Friday
2016-04-07, 13:26
The following instructions have been created to help you to get rid of "Ad.QvodPlayer" manually.
Use this guide at your own risk; software should usually be better suited to remove malware, since it is able to look deeper.
If this guide was helpful to you, please consider donating towards this site (http://www.safer-networking.org/index.php?page=donate).
Threat Details:
Categories:
adware
Description:
Ad.QvodPlayer installs a chinese video player and adware applications, e.g. BaiduBar.
Removal Instructions:
Desktop:
Please remove the following files from your desktop.
To check where they are pointing to, right-click them and choose "Properties" from the context menu appearing.
Shortcuts named "QvodPlayer" and pointing to "E:\Program Files\QvodPlayer\QvodPlayer.exe".
Important: There are more desktop links that cannot be safely described in simple words. Please use Spybot-S&D (http://www.safer-networking.org/index.php?page=spybotsd) to remove them.
Quicklaunch area:
Important: There are more quicklaunch items that cannot be safely described in simple words. Please use Spybot-S&D (http://www.safer-networking.org/index.php?page=spybotsd) to remove them.
Autorun:
Please use Spybot-S&D (http://www.safer-networking.org/index.php?page=spybotsd), RunAlyzer (http://www.safer-networking.org/index.php?page=runalyzer) or msconfig.exe to remove the following autorun entries.
Entries named "Kuaiwan" and pointing to "?<$PROGRAMFILES>\Kuaiwan\Kuaiwan.exe*".
Entries named "QvodPlayer" and pointing to "<$SYSDRIVE>\Program Files\QvodPlayer\QvodTerminal.exe".
Installed Software List:
You can try to uninstall products with the names listed below; for items identified by other properties or to avoid malware getting active again on uninstallation, use Spybot-S&D (http://www.safer-networking.org/index.php?page=spybotsd) or RunAlyzer (http://www.safer-networking.org/index.php?page=runalyzer) to locate and get rid of these entries.
Products that have a key or property named "Kuaiwan".
Products that have a key or property named "QvodPlayer".
Files:
Please use Windows Explorer or another file manager of your choice to locate and delete these files.
The file at "<$COMMONAPPDATA>\KuaiWan\AppInfo.xml".
The file at "<$COMMONAPPDATA>\KuaiWan\User.ini".
The file at "<$PROGRAMFILES>\Kuaiwan\skin\DefaultSkin.xml".
The file at "<$PROGRAMFILES>\Kuaiwan\skin\DefaultSkin\MainTab\Thumbs.db".
The file at "<$PROGRAMFILES>\Kuaiwan\skin\DefaultSkin\WebGameTab\Thumbs.db".
The file at "<$SYSDRIVE>\desktop.ini".
The file at "<$SYSDRIVE>\Program Files\QvodPlayer\AddIn\ASBarBroker.exe".
The file at "<$SYSDRIVE>\Program Files\QvodPlayer\QvodCfg.ini".
The file at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\Default\volumep.bmp".
The file at "<$SYSDRIVE>\Program Files\QvodPlayer\Tip\PopMessage.xml".
The file at "<$SYSDRIVE>\Program Files\QvodPlayer\Tip\QvodTip.exe".
The file at "<$SYSDRIVE>\Program Files\QvodPlayer\Tip\QvodTips.dll".
Make sure you set your file manager to display hidden and system files. If Ad.QvodPlayer uses rootkit technologies, use the rootkit scanner integrated into Spybot-S&D (http://www.safer-networking.org/index.php?page=spybotsd) 2.x or our Total Commander anti-rootkit plugins (http://forums.spybot.info/downloads.php?id=3).
You will have to use a global search for files without a name specified. Be extra careful, because just the name might not be enough to identify files!
Important: There are more files that cannot be safely described in simple words. Please use Spybot-S&D (http://www.safer-networking.org/index.php?page=spybotsd) to remove them.
Folders:
Please use Windows Explorer or another file manager of your choice to locate and delete these folders.
The directory at "<$APPDATA>\qvodaddr".
The directory at "<$COMMONAPPDATA>\KuaiWan".
The directory at "<$COMMONPROGRAMFILES>\QvodPlayer\Codecs".
The directory at "<$COMMONPROGRAMFILES>\QvodPlayer".
