hot games and gaming.url
  • mp3.url
  • travel.url
  • black jack.url
  • chips.url
  • craps.url
  • multi player.url
  • online casinos.url
  • poker.url
  • roulette.url
  • slots.url
  • sports books.url
  • art.url
  • astrology.url
  • books.url
  • community.url
  • ebooks.url
  • kids.url
  • magazines.url
  • pets.url
  • self help.url
  • wine.url
  • women.url
  • education.url
  • training.url
  • beauty.url
  • health and fitness.url
  • pharmacy.url
  • construction.url
  • furniture.url
  • home and garden.url
  • real estate.url
  • utilities.url
  • accessories.url
  • apparel.url
  • cards.url
  • electronics.url
  • flowers.url
  • gifts.url
  • jewlery.url
  • retail products.url
  • shoes.url
  • shopping.url
  • toys.url
  • games.url
  • rule keep.dll
  • barbboob.dll
  • chin mfcd.bin
  • 16537.exe
  • store funk.dll
  • 3549.exe
  • antitype.dll
  • hole title.dll
  • longpuresoft.bin
  • bdvcnypx.exe
  • binidledumb.exe
  • jynqzshx.exe
  • oozeboob.exe
  • pazgtrve.exe
  • plus thunk mags.exe
  • settings browse.exe
  • skfvhmqz.exe
  • 64bikeabout.exe
  • bore active info funk.exe
  • bqssapdm.exe
  • ftulpefl.exe
  • funktypebin.exe
  • 16021.exe
  • thatlong.dll
  • bowsbleh.exe
  • fkrbssba.exe
  • ford wma dead.exe
  • gagmqvaf.exe
  • kcwarhnv.exe
  • pure bash.exe
  • qsrdfyqj.exe
  • fastfirst.exe
  • knynnyma.exe
  • mfcdpingwarnfast.exe
  • activebitsflap.exe
  • afniekvu.exe
  • cakerdrplan.exe
  • idle barb ball.exe
  • vzmhfjyb.exe
  • manager free.exe
  • pile inter grim.bin
  • deafdoes.dll
  • 1072.exe
  • acid slow.bin
  • peak that.dll
  • bold grim.exe
  • bzqzgkdq.exe
  • cjcegzut.exe
  • dentcurbfree.exe
  • drv list part corn.exe
  • flaw army name.exe
  • hojxfjdu.exe
  • loyftzhg.exe
  • phone internet.dll
  • curbuser.exe
  • 16logplayprogram.exe
  • bait cake part bash.exe
  • safesoaplicenseplay.exe
  • sizebuildlogo.exe
  • 14599.exe
  • 19205.exe
  • 24758.exe
  • 29923.exe
  • copy data.dll
  • dent team.dll
  • city tons.exe
  • clock mags inter book.exe
  • cmbjcmrq.exe
  • else iso user bows.exe
  • flapholdlogo.exe
  • inter phone pile default.exe
  • one cdrom type more.exe
  • wipekind.exe
  • zwsghqhs.exe
  • boldabout.exe
  • citydog.exe
  • more.exe
  • realaudio.exe
  • roam.exe
  • salrukuu.exe
  • delete play.exe
  • rulefindcamp.exe
  • window skip.exe
  • stop hope.exe
  • skipbase.exe
  • media else rdr.exe
  • ewgcgvzk.exe
  • jxmiyjlq.exe
  • lfgaukbm.exe
  • nnzmpuhm.exe
  • wtmtyuls.exe
  • eksthzea.exe
  • gcvbdwdc.exe
  • intramemocomp.exe
  • jeursyec.exe
  • lsocnmju.exe
  • ocyixkfk.exe
  • uyibygkh.exe
  • zgplkbke.exe
  • etarwlaf.exe
  • glue blue tons.exe
  • mediawebdownload.exe
  • ozrkesxz.exe
  • qmgytdru.exe
  • ruledatawma.exe
  • eygfyuoe.exe
  • rppzstyl.exe
  • 32437.exe
  • aim 1.dll
  • 20044.exe
  • 7310.exe
  • acid team.dll
  • elsemode.dll
  • 1716.exe
  • great ante.dll
  • moreamok.bin
  • acid stop.bin
  • curb bind.dll
  • info wait.dll
  • unbzip2s.dll
  • winactive.exe
  • b_dnserr.gif
  • desktop.htm
  • dnserror.htm
  • i_dnserr.gif
  • jexpoofro.htm
  • r_dnserr.gif
  • s_dnserr.gif
  • ubipwdk.exe
  • asshuktr.exe
  • bilyooas.exe
  • byb_save.exe
  • chksbdriya.dll
  • crgbeaoa.exe
  • dmvcrthl.exe
  • droxtrdchdoo.dll
  • eaeeishllblc.dll
  • ealymfrprwch.dll
  • eaymulyl.exe
  • eelykofrllfrj.dll
  • eelykofrllfrpr.dll
  • eeublidc.exe
  • epllkeeoopr.dll
  • freabrlaouw.dll
  • gldqumssfrie.dll
  • glxshmcr.exe
  • heeachmstll.dll
  • hglllyxrxw.dll
  • icdrhwno.dll
  • ijlysseb.exe
  • jqumysto.exe
  • kfriegbs.exe
  • llfggrdr.exe
  • lltckiey.exe
  • lopsearc.exe
  • meemnckyqbr.exe
  • meepajlr.dll
  • meepajlr.exe
  • mprcouie.exe
  • oofrkxpe.exe
  • ousszidrta.dll
  • peebqusz.exe
  • prnouestssstx.dll
  • prxzoustustgr.dll
  • quglwachfs.dll
  • quveioot.exe
  • shoucrck.exe
  • ssmeeibl.exe
  • sstroallhqch.dll
  • tblchepruprgr.dll
  • tchpeatr.exe
  • tglblrll.exe
  • trdzhtxf.exe
  • trstdris.exe
  • trstshcrscksr.dll
  • ukfroigl.dll
  • ulyuiexeechp.exe
  • upckeetoutw.dll
  • veaeyglckr.dll
  • vestufck.exe
  • vfthrcbr.exe
  • woafrquzn.dll
  • xogyfhp.exe
  • yeecrsoustoull.dll
  • ykphmbre.exe
  • ylynfste.exe
  • ziebaeeoaeepr.dll
  • the_ultimate_browser_enhancer.exe
  • donk_bar.dll
  • npddeapi.dll
  • sxbmat.exe
  • veg32.dll.dll
  • rem9b.exe
  • remd.exe
  • desktop.swf
  • 1 eggs.exe
  • 1 grim.exe
  • 16 mess.exe
  • 64KIND.exe
  • Admindrive.exe
  • audio about boob.exe
  • Barbfirst.exe
  • bin skip.exe
  • Boob army.exe
  • boobdelete.exe
  • Build Load.exe
  • c_12sp10.exe
  • cashmeow.exe
  • chin part.exe
  • chindownload.exe
  • CornCast.exe
  • datefrag.exe
  • Default Bits Blue.exe
  • default frag.exe
  • DeleteSeek.exe
  • drivesign.exe
  • ExtraMpeg.exe
  • find chic trans.exe
  • firstboob.exe
  • five funk camp.exe
  • hold help anti.exe
  • Internet This.exe
  • link cool the.exe
  • Meet Plus.exe
  • Memo Wait.exe
  • mix loud.exe
  • MIX MANAGER BASH.exe
  • MyKey disgo.exe
  • Newabout.exe
  • Ooze About.exe
  • ooze enc.exe
  • PopFileSend.exe
  • pure film.exe
  • Rect Cash.exe
  • Rect load.exe
  • rectsect.exe
  • ref meal.exe
  • SHIM NAME.exe
  • software find.exe
  • SoftwareAmen.exe
  • Support Settings.exe
  • Team idol.exe
  • THIRD CLOSE.exe
  • TickOkay.exe
  • typeplatform.exe
  • Upload Mapi.exe
  • Web jump.exe
  • WmaDrv.exe
  • cmd.exe
  • Kind Idle.exe
  • Axis burn.exe
  • spool32.exe
  • plan memo.exe
  • defyroad.exe
  • flaw upload.exe
  • live copy.exe
  • sfkqtj.exe
  • gcrljntf.exe
  • multi platform.exe
  • adminlove.exe
  • sta1.exe
  • 15ee62.exe
  • mlnznqjv.exe
  • slow move bat hold.exe
  • mntrkqog.exe
  • beep owns.exe
  • 1bb13c.exe
  • wmauoigj.exe
  • qsmswpjl.exe
  • ford cash.exe
  • wait less.exe
  • irjvispr.exe
  • ping once.exe
  • 19f20a.exe
  • curb noun.exe
  • gkrlkmdr.exe
  • joybrowsebytethis.exe
  • that new settings.exe
  • 13bc960
  • fast eggs mail
  • win wave.exe
  • mapijump.exe
  • a5b238b69181b682.job
  • Less4.exe
  • team axis.exe
  • gzkrpkcb.exe
  • setupheck.exe
  • a3919ae1918a1909.job
  • 5b8d7c.exe
  • kvrvbpim.exe
  • mess ace.exe
  • a324ca3f91c34613.job
  • bis1.exe
  • rnrvwnyq.exe
  • dvd fork.exe
  • swamriyb.exe
  • program view.exe
  • xazzynid.exe
  • complist.exe
  • *reack*.html
  • ?????????*ff.gif
  • 2 ace.exe
  • 20023.exe
  • adult.*
  • Aim readme.exe
  • BATGLUE.exe
  • bind fast.exe
  • bingo.*
  • Boob keep.exe
  • bottomleft.gif
  • bottomright.gif
  • card games.*
  • casino online.*
  • Deletegram.exe
  • draw keep.dll
  • explore internet.*
  • Find Exit.exe
  • fiz1
  • fiz2
  • fiz3
  • fiz4
  • fiz5
  • fiz6
  • fiz7
  • fiz8
  • fiz9
  • Fork Coal.dll
  • free_sex_viewer.exe
  • gambling and online casinos.*
  • gltprfrll.lib
  • Idle Bows.exe
  • index_??.gif
  • investing.*
  • MAGSOWNS.exe
  • main_01.gif
  • main_02.gif
  • mp3 music search.*
  • Mp3 wma.exe
  • mp3search_02.gif
  • news and sports.*
  • newsbarend.gif
  • online movies.*
  • onlinecontent.*
  • Part up soap.bin
  • printer cartridges.*
  • ProgramLogo.exe
  • qprflyeg.exe
  • ReadmeSupport.exe
  • searchnow.gif
  • seperateline.gif
  • seperateline1.gif
  • seperateline3.gif
  • SHOWLOAD.exe
  • Soft Live Wave.exe
  • topleft.gif
  • topright.gif
  • travel.*
  • try_b_16.gif
  • vga obj.exe
  • vv.bat
  • website hosting.*
  • euplkc.exe
  • wuauboot.dll
  • qqzzm.exe
  • rgkajbu6.exe
  • hgrgh.exe
  • ydovgz.exe
  • lavktmn.exe
  • PollJoy.exe

