Smitfraud Processes:
intmon.exe
popuper.exe
bsw.exe
helper.exe
hookdump.exeintmonp.exe
msmsgs.exe
msole32.exe
ole32vbs.exe
Smitfraud Registry Entries
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionRunWindowsFY
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionRunWindowsFZ
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionRunmsn messenger
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionExplorerBrowser Helper Objects{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}
HKEY_CURRENT_USER SoftwareMicrosoftInternet ExplorerMainDefault_Page_URL=[site address]
HKEY_CURRENT_USER SoftwareMicrosoftInternet ExplorerMainDefault_Search_URL=[site address]
HKEY_CURRENT_USER SoftwareMicrosoftInternet ExplorerMainSearch Bar=[site address]
HKEY_CURRENT_USER SoftwareMicrosoftInternet ExplorerMainSearch Page=[site address]
HKEY_CURRENT_USER SoftwareMicrosoftInternet ExplorerMainLocal Page=[site address]
Other Smitfraud Files
hhk.dll
oleadm.dll
oleadm32.dll
wldr.dll
param32.dll
Warning
Removing
registry entries can be very dangerous when done manually.
You
can accidentally cause
windows errors, blue screens, even the collapse
of your hard drive. Procede with caution!
.