The directory at "<$PROGRAMFILES>\Kuaiwan\skin\DefaultSkin\insert".
The directory at "<$PROGRAMFILES>\Kuaiwan\skin\DefaultSkin\key".
The directory at "<$PROGRAMFILES>\Kuaiwan\skin\DefaultSkin\MainTab".
The directory at "<$PROGRAMFILES>\Kuaiwan\skin\DefaultSkin\webgame".
The directory at "<$PROGRAMFILES>\Kuaiwan\skin\DefaultSkin\WebGameTab".
The directory at "<$PROGRAMFILES>\Kuaiwan\skin\DefaultSkin".
The directory at "<$PROGRAMFILES>\Kuaiwan\skin".
The directory at "<$PROGRAMFILES>\Kuaiwan".
The directory at "<$PROGRAMS>\QVOD".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\AddIn".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Codecs".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Lang".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Lyrics".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\Aluminum".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\Blue".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\Dark".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\Default".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\Exalted".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\Gray".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\MediaPlayer".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\MiNi".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\Navy".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\new_ccch".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\new_gysd".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\new_lskj".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\new_ly".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\new_QuickTimer".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\new_sl".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\new_xlxl".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\new_yh".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\new_yryh".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\new_zcl".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\Simple".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\Simple2".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Tip".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Viewdata".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer".
Make sure you set your file manager to display hidden and system files. If Ad.QvodPlayer uses rootkit technologies, use our RootAlyzer (http://forums.spybot.info/downloads.php?id=8) or our Total Commander anti-rootkit plugins (http://forums.spybot.info/downloads.php?id=3).
You will have to use a global search for files without a name specified. Be extra careful, because just the name might not be enough to identify folders!
Registry:
You can use regedit.exe (included in Windows) to locate and delete these registry entries.
A key in HKEY_CLASSES_ROOT\ named "KWCheck.KuaiWan.1", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "KWCheck.KuaiWan", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "QVOD", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "QVODADD", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "Qvodbt", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "QVODCHA", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "QvodInsert.QvodCtrl.1", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "QvodInsert.QvodCtrl", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.3g2", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.3gp", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.3gp2", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.3gpp", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.aac", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.ac3", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.aif", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.aifc", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.aiff", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.amr", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.amv", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.ape", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.asf", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.asx", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.au", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.avi", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.bik", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.cda", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.csf", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.cue", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.d2v", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.dsa", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.dsm", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.dss", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.dsv", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.dts", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.dvd", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.evo", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.f4v", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.flac", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.flc", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.fli", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.flv", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.ivf", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.m1v", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.m2p", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.m2ts", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.m2v", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.m3u", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.m4a", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.m4b", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.m4p", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.m4v", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mac", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mid", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.midi", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mkv", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mod", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mov", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mp2", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mp3", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mp4", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mp5", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mpa", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mpe", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mpeg", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mpg", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mpga", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mts", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mvx", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.ogg", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.ogm", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.pm2", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.pmp", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.pmp2", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.pss", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.pva", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.qmv", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.qpl", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.qsed", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.qt", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.ra", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.ram", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.rat", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.rm", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.rmi", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.rmvb", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.roq", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.rp", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.rpm", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.rsc", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.rt", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.smil", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.smk", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.smv", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.swf", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.tim", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.tp", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.tpr", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.ts", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.tta", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.ttpl", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.vg2", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.vid", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.vob", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.vp6", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.vp7", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.wav", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.wm", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.wma", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.wmp", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.wmv", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.wmx", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.wpl", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.wv", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "QVODSEA", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "ShareModule.QvodShare.1", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "ShareModule.QvodShare", plus associated values.