Warning: you should delete only those files which checksums are listed as malicious. There may be valid files with the same names in your system. We recommend you to use WiperSoft Antispyware Malware Remediation Tool for safe problem solution.

**Trial version of SpyHunter provides detection of computer viruses for FREE. To remove malware, you have to purchase the full version of Spyhunter.

windows folder logo

2. Delete the following malicious folders:

  • %profile%\local settings\temp\delete.me\
  • %programfiles%\dvdfindload\
  • %programfiles%\elsewa~1\
  • %programfiles%\logobi~1\
  • %programfiles%\proxyn~1\
  • %programfiles%\roamju~1\
  • %programfiles%\showsu~1\
  • %programfiles%\showsupport\
  • %programfiles%\sitein~1\
  • %programfiles%\waveba~1\
  • %programfiles%\wavesu~1\
  • %programfiles%\waymov~1\
  • %programfiles%\wayvga~2\
  • %programfiles%\window active\
  • c:\docume~1\yapü@w~1\applic~1\
  • %profile%\application data\
  • %profile%\application data\list cool loud math\
  • %profile%\application data\memo01idleheart\
  • %profile%\application data\one bolt bleh anti\
  • %profile%\application data\roam surf part tick\
  • %profile%\application data\save third mfcd boob\
  • %profile%\local settings\temporary internet files\content.ie5\s9grsz83\
  • %profile%\owner\local settings\temp\
  • %favorites%\ adult\
  • %favorites%\ business and finance\
  • %favorites%\ computers and tech\
  • %favorites%\ computers and tech\telecommunication\
  • %favorites%\ cool stuff\
  • %favorites%\ entertainment\
  • %favorites%\ gambling\
  • %favorites%\ on lifestyle\
  • %favorites%\ on lifestyle\education\
  • %favorites%\ on lifestyle\health and beauty\
  • %favorites%\ on lifestyle\home and garden\
  • %favorites%\entertainment\
  • %programfiles%\64comp~1\
  • %programfiles%\acidme~1\
  • %programfiles%\active download\
  • %programfiles%\armymo~1\
  • %programfiles%\burn media meta\
  • %programfiles%\cityai~1\
  • %programfiles%\creati~1\
  • %programfiles%\driveh~1\
  • %programfiles%\fourat~1\
  • %programfiles%\freein~1\
  • %programfiles%\global~1\
  • %programfiles%\greato~1\
  • %programfiles%\inside~1\
  • %programfiles%\jugsse~1\
  • %programfiles%\manager ace gram\
  • %programfiles%\mapigr~1\
  • %programfiles%\mathte~1\
  • %programfiles%\memoli~1\
  • %programfiles%\metaac~1\
  • %programfiles%\nounbe~1\
  • %programfiles%\objcdrom\
  • %programfiles%\objels~1\
  • %programfiles%\oozejo~1\
  • %programfiles%\progra~1\
  • %programfiles%\roamse~1\
  • %programfiles%\safeba~1\
  • %programfiles%\sectmp~1\
  • %programfiles%\thirda~1\
  • %programfiles%\trayokay\
  • %programfiles%\wavebo~1\
  • %windows%\application data\
  • %windows%\temp\
  • %windows%\web\wallpaper\
  • %programfiles%\bone balm\
  • %programfiles%\that dale\
  • %programfiles%\windows\currentversion\runactive\
  • %appdata%\HelpLoadUserStupid\
  • %appdata%\helpmp3funkbits\
  • %appdata%\holdcdromthepop\
  • %appdata%\PLAY UPLOAD DASH CORN\
  • %appdata%\PureUpSoapAxis\
  • %appdata%\Stop Joy Info Bib\
  • %appdata%\Surfchiccompshim\
  • %appdata%\tray each cast okay\
  • %appdata%\Warn bin chin jump\
  • %appdata%\MATH MIX LONG JOY\
  • %appdata%\Chin Exit Bin Love\
  • %appdata%\GRIMONETYPEABOUT\
  • %appdata%\ThatTheRdrProc\
  • %appdata%\clockrectmemodelete\
  • %appdata%\axiswarn\
  • %appdata%\FilmIsoPlatformCast\
  • %appdata%\64SHIM\
  • %appdata%\rdrante\
  • %appdata%\send grim bend tons\
  • %appdata%\INFOHOLD\
  • %appdata%\timedashgriminfo\
  • %appdata%\idle clock title mode\
  • %appdata%\More wait active less\
  • %appdata%\Dupe trust vga sect\
  • %appdata%\Pure Once Up Balm\
  • %appdata%\INTERN~1\
  • %appdata%\BLEHWI~1\
  • %profile%\itch gram active great\
  • %appdata%\FOURMA~1\
  • %appdata%\JUMPDA~1\
  • %appdata%\FLAGME~1\
  • %appdata%\stupiddrive2flaw\
  • %appdata%\DARTBU~1\
  • %appdata%\MPEGOK~1\
  • %appdata%\online tick default once\
  • %appdata%\HELPDE~1\
  • %appdata%\Skipprochelpdelete\
  • %appdata%\LISTFA~1\
  • %appdata%\vcbibcampelse\
  • %appdata%\POPDAS~1\
  • %appdata%\My-disgo\
  • %appdata%\FragFlawSeekRef\
  • %appdata%\NEWBON~1\
  • %appdata%\htm heart error byte\
  • %appdata%\SOAPIN~1\
  • %appdata%\HOLE2~1\
  • %appdata%\sendactivesoapthird\
  • %appdata%\Load keep 4 two\
  • %appdata%\SEEKMA~1\
  • %appdata%\CDROMB~1\
  • %appdata%\cdromrefmovebalm\
  • %appdata%\info does heck window\
  • %appdata%\procsoftwarewinlogo\
  • %appdata%\faceflawclockchin\
  • %appdata%\BrowseFileGreatSecond\
  • %appdata%\Four wma that window\
  • %appdata%\Tool Kind Meal Meet\
  • %appdata%\five default mess idle\
  • %appdata%\CREATI~1\
  • %appdata%\supportaimfunktwo\
  • ࡸ\
  • %appdata%\long locks mfcd atom\
  • %appdata%\denteqbikelies\
  • %system%\wnsxs~1\
  • docume~1\karl\applic~1\creati~1\
  • %appdata%\dart regs inter trans\
  • docume~1\jenna\applic~1\trustt~1\
  • %appdata%\chic chin grey tray\
  • %appdata%\army tool\
  • %appdata%\buildsafebike\
  • %appdata%\eggs store aim cake\
  • %appdata%\corn soft sign\
  • %appdata%\CampBendNameBash\
  • %appdata%\sizephone2itch\
  • %appdata%\remotebarbliveref\
  • %appdata%\SIXTHD~1\
  • %programfiles%\manager burn 16\
  • %appdata%\INTRAD~1\
  • %appdata%\FACENE~1\
  • %programfiles%\GLOBAL~1\
  • %appdata%\GREATH~1\
  • %programfiles%\Knob test\
  • %windows%\java\
  • %appdata%\two scr mfcd meal\

windows registry logo

3. Delete the following malicious registry entries and\or values:

  • Key: clsid\{03e3d2bf-051f-5094-5068-c5ee261285bc}
    Value: @
  • Key: CLSID\{07C0D34D-11D7-43F7-832B-C6BB41726F5F}
  • Key: clsid\{0d4312e2-5e4d-4a27-a9d8-043e43904277}
    Value: @
  • Key: clsid\{139e58c9-85b4-45db-9fc9-3919813709f0}
    Value: @
  • Key: clsid\{1502ab76-0376-4b7b-8226-d34c941072f2}
    Value: @
  • Key: clsid\{162ab497-087d-4fb3-83ba-4f5159613796}
    Value: @
  • Key: clsid\{189210a0-36c2-11d7-9928-444553540000}
    Value: @
  • Key: clsid\{18fd2e3d-35df-aa65-0952-7875de70845f}
    Value: @
  • Key: clsid\{1a35419c-7394-4989-b3c5-6189eb06bd66}
    Value: @
  • Key: clsid\{1e62ecd8-ae05-988b-f40a-369b2026409e}
    Value: @
  • Key: clsid\{24f13043-edfc-446c-a07c-8ed6beb9e39e}
    Value: @
  • Key: clsid\{25f1bb0d-2d8c-4dda-ad46-684719d09b7e}
    Value: @
  • Key: clsid\{289848e1-2d29-4d00-9ff1-0c09a1256662}
    Value: @
  • Key: clsid\{2e1162f8-d289-359d-b1e4-0a4d9301a7d1}
    Value: @
  • Key: clsid\{3247f2dc-f2a1-9d95-a072-dbb3e1690643}
    Value: @
  • Key: clsid\{3dcdb313-84a2-6218-64ee-1110caa46fb5}
    Value: @
  • Key: clsid\{4b8edc53-6cfd-4ee4-9504-38ce7a5bc416}
    Value: @
  • Key: clsid\{562a6158-bcae-e53f-d40e-403ef85b70a4}
    Value: @
  • Key: clsid\{56d59f1a-e81a-c85f-d7bb-07a6f380a834}
    Value: @
  • Key: clsid\{7b49a2a5-b45f-46f3-ac60-2578477671ee}
    Value: @
  • Key: clsid\{80fddae7-d472-4e1f-8c3a-36b75a091c44}
    Value: @
  • Key: clsid\{84b55b37-aff7-8942-25ac-f0c5d7a32619}
    Value: @
  • Key: clsid\{8522f9b3-38c5-4aa4-ae40-7401f1bbc851}
    Value: @
  • Key: clsid\{8f1a15a7-92b0-4467-ad12-369f60174008}
    Value: @
  • Key: clsid\{914d0f58-630a-465d-8e28-aea5158e6606}
    Value: @
  • Key: CLSID\{9B35A850-66AB-4c6d-8A66-136ECADCD904}
  • Key: clsid\{a27d4f42-3018-59ed-19ff-4c1b7a2c18fa}
    Value: @
  • Key: clsid\{b0a11536-00dc-268e-042a-6cb617e6965e}
    Value: @
  • Key: clsid\{b9c38317-4e71-4d7b-b072-3aa8dda923b3}
    Value: @
  • Key: clsid\{bcd5534b-2f54-428e-b3f3-e03b6f10a233}
    Value: @
  • Key: clsid\{bd8fd0b2-0e6b-4ffa-916f-db8ff7411d5f}
    Value: @
  • Key: clsid\{c4b41c0c-4e7b-37e0-7b80-ed6437c8eb2c}
    Value: @
  • Key: clsid\{c5d6b9c5-1c08-43f9-bd04-6aefa21dd754}
    Value: @
  • Key: clsid\{c61c874f-60bb-4ee7-8afa-92dc85b180c9}
    Value: @
  • Key: clsid\{c65cad7f-e382-4b90-95c6-89123d0aee61}
    Value: @
  • Key: clsid\{cfadae1d-f67a-c8f7-46a6-eb20e32a92cd}
    Value: @
  • Key: clsid\{d1d9e2f6-c179-4386-b197-c4a85c026f67}
    Value: @
  • Key: clsid\{d3119527-9be0-422c-b9fa-5143d75dfbea}
    Value: @
  • Key: clsid\{d31e488c-9ed3-4fb0-8f82-f1d559553c06}
    Value: @
  • Key: CLSID\{D44B5436-B3E4-4595-B0E9-106690E70A58}
  • Key: clsid\{e58e7c45-c426-993a-2a9f-3640a22bf60e}
    Value: @
  • Key: clsid\{e69e6d3b-861e-4c8b-bdd4-a8b7a61af313}
    Value: @
  • Key: clsid\{eb9bdd24-ccf1-4a87-98c0-579dba9bda83}
    Value: @
  • Key: clsid\{ec28a907-37ac-4d9a-a928-ee2ba555a141}
    Value: @
  • Key: clsid\{f2a5a613-88e0-b267-ce78-aedd8db3ce45}
    Value: @
  • Key: clsid\{fe289ae1-16e9-9235-420a-95ff90a194f4}
    Value: @
  • Key: clsid\{fe54e96b-f246-4ed7-97a2-e27086ce5b21}
    Value: @
  • Key: coal.insidechic
    Value: @
  • Key: dybvi.rngrstrm
    Value: @
  • Key: invisiblepop.invisible
    Value: @
  • Key: pop.phonebird
    Value: @
  • Key: Proto.handler
  • Key: PROTOCOLS\Handler\ayb
  • Key: software\microsoft\windows\currentversion\explorer\browser helper objects
    \{d44b5436-b3e4-4595-b0e9-106690e70a58}

    Value: @
  • Key: Swish.BrowserHelper
  • Key: Swish.ToolBand
  • Key: typelib\{1a35419c-7394-4989-b3c5-6189eb06bd66}
    Value: @
  • Key: typelib\{8f1a15a7-92b0-4467-ad12-369f60174008}
    Value: @
  • Key: TypeLib\{C65CAD7F-E382-4B90-95C6-89123D0AEE61}
  • Key: typelib\{d31e488c-9ed3-4fb0-8f82-f1d559553c06}
    Value: @
  • Key: typelib\{dffe1ccf-e1e8-4470-9962-73277cc2c898}
    Value: @
  • Key: typelib\{fe54e96b-f246-4ed7-97a2-e27086ce5b21}
    Value: @
  • Key: udhiu.rngrstrjyvscd
    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\webbrowser\{18fd2e3d-35df-aa65-0952-7875de70845f}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\webbrowser\{2e1162f8-d289-359d-b1e4-0a4d9301a7d1}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\webbrowser\{38d8beb0-8e9c-48e2-b36e-759615f9930f}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\webbrowser\{562a6158-bcae-e53f-d40e-403ef85b70a4}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\webbrowser\{56d59f1a-e81a-c85f-d7bb-07a6f380a834}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\webbrowser\{84b55b37-aff7-8942-25ac-f0c5d7a32619}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\webbrowser\{a27d4f42-3018-59ed-19ff-4c1b7a2c18fa}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\webbrowser\{b0a11536-00dc-268e-042a-6cb617e6965e}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\webbrowser\{e58e7c45-c426-993a-2a9f-3640a22bf60e}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\webbrowser\{fe289ae1-16e9-9235-420a-95ff90a194f4}

    Value: @
  • Key: Software\Microsoft\Windows\CurrentVersion\Backup
  • Key: Software\TrinityAYB
  • Key: Software\WinActive
  • Key: software\xsswbrwougouecr
    Value: @
  • Key: software\classes\clsid\{092d8662-f5c6-41a3-be1d-14d940f6010d}
    Value: @
  • Key: software\classes\clsid\{139e58c9-85b4-45db-9fc9-3919813709f0}
    Value: @
  • Key: software\classes\clsid\{162ab497-087d-4fb3-83ba-4f5159613796}
    Value: @
  • Key: software\classes\clsid\{289848e1-2d29-4d00-9ff1-0c09a1256662}
    Value: @
  • Key: software\classes\clsid\{33a4af42-fc94-4873-8bc0-1da97d6edd6d}
    Value: @
  • Key: software\classes\clsid\{80fddae7-d472-4e1f-8c3a-36b75a091c44}
    Value: @
  • Key: software\classes\clsid\{914d0f58-630a-465d-8e28-aea5158e6606}
    Value: @
  • Key: software\classes\clsid\{9b35a850-66ab-4c6d-8a66-136ecadcd904}
    Value: @
  • Key: software\classes\clsid\{b0a11536-00dc-268e-042a-6cb617e6965e}
    Value: @
  • Key: software\classes\clsid\{b9c38317-4e71-4d7b-b072-3aa8dda923b3}
    Value: @
  • Key: software\classes\clsid\{bd8fd0b2-0e6b-4ffa-916f-db8ff7411d5f}
    Value: @
  • Key: software\classes\clsid\{c5d6b9c5-1c08-43f9-bd04-6aefa21dd754}
    Value: @
  • Key: software\classes\clsid\{c8a113e0-6da0-4f0e-bb89-9726212aaf32}
    Value: @
  • Key: software\classes\clsid\{d3119527-9be0-422c-b9fa-5143d75dfbea}
    Value: @
  • Key: software\classes\clsid\{d44b5436-b3e4-4595-b0e9-106690e70a58}
    Value: @
  • Key: software\classes\clsid\{e69e6d3b-861e-4c8b-bdd4-a8b7a61af313}
    Value: @
  • Key: software\classes\clsid\{f689307b-c3cd-4d10-aaf2-d1f75358a5c2}
    Value: @
  • Key: software\classes\clsid\{fe289ae1-16e9-9235-420a-95ff90a194f4}
    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\{18fd2e3d-35df-aa65-0952-7875de70845f}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\{1e62ecd8-ae05-988b-f40a-369b2026409e}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\{289848e1-2d29-4d00-9ff1-0c09a1256662}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\{2e1162f8-d289-359d-b1e4-0a4d9301a7d1}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\{562a6158-bcae-e53f-d40e-403ef85b70a4}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\{56d59f1a-e81a-c85f-d7bb-07a6f380a834}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\{7b49a2a5-b45f-46f3-ac60-2578477671ee}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\{80fddae7-d472-4e1f-8c3a-36b75a091c44}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\{84b55b37-aff7-8942-25ac-f0c5d7a32619}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\{914d0f58-630a-465d-8e28-aea5158e6606}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\{a27d4f42-3018-59ed-19ff-4c1b7a2c18fa}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\{b0a11536-00dc-268e-042a-6cb617e6965e}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\{c4b41c0c-4e7b-37e0-7b80-ed6437c8eb2c}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\{c5d6b9c5-1c08-43f9-bd04-6aefa21dd754}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\{d3119527-9be0-422c-b9fa-5143d75dfbea}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\{e58e7c45-c426-993a-2a9f-3640a22bf60e}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\{ec28a907-37ac-4d9a-a928-ee2ba555a141}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\{f689307b-c3cd-4d10-aaf2-d1f75358a5c2}