Delete the registry key "{00000001-4FEF-40D3-B3FA-E0531B897F98}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{007FC171-01AA-4B3A-B2DB-062DEE815A1E}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{0180E49C-13BF-46DB-9AFD-9F52292E1C22}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{02AFA80F-4BEE-41FD-8572-214B58A9EF90}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{03D82D06-49E2-4E37-9670-BCAB4DBC642D}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{04FE9017-F873-410E-871E-AB91661A4EF7}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{0512B874-44F6-48F1-AFB5-6DE808DDE230}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{05F983EC-637F-4133-B489-5E03914929D7}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{0912B4DD-A30A-4568-B590-7179EBB420EC}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{09571A4B-F1FE-4C60-9760-DE6D310C7C31}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{0B390488-D80F-4A68-8408-48DC199F0E97}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{0C56B154-43F7-48A0-87B2-E9ACC8E1E471}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{0E9D4BF7-CBCB-46C7-BD80-4EF223A3DC2B}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{0F40E1E5-4F79-4988-B1A9-CC98794E6B55}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{11CC93E4-0BE6-4f8f-82AA-D577FB955B05}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{1365BE7A-C86A-473C-9A41-C0A6E82C9FA3}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{164A68B6-3F90-47C2-85A7-1E4D8952EF0A}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{1932C124-77DA-4151-99AA-234FEA09F463}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{1ADD57B8-A7A9-4518-B9B5-862590FF9EB4}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4}" at "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\".
Delete the registry key "{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4}" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\".
Delete the registry key "{1F71651E-65D2-40BF-AC44-275D11927D99}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{20E9DE6B-87D5-4E85-8BB0-038284A6C44D}" at "HKEY_CLASSES_ROOT\TypeLib\".
Delete the registry key "{212CA6D1-E9BB-41cf-BF77-06E000F403A8}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{238D0F23-5DC9-45A6-9BE2-666160C324DD}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{24FA7933-FE18-46A9-914A-C2AA0DBACE93}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{2566F758-FE4A-4691-9F93-30AF685BB403}" at "HKEY_CLASSES_ROOT\TypeLib\".
Delete the registry key "{2627A1B6-F8FF-4E9C-9422-4908E8D1DFE9}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{2F09858D-D67F-4F8B-8DE8-666666CB9FAD}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{32E2BDD6-8812-42c3-A907-B9587C148EE3}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{363F46BE-27B4-4C8D-99E7-B1E049B84376}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{37991D68-42A3-40E3-8C05-037170E1A42A}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{3BB3828F-9787-48A7-A894-6ADE46C64737}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{3CCC052E-BDEE-408A-BEA7-90914EF2964B}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{3E3ECA90-4D6A-4344-98C3-1BB95BF24038}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{3FD0479E-D6B9-4629-9496-509D3D070918}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{412C98D0-B46E-4FFA-92E1-4016782EE0AB}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{432F118C-DB79-4561-9799-CC95EA78208B}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{46E00789-37CA-4278-8907-02088898B6B0}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{47E792CF-0BBE-4F7A-859C-194B0768650A}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{48B51CD7-D8FA-4452-B00C-5BBFDE92B9AB}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{49590BC9-6DD5-4E44-AD4C-E8FCB7131EC4}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{4DB2B5D9-4556-4340-B189-AD20110D953F}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{50DDA33E-C529-4343-9689-338ADC793BB5}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{525F116F-04AD-40A2-AE2F-A0C4E1AFEF98}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{533B0507-1869-4503-B61C-DA4842EEB800}" at "HKEY_CLASSES_ROOT\TypeLib\".
Delete the registry key "{53D9DE0B-FC61-4650-9773-74D13CC7E582}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{545A00C2-FCCC-40B3-9310-2C36AE64B0DD}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{54A35221-2C8D-4A31-A5DF-6D809847E393}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{5593CF36-190B-4A47-A4DD-9680093DBA1D}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{55DA30FC-F16B-49FC-BAA5-AE59FC65A150}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{5711D95F-0984-4A22-8FF8-90A954958D0C}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{57A5353F-2725-440c-BBBC-DB20A1C8A57D}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{5905A0A9-A82C-4A7B-8418-FC1F6D1AD5DB}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{59A0DB73-0287-4C9A-9D3C-8CFF39F8E5DB}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{5BC26A00-5101-47d7-A5DB-AB6AAC44F51B}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{60765CF5-01C2-4EE7-A44B-C791CF25FEA0}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{61F47056-E400-43D3-AF1E-AB7DFFD4C4AD}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{64697678-0000-0010-8000-00AA00389B71}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{64F2005C-6CF5-4652-B94F-600360B15B27}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{650DE05E-5CD3-44F8-BA20-A5BB91FC61E6}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{66EA14E6-E2B3-433D-923E-EE401CADBBD9}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{6B97CB13-A992-4970-8864-4F32E845B7B4}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{6D3688CE-3E9D-42F4-92CA-8A11119D25CD}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{6E756F73-15A3-4ECE-98C0-D9CD2744F5A8}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{6F6C6F63-0000-0010-8000-00AA00389B71}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{7139E26A-49CA-4344-B063-C702858627D9}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{75878923-D1ED-49AF-B550-BC993578292E}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{760A8F35-97E7-479D-AAF5-DA9EFF95D751}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{765035B3-5944-4A94-806B-20EE3415F26F}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{78302E8C-3C6F-267C-2E0D-1D37BF7E3D64}" at "HKEY_LOCAL_MACHINE\SOFTWARE\".