    Value: @
  • Key:
    software\microsoft\internet explorer\toolbar\{fe289ae1-16e9-9235-420a-95ff90a194f4}

    Value: @
  • Key: software\microsoft\windows\currentversion\explorer\browser helper objects
    \{03e3d2bf-051f-5094-5068-c5ee261285bc}

    Value: @
  • Key: software\microsoft\windows\currentversion\explorer\browser helper objects
    \{092d8662-f5c6-41a3-be1d-14d940f6010d}

    Value: @
  • Key: software\microsoft\windows\currentversion\explorer\browser helper objects
    \{139e58c9-85b4-45db-9fc9-3919813709f0}

    Value: @
  • Key: software\microsoft\windows\currentversion\explorer\browser helper objects
    \{162ab497-087d-4fb3-83ba-4f5159613796}

    Value: @
  • Key: software\microsoft\windows\currentversion\explorer\browser helper objects
    \{24f13043-edfc-446c-a07c-8ed6beb9e39e}

    Value: @
  • Key: software\microsoft\windows\currentversion\explorer\browser helper objects
    \{26dc15e7-ea6e-378b-68aa-cd224b3ad7c3}

    Value: @
  • Key: software\microsoft\windows\currentversion\explorer\browser helper objects
    \{3247f2dc-f2a1-9d95-a072-dbb3e1690643}

    Value: @
  • Key: software\microsoft\windows\currentversion\explorer\browser helper objects
    \{33a4af42-fc94-4873-8bc0-1da97d6edd6d}

    Value: @
  • Key: software\microsoft\windows\currentversion\explorer\browser helper objects
    \{3dcdb313-84a2-6218-64ee-1110caa46fb5}

    Value: @
  • Key: software\microsoft\windows\currentversion\explorer\browser helper objects
    \{4b8edc53-6cfd-4ee4-9504-38ce7a5bc416}

    Value: @
  • Key: software\microsoft\windows\currentversion\explorer\browser helper objects
    \{b9c38317-4e71-4d7b-b072-3aa8dda923b3}

    Value: @
  • Key: software\microsoft\windows\currentversion\explorer\browser helper objects
    \{bd8fd0b2-0e6b-4ffa-916f-db8ff7411d5f}

    Value: @
  • Key: software\microsoft\windows\currentversion\explorer\browser helper objects
    \{c8a113e0-6da0-4f0e-bb89-9726212aaf32}

    Value: @
  • Key: software\microsoft\windows\currentversion\explorer\browser helper objects
    \{cfadae1d-f67a-c8f7-46a6-eb20e32a92cd}

    Value: @
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    \{D44B5436-B3E4-4595-B0E9-106690E70A58}
  • Key: software\microsoft\windows\currentversion\explorer\browser helper objects
    \{e69e6d3b-861e-4c8b-bdd4-a8b7a61af313}

    Value: @
  • Key: software\microsoft\windows\currentversion\explorer\browser helper objects
    \{f2a5a613-88e0-b267-ce78-aedd8db3ce45}

    Value: @
  • Key: software\microsoft\windows\currentversion\installer\products\c8d617f6f8933d11581e000540386890
    \webpublfiles\usage

    Value: @
  • Key: software\microsoft\windows\currentversion\run\blehantimapimeta
    Value: @
  • Key: software\microsoft\windows\currentversion\run\cam-6415[1]
    Value: @
  • Key: software\microsoft\windows\currentversion\run\defyactive
    Value: @
  • Key: software\microsoft\windows\currentversion\run\ford site
    Value: @
  • Key: software\microsoft\windows\currentversion\run\frckshll
    Value: @
  • Key: software\microsoft\windows\currentversion\run\idle heart free wipe
    Value: @
  • Key: software\microsoft\windows\currentversion\run\iso real
    Value: @
  • Key: software\microsoft\windows\currentversion\run\list 4
    Value: @
  • Key: software\microsoft\windows\currentversion\run\loud math help cash
    Value: @
  • Key: software\microsoft\windows\currentversion\run\meta mail
    Value: @
  • Key: software\microsoft\windows\currentversion\run\mfcd boob film frag
    Value: @
  • Key: software\microsoft\windows\currentversion\run\move delete
    Value: @
  • Key: software\microsoft\windows\currentversion\run\parttickwaitjugs
    Value: @
  • Key: software\microsoft\windows\currentversion\run\proxycity
    Value: @
  • Key: software\microsoft\windows\currentversion\run\setup wipe
    Value: @
  • Key: software\microsoft\windows\currentversion\run\start idle
    Value: @
  • Key: software\microsoft\windows\currentversion\run\two bags
    Value: @
  • Key: software\microsoft\windows\currentversion\run\twquh
    Value: @
  • Key: software\microsoft\windows\currentversion\run\ubipwdk
    Value: @
  • Key: software\microsoft\windows\currentversion\run\uqzborauqedw
    Value: @
  • Key: software\microsoft\windows\currentversion\run\winactive
    Value: @
  • Key: software\microsoft\windows\currentversion\run\window balm
    Value: @
  • Key: software\microsoft\windows\currentversion\run\ws2f35t
    Value: @
  • Key: software\microsoft\windows\currentversion\run\wstpsh
    Value: @
  • Key: software\microsoft\windows\currentversion\run\ybmk
    Value: @
  • Key: software\microsoft\windows\currentversion\uninstall\nthlllleth
    Value: @
  • Key: software\microsoft\windows\currentversion\uninstall\pprwazmprss
    Value: @
  • Key: software\microsoft\windows\currentversion\uninstall\shubryochuss
    Value: @
  • Key: bvqye.oustscre
  • Key: bvqye.oustscre.1
  • Key: bvqye.oustscre\CurVer
  • Key: cdbnz.oustscrqzbrpy
  • Key: cdbnz.oustscrqzbrpy.1
  • Key: cdbnz.oustscrqzbrpy\CurVer
  • Key: cetrf.rjshhouz
  • Key: cetrf.rjshhouz.1
  • Key: CLSID\{03e22cd3-ff65-4fd7-98cb-ab6b1d24034d}
  • Key: CLSID\{07304db3-22dd-491a-932b-59cbce84422b}
  • Key: CLSID\{09ad2eb0-9b56-4b08-9fdb-597ca13f084c}
  • Key: CLSID\{113b0dd9-9059-4fff-aca2-e7d12fce5345}
  • Key: CLSID\{15818a0b-3df7-4544-8f79-379c821bb0cc}
  • Key: CLSID\{18922f00-0a29-11d8-910b-00047690cc2a}
  • Key: CLSID\{18922f01-0a29-11d8-910b-00047690cc2a}
  • Key: CLSID\{2a8786d6-6a6b-4176-ae84-73c661a21f88}
  • Key: CLSID\{4acbba89-5b67-4e47-8bd3-0d84a504d9b2}
  • Key: CLSID\{5038e81c-dd9b-462c-8ff4-1d92ab1435e8}
  • Key: CLSID\{5a26980e-f93f-436c-a63b-35e46ee097d0}
  • Key: CLSID\{6883643a-2d81-481a-b094-802697f00f1f}
  • Key: CLSID\{7b718724-b392-4f52-a7a7-c71c2c6112e3}
  • Key: CLSID\{852a9e98-3b8d-43d8-bffe-4e4215521fef}
  • Key: CLSID\{870bb107-485b-4c4f-8271-89574d6081c6}
  • Key: CLSID\{8d9acd24-2cc7-4035-9664-b2e528b3ea57}
  • Key: CLSID\{91dac320-5c93-11d7-b0eb-00805f534689}
  • Key: CLSID\{91dac321-5c93-11d7-b0eb-00805f534689}
  • Key: CLSID\{945f3b06-83e0-4edb-a86f-d4fafd41dba5}
  • Key: CLSID\{94ff852c-21d3-488d-bda0-9ce39b5ad904}
  • Key: CLSID\{a1f7ab69-c1fb-4b73-bf1d-cca87a96b3f3}
  • Key: CLSID\{bad32641-1d32-11d8-9059-444553540000}
  • Key: CLSID\{c08bc100-951a-4515-b759-ffa58cfea004}
  • Key: CLSID\{c12bfa73-4513-4b82-9410-6af4a19659a3}
  • Key: CLSID\{c1ee67a5-f26b-4fc4-8dd4-3e11ae52eec7}
  • Key: CLSID\{c5e15f88-bc0f-49ac-a411-b9f01fd7ec11}
  • Key: CLSID\{ca064947-0f9a-4967-9269-8c370d7f4ce0}
  • Key: CLSID\{cd2696db-0766-44cc-b1b7-e5af9cc24c85}
  • Key: CLSID\{d76ac888-499e-4207-a77c-1c9896c4bad7}
  • Key: CLSID\{e072431c-2044-4e56-84da-ac83baad78c3}
  • Key: CLSID\{eaf81c80-ad77-4936-ac6b-dd1b8b1315d4}
  • Key: CLSID\{ec5da27c-5ae5-4d0f-9e1c-fba1030c8934}