Delete the registry key "{78766964-0000-0010-8000-00AA00389B71}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{7A33CE9E-4F33-4B4E-B263-6AEEAB6C3DC2}" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\".
Delete the registry key "{7B63A013-DC2C-462E-9292-CAF8C867100F}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{7B6F8B69-0925-48F1-AE78-7506D6C3972C}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{7CA71B1E-A67D-4D54-A200-FA47605483A7}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{7E493C9A-2E54-4F25-9B9A-D3C4DEBFCB62}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{803E8280-F3CE-4201-982C-8CD8FB512004}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{86708513-5A2E-424f-AB46-F4BE3F82954F}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{87271B4E-1726-4CED-AF0D-BE675621FD29}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{87BBB4ED-1767-4b7e-821C-7C4657E439D4}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{895322C5-84A1-450C-8478-C57793CAE86F}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{89B2C28D-779F-4704-AD29-113B0977E8A5}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{8E8B4A31-408B-4929-86A4-A9FA9F01BA43}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{8E9922F0-B775-45B8-B650-941BEA790EEB}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{8F43B7D9-9D6B-4F48-BE18-4D787C795EEA}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{90A9B7D2-3794-45EA-9E23-140E3938D2D9}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{90C7D10E-CE9A-479B-A238-1A0F2396DE43}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{91878E42-FC03-4785-B513-1F9E613D1027}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{93A22E7A-5091-45EF-BA61-6DA26156A5D0}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{941A4793-A705-4312-8DFC-C11CA05F397E}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{94C3E4BB-A261-4A83-B437-EA6F7A28CA68}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{94C3E4BB-A261-4A83-B437-EA6F7A28CA68}" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\".
Delete the registry key "{96CE7B0D-06B3-42E2-8DB7-CFC6CF0121F6}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{9736D831-9D6C-4E72-B6E7-560EF9181001}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{9852A670-F845-491B-9BE6-EBD841B8A613}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{99735894-CAF4-488B-8275-B8CB1998216E}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{99AA8908-FC7F-4815-B023-3BC2F5F8D372}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{99D9DC39-90DE-41D3-AECA-345D7F1B9540}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{9A6E096E-4588-3E32-F06C-69F6B8784825}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{9A6E096E-4588-3E32-F06C-69F6B8784825}" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\".
Delete the registry key "{9A98ADCC-C6A4-449E-A8B1-0363673D9F8A}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{9B2DBA95-39D2-4537-8BBF-CED535E8DE56}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{9F44453E-1E46-4D5C-B57C-112FF2EDAE82}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{9FF48807-E133-40AA-826F-9B2959E5232D}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{A0606860-51BE-4CF6-99C0-7CE5F78AC2D8}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{A28F324B-DDC5-4999-AA25-D3A7E25EF7A8}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{A36C253D-CEE4-4BCA-9CC2-E03CF6BBB054}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{A753A1EC-973E-4718-AF8E-A3F554D45C44}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{A8B25C0E-0894-4531-B668-AB1599FAF7F6}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{A94662D1-35FD-43d1-BDA3-172CE4D5C236}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{A975010E-D292-4A74-A9FF-E536C94C0647}" at "HKEY_CLASSES_ROOT\TypeLib\".
Delete the registry key "{AAA4AACD-FD95-4240-9C45-9EB98E5DAC52}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{ACD23F8C-B37E-4B2D-BA08-86CB6E621D6A}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{ACE4747B-35BD-4E97-9DD7-1D4245B0695C}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{AD461A96-4DB8-4C6E-BF23-84D682ADC382}" at "HKEY_CLASSES_ROOT\TypeLib\".
Delete the registry key "{AD92C6E6-997A-4E9E-9D7D-EDED6DE933FB}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{AF54DF04-9597-4B3D-947A-3A7A7F29C0E9}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{B3DE7EDC-0CD4-4d07-B1C5-92219CD475CC}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{B4DAEDB7-7F0E-434F-9AA3-B82B549A3680}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{B5A7D70F-AE96-4F83-B811-572CA3529323}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{B6EAE677-074B-43EA-9239-5E509F87C652}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{B7BCE5B0-2112-420A-BDFF-178995FBFCA2}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{B841F346-4835-4de8-AA5E-2E7CD2D4C435}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{B86F6BEE-E7C0-4D03-8D52-5B4430CF6C88}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{B8E20CD7-BAC2-4820-9AA6-1060B3AF25E2}" at "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\".
Delete the registry key "{BA327E17-6AE9-430B-8246-1A90208AD1D7}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{BAC04407-3588-42AA-93BE-6D3720E9FB28}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{BB9CDE7F-AF28-4205-9B3C-789FA7D0F29F}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{BD4FB4BE-809D-487b-ADD6-F7D164247E52}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{BDE0D9DF-288F-4286-906F-93197673B3A7}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{C1630673-8C58-481C-9F15-83F11D8B89F0}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{C204438D-6E1A-4309-B09C-0C0F749863AF}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{C29CE93C-3908-4DA7-A7DA-4968C3AF2AE8}" at "HKEY_CLASSES_ROOT\TypeLib\".
Delete the registry key "{C2D6D98F-09CA-4524-AF64-1049B5665C9C}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{C7E094E1-A326-4E33-824D-6598D399DA13}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{C8B9C208-9E5C-4F09-AED5-B21A273C4CCA}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{C9ECE7B3-1D8E-41F5-9F24-B255DF16C087}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{CE77C59C-CFD2-429F-868C-8B04D23F94CA}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{CEA8DEFF-0AF7-4DB9-9A38-FB3C3AEFC0DE}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{D02E3AB9-7796-40CB-BDFC-20D834FE1F75}" at "HKEY_CLASSES_ROOT\TypeLib\".
Delete the registry key "{D0430FE6-1621-41e4-A109-CA5B0C57FE1D}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{D2598A88-4035-4556-84A2-B0F76A544E92}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{D367878E-F3B8-4235-A968-F378EF1B9A44}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{D3D9D58B-45B5-48AB-B199-B8C40560AEC7}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{D48D1EB2-BF95-4EE1-BD69-9AD0515F050D}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{D6065CEC-BDEE-4C6D-BE53-DD27DFED2E75}" at "HKEY_CLASSES_ROOT\TypeLib\".
Delete the registry key "{D6A9B8CC-192D-4F00-8BF8-AD8774011B07}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{D6D61C19-8563-4e8e-B755-0589DA6A3077}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{D7AF1F00-A702-4D1B-8490-8B7E0CDC3DEF}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{D8DF27C0-209C-41EF-8AF9-30A0C2C13268}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{DB43B405-43AA-4f01-82D8-D84D47E6019C}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{DBF9000E-F08C-4858-B769-C914A0FBB1D7}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{DC257063-045F-4BE2-BD5B-E12279C464F0}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{df20ddfa-0d19-463a-ab46-e5d8ef6efd69}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{E117D42B-839C-498A-95DA-647BC90E2B8F}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{E21BE468-5C18-43EB-B0CC-DB93A847D769}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{E2B98EEA-EE55-4E9B-A8C1-6E5288DF785A}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{E3DEC0EB-13E4-45EE-8F2E-577A3ECAFCBD}" at "HKEY_CLASSES_ROOT\TypeLib\".
Delete the registry key "{E4C3B74F-0C02-4D4E-B932-F7A1889B3ABB}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{E5960BC4-A76B-4211-BEEC-9AEE2AF8AAE6}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{E9203D3F-6404-40aa-99CC-5267215B81A7}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{EBCBF283-A798-4BA1-A8E1-E9413927F715}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{ECCBA771-92F2-497b-98AA-5FAA0BAA2DF6}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{F0B801B1-A239-473B-B6B4-6AE3DB3ABBD3}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{F13D3732-96BD-4108-AFEB-E85F68FF64DC}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{F23B1F18-CB1A-47ED-A1FE-B60494A626D0}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{F3D0D36F-23F8-4682-A195-74C92B03D4AF}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{F4F4A9DC-D4B6-4145-8EBC-8E5099686237}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{F544E0F5-CA3C-47EA-A64D-35FCF1602396}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{F6E8FC04-8B05-48B1-9399-848229502A06}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{F9BC0421-BB5C-447D-8547-BB45AFA80A4D}" at "HKEY_CLASSES_ROOT\TypeLib\".