  • Key: CLSID\{f4a058f2-9387-4270-8878-ca49d19f9623}
  • Key: CLSID\{fdca247e-e111-409d-a3ba-259e29d297ee}
  • Key: crjxd.equlootu
  • Key: crjxd.equlootu.1
  • Key: dafgm.equloottzkvyp
  • Key: dafgm.equloottzkvyp.1
  • Key: eghqp.yshfoamreseif
  • Key: eghqp.yshfoamreseif.1
  • Key: gbkcc.brtkthguywyte
  • Key: gbkcc.brtkthguywyte.1
  • Key: hbznu.gobfsqur
  • Key: hbznu.gobfsqur.1
  • Key: hckwo.llsthiqmtvejj
  • Key: hckwo.llsthiqmtvejj.1
  • Key: hwtjq.rjshhoud
  • Key: hwtjq.rjshhoud.1
  • Key: ihliw.yshfoamq
  • Key: ihliw.yshfoamq.1
  • Key: jfvam.zauglqlpnydzy
  • Key: jfvam.zauglqlpnydzy.1
  • Key: ksilm.rjshhouppiibi
  • Key: ksilm.rjshhouppiibi.1
  • Key: mgbwr.uchlquotwatij
  • Key: mgbwr.uchlquotwatij.1
  • Key: mtcrz.uchlquol
  • Key: mtcrz.uchlquol.1
  • Key: pacbo.yshfoamd
  • Key: pacbo.yshfoamd.1
  • Key: pacbo.yshfoamd\CLSID
  • Key: Proto.handler.1
  • Key: pxoir.yshfoamg
  • Key: pxoir.yshfoamg.1
  • Key: qmhrr.brtkthgbqblzz
  • Key: qmhrr.brtkthgbqblzz.1
  • Key: rrzid.achzthbl
  • Key: rrzid.achzthbl.1
  • Key: sljeh.yshfoamw
  • Key: sljeh.yshfoamw.1
  • Key: Software\acrquxqueedreeprly
  • Key: Software\Classes\DRIVE.OwnsDefy
  • Key: Software\Classes\FRAG.elseChin
  • Key: Software\Classes\FRAG.elseChin.1
  • Key:
    SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8522F9B3-38C5-4AA4-AE40-7401F1BBC851}
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    \{03e22cd3-ff65-4fd7-98cb-ab6b1d24034d}
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    \{07304db3-22dd-491a-932b-59cbce84422b}
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    \{15818a0b-3df7-4544-8f79-379c821bb0cc}
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    \{18922f00-0a29-11d8-910b-00047690cc2a}
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    \{2a8786d6-6a6b-4176-ae84-73c661a21f88}
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    \{8108474E-F221-1398-B1F6-5CEFCD581C8D}
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    \{852a9e98-3b8d-43d8-bffe-4e4215521fef}
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    \{8d9acd24-2cc7-4035-9664-b2e528b3ea57}
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    \{91dac320-5c93-11d7-b0eb-00805f534689}
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    \{94ff852c-21d3-488d-bda0-9ce39b5ad904}
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    \{a1f7ab69-c1fb-4b73-bf1d-cca87a96b3f3}
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    \{c5e15f88-bc0f-49ac-a411-b9f01fd7ec11}
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    \{DACBB2E8-6FFF-17C0-E7CF-4709098D8441}
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    \{eaf81c80-ad77-4936-ac6b-dd1b8b1315d4}
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    \{ec5da27c-5ae5-4d0f-9e1c-fba1030c8934}
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    \{f4a058f2-9387-4270-8878-ca49d19f9623}
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\oaeohprxem
  • Key: Software\trmwowdrbldrllst
  • Key: Software\WinActive\Basic
  • Key: Swish.BrowserHelper.1
  • Key: Swish.ToolBand.1
  • Key: tdumx.rjshhouaovfrk
  • Key: tdumx.rjshhouaovfrk.1
  • Key: uyjhk.achzthbfqvyxo
  • Key: uyjhk.achzthbfqvyxo.1
  • Key: vshls.brtkthgg
  • Key: vshls.brtkthgg.1
  • Key: vvxlj.rdllbllrrynui
  • Key: vvxlj.rdllbllrrynui.1
  • Key: vwzjt.yshfoamzymdle
  • Key: vwzjt.yshfoamzymdle.1
  • Key: wkjrd.yshfoame
  • Key: wkjrd.yshfoame.1
  • Key: wokhf.zauglqlm
  • Key: wokhf.zauglqlm.1
  • Key: xnihy.tueatrtg
  • Key: xnihy.tueatrtg.1
  • Key: xsrqy.rdllbllp
  • Key: xsrqy.rdllbllp.1
  • Key: xzouz.llsthiqi
  • Key: xzouz.llsthiqi.1
  • Key: yhypv.tueatrtmdahez
  • Key: yhypv.tueatrtmdahez.1
  • Key: zhnhs.brtkthge
  • Key: zhnhs.brtkthge.1
  • Key: CLSID\{74734139-76EA-E51A-D38C-1E5BD64F983C}\InprocServer32
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Bait Global
  • Key: CLSID\{55C23FF8-82D9-3B7C-EDDC-1CB688B2A864}\InprocServer32
    Value: ThreadingModel
  • Key: Software\Classes\CLSID\{4F348742-4286-F2ED-6FB3-371AE0D97F04}
    Value: 43FA8F84
  • Key:
    Software\Classes\CLSID\{4F348742-4286-F2ED-6FB3-371AE0D97F04}\InprocServer32

    Value: ThreadingModel
  • Key: Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    \{4F348742-4286-F2ED-6FB3-371AE0D97F04}
  • Key: CLSID\{8CD59458-ECF2-EA07-E89C-02102AF66A5F}\InprocServer32
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
    \{55C23FF8-82D9-3B7C-EDDC-1CB688B2A864}
  • Key:
    SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{55C23FF8-82D9-3B7C-EDDC-1CB688B2A864}
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{55C23FF8-82D9-3B7C-EDDC-1CB688B2A864}
    \iexplore

    Value: Time
  • Key: SOFTWARE\Classes\CLSID\{55C23FF8-82D9-3B7C-EDDC-1CB688B2A864}
    Value: 05B08A79
  • Key:
    SOFTWARE\Classes\CLSID\{55C23FF8-82D9-3B7C-EDDC-1CB688B2A864}\InprocServer32

    Value: ThreadingModel
  • Key: software\microsoft\internet explorerinternet0%\Toolbar
    Value: {0185db52-4c39-44f4-b4c9-f8a3ef1162bb}
  • Key: software\microsoft\internet explorerinternet0%\Toolbar
    Value: {4acbba89-5b67-4e47-8bd3-0d84a504d9b2}
  • Key: software\microsoft\internet explorerinternet0%\Toolbar
    Value: {5038e81c-dd9b-462c-8ff4-1d92ab1435e8}
  • Key: software\microsoft\internet explorerinternet0%\Toolbar
    Value: {7b718724-b392-4f52-a7a7-c71c2c6112e3}
  • Key: software\microsoft\internet explorerinternet0%\Toolbar
    Value: {870bb107-485b-4c4f-8271-89574d6081c6}
  • Key: software\microsoft\internet explorerinternet0%\Toolbar
    Value: {91dac321-5c93-11d7-b0eb-00805f534689}
  • Key: software\microsoft\internet explorerinternet0%\Toolbar
    Value: {945f3b06-83e0-4edb-a86f-d4fafd41dba5}
  • Key: software\microsoft\internet explorerinternet0%\Toolbar
    Value: {9B35A850-66AB-4c6d-8A66-136ECADCD904}
  • Key: software\microsoft\internet explorerinternet0%\Toolbar
    Value: {c08bc100-951a-4515-b759-ffa58cfea004}
  • Key: software\microsoft\internet explorerinternet0%\Toolbar
    Value: {c12bfa73-4513-4b82-9410-6af4a19659a3}
  • Key: software\microsoft\internet explorerinternet0%\Toolbar
    Value: {c1ee67a5-f26b-4fc4-8dd4-3e11ae52eec7}
  • Key: software\microsoft\internet explorerinternet0%\Toolbar
    Value: {ca064947-0f9a-4967-9269-8c370d7f4ce0}
  • Key: software\microsoft\internet explorerinternet0%\Toolbar
    Value: {cd2696db-0766-44cc-b1b7-e5af9cc24c85}
  • Key: software\microsoft\internet explorerinternet0%\Toolbar
    Value: {d76ac888-499e-4207-a77c-1c9896c4bad7}
  • Key: software\microsoft\internet explorerinternet0%\Toolbar
    Value: {e072431c-2044-4e56-84da-ac83baad78c3}
  • Key: software\microsoft\internet explorerinternet0%\Toolbar\WebBrowser
    Value: {18922F01-0A29-11D8-910B-00047690CC2A}
  • Key: software\microsoft\internet explorerinternet0%\Toolbar\WebBrowser
    Value: {38D8BEB0-8E9C-48E2-B36E-759615F9930F}
  • Key: software\microsoft\internet explorerinternet0%\Toolbar\WebBrowser
    Value: {FDCA247E-E111-409D-A3BA-259E29D297EE}
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Windows
    Value: AppInit_DLLs
    Data: %system%\wuauboot.dll %system%\wucrtupd.dll
  • Key: Software\Microsoft\Internet Explorer\New Windows\Allow
    Value: searchweb2.com
  • Key: Software\Microsoft\Internet Explorer\New Windows\Allow
    Value: www.searchweb2.com
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\View32Joy
    Value: UninstallString
  • Key: Software\Microsoft\Internet Explorer\New Windows\Allow
    Value: search200.com
  • Key: Software\Microsoft\Internet Explorer\New Windows\Allow
    Value: www.search200.com
  • Key: Software\Microsoft\Internet Explorer\New Windows\Allow
    Value: dns-look-up.com
  • Key: Software\Microsoft\Internet Explorer\New Windows\Allow
    Value: www.dns-look-up.com
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\surf ace about
    Value: DisplayName
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\surf ace about
    Value: UninstallString
  • Key: Software\Microsoft\Windows\CurrentVersion\The Meal Ace
    Value: LogoEggs
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{55C23FF8-82D9-3B7C-EDDC-1CB688B2A864}
    \iexplore

    Value: Type
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{55C23FF8-82D9-3B7C-EDDC-1CB688B2A864}
    \iexplore

    Value: Count
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\surf ace about
    Value: DisplayName
  • Key: software\microsoft\internet explorerinternet0%\Main
    Value: Search Bar
    Data: ~~~ecmh.com
  • Key: software\microsoft\internet explorerinternet0%\Main
    Value: Search Bar
    Data: ~~~search200.com
  • Key: software\microsoft\internet explorerinternet0%\Main
    Value: Search Page
    Data: ~~~ecmh.com
  • Key: software\microsoft\internet explorerinternet0%\Main
    Value: Search Page
    Data: ~~~search200.com
  • Key: software\microsoft\internet explorerinternet0%\Main
    Value: Start Page
    Data: ~~~ecmh.com
  • Key: software\microsoft\internet explorerinternet0%\Main
    Value: Start Page
    Data: ~~~search200.com
  • Key: software\microsoft\internet explorerinternet0%\Search
    Value: SearchAssistant
    Data: ~~~ecmh.com
  • Key: software\microsoft\internet explorerinternet0%\Search
    Value: SearchAssistant
    Data: ~~~search200.com
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon
    Value: Userinit
    Data: %system%\userinit.exe,icrbwhr.exe
  • Key: Software\Microsoft\Internet Explorer\Main
    Value: Start Page
    Data: http://www.abitlbmljjfqurj.uk/bVWgzPUDnvq1xYne5YIqukhDs2S3VGccwQtatZ/j_U8.html
  • Key: Software\Microsoft\Internet Explorer\Main
    Value: Search Bar
    Data: http://www.jbzzstnqwfbrunfbvhxonebfm.com/pKZqz6XuiJ3qy_rrm_IeDrr3ZUoBW/Xd2aUqN4/hflCRCJwuEEVbCj0kQ5sjMXgi.php
  • Key: Software\Microsoft\Internet Explorer\Main
    Value: Start Page
    Data: http://hslvvmhmqhuellmxgk.net/pKZqz6XuiJ3eOfKNlA/pqWFFuEVL8rg5e33edw5O3zY.php
  • Key: Software\Microsoft\Internet Explorer\Main
    Value: Search Bar
    Data: http://mnswkmpnjevlsn.net/Jgx0AHO8Z7CHu0H1E9CCa6aogPTKDbuMiVRGxJgB1FI2N58_v_fSUyd84mEKeM9n.html
  • Key: Software\Microsoft\Internet Explorer\Main
    Value: Start Page
    Data: http://www.jgowblsytazinjdzckrulmvlf.com/Jgx0AHO8Z7COWDflaF/bb/eCtBB9RQeeCsM4XAVFVG8.html
  • Key: Software\Microsoft\Internet Explorer\Main
    Value: Search Bar
    Data: http://www.edhgdwfijcfsoyej.com/pKZqz6XuiJ3qy_rrm_IeDrr3ZUoBW/Xd2aUqN4/hflD0u/JN_HjaJz0kQ5sjMXgi.jsp
  • Key: Software\Microsoft\Internet Explorer\Main
    Value: Start Page
    Data: http://www.ztdpesmoudfk.com/pKZqz6XuiJ3eOfKNlA/pqTuD_jr4IZ_He33edw5O3zY.jsp
  • Key: Software\Microsoft\Internet Explorer\Main
    Value: Search Bar
    Data: http://www.vadskjrimo.com/pKZqz6XuiJ3qy_rrm_IeDrr3ZUoBW/Xd2aUqN4/hflCskkrf7rK4Bj0kQ5sjMXgi.asp
  • Key: Software\Microsoft\Internet Explorer\Main
    Value: Start Page
    Data: http://www.exrricenwvajeqvqkaiunrogy.info/pKZqz6XuiJ3eOfKNlA/pqTk6AlawZRtGe33edw5O3zY.cgi

Warning: if value is listed for some registry entries, you should only clear these values and leave keys with such values untouched. We recommend you to use WiperSoft Antispyware Malware Remediation Tool for safe problem solution.


4. Manually fix browser problems

Lop.com can affect your browsers which results in browser redirection or search hijack. We recommend you to use free option "Reset Browsers" under "Tools" in Spyhunter Remediation Tool to reset all the browsers at once. Mention that you need to remove all files and kill all processes belonging to Lop.com before doing this. To reset your browsers manually and restore your homepage perform the following steps:

internet explorer logo

Internet Explorer

  • If you use Windows XP, click Start, and then click Run. Type the following in the Open box without quotes, and press Enter: "inetcpl.cpl"

  • If you use Windows 7 or Windows Vista, click Start. Type the following in the Search box without quotes, and press Enter: "inetcpl.cpl"

  • Click the Advanced tab

  • In Reset Internet Explorer settings, click Reset. Click Reset in opened window again.

  • Select Delete personal settings checkbox to remove browsing history, search providers, homepage

  • After Internet Explorer finishes resetting, click Close in the Reset Internet Explorer Settings dialog box

Warning: In case this option will not work use free option Reset Browsers under Tools in Spyhunter Remediation Tool.

google chrome logo

Google Chrome

  • Go to the installation folder of Google Chrome: C:\Users\"your username"\AppData\Local\Google\Chrome\Application\User Data.

  • In the User Data folder, look for a file named as Default and rename it to DefaultBackup.

  • Launch Google Chrome and a new clean Default file will be created.

Warning: This option might not work if in Google Chrome you use online synchronization between PCs. In this case use free option Reset Browsers under Tools in Spyhunter Remediation Tool.

mozilla firefox logo

Mozilla Firefox

  • Open Firefox

  • Go to Help > Troubleshooting Information in menu.

  • Click the Reset Firefox button.

  • After Firefox is done, it will show a window and create folder on the desktop. Click Finish.

Warning: This option will also clean all your account passwords for all websites. If you don't want it use free option Reset Browsers under Tools in Spyhunter Remediation Tool.

Information provided by: Aleksei Abalmasov

DMCA.com Protection Status

Here are the descriptions of problems connected with Lop.com and sed.exe we received earlier:

Problem Summary: I think this is spyware

roamse~1.exe window keeps popping up every 30 minutes - how do I get rid of this?

thank you

Problem was successfully solved. Ticket was closed.

Problem Summary: bend upload.exe

Starting up PC this comes up as error. Cannot load bend upload.exe How do I fix this as I do not know what this program is.

Problem was successfully solved. Ticket was closed.

Most wanted threat: gator

« Back to catalog

Home | Partners | Shop | Support | Terms of use | Contact Us | Privacy Policy | Sitemap

Copyright © 2022 Security Stronghold. All Rights Reserved. All content on this website is protected and belongs to Security Stronghold LLC.