Delete the registry key "{F9D06915-85A0-442A-A465-5F3AAAFE059B}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{FBA5FB05-58C3-45CB-8B0D-C2313EA048CF}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{FBEDBA6C-44A2-43b9-BD49-20EB6E0C4E86}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{FF5DCC7A-7147-41E1-86E8-DD05ABD588BF}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{FFFCC670-5CD4-4C09-952C-F53F46C2B1A7}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "Kuaiwan.exe" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\".
Delete the registry key "Kuaiwan" at "HKEY_CURRENT_USER\Software\".
Delete the registry key "KuaiWanInsert" at "HKEY_CURRENT_USER\Software\MozillaPlugins\".
Delete the registry key "madFlac" at "HKEY_CURRENT_USER\Software\".
Delete the registry key "QvodCDAudioOnArrival" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\".
Delete the registry key "QvodDVDMovieOnArrival" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\".
Delete the registry key "QvodMediaOnArrival" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\".
Delete the registry key "QvodMenu" at "HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\".
Delete the registry key "QvodPlayer.exe" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\".
Delete the registry key "QvodPlayer" at "HKEY_CURRENT_USER\Software\".
Delete the registry key "QvodPlayer" at "HKEY_CURRENT_USER\Software\CyberLink\Common\CLVSD\".
Delete the registry key "QvodPlayer" at "HKEY_LOCAL_MACHINE\SOFTWARE\".
Delete the registry value "(Default)" at "HKEY_CLASSES_ROOT\.dat\".
Delete the registry value "(Default)" at "HKEY_CLASSES_ROOT\.dvd\".
Delete the registry value "(Default)" at "HKEY_CLASSES_ROOT\.mov\".
Delete the registry value "(Default)" at "HKEY_CLASSES_ROOT\.torrent\".
Delete the registry value "(Default)" at "HKEY_CLASSES_ROOT\.wmp\".
Delete the registry value "qhtp" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Accepted Documents\".
Delete the registry value "qvod" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Accepted Documents\".
Delete the registry value "QvodCDAudioOnArrival" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\PlayCDAudioOnArrival\".
Delete the registry value "QvodDVDMovieOnArrival" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\PlayDVDMovieOnArrival\".
Delete the registry value "QvodMediaOnArrival" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\PlayMusicFilesOnArrival\".
Delete the registry value "QvodMediaOnArrival" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\PlayVideoFilesOnArrival\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.aif\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.aifc\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.aiff\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.asf\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.asx\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.au\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.avi\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.cda\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.ivf\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.m1v\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.m3u\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.mid\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.midi\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.mp2\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.mp3\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.mpa\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.mpe\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.mpeg\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.mpg\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.rat\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.rmi\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.rpm\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.swf\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.wav\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.wm\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.wma\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.wmv\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.wmx\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.wpl\".
If Ad.QvodPlayer uses rootkit technologies, use our RegAlyzer (http://www.safer-networking.org/index.php?page=regalyzer), RootAlyzer (http://forums.spybot.info/downloads.php?id=8) or our Total Commander anti-rootkit plugins (http://forums.spybot.info/downloads.php?id=3).
Browser:
The following browser plugins or items can either be removed directly in your browser, or through the help of e.g. Spybot-S&D (http://www.safer-networking.org/index.php?page=spybotsd) or RunAlyzer (http://www.safer-networking.org/index.php?page=runalyzer).
Please check your bookmarks for links to "kuaibo.com".
Final Words:
If neither Spybot-S&D nor self help did resolve the issue or you would prefer one on one help,
Please read these instructions (http://forums.spybot.info/showthread.php?t=288) before requesting assistance,
Then start your own thread in the Malware Removal Forum (http://forums.spybot.info/forumdisplay.php?f=22) where a volunteer analyst will advise you as soon as available.
Use this guide at your own risk; software should usually be better suited to remove malware, since it is able to look deeper.
If this guide was helpful to you, please consider donating towards this site (http://www.safer-networking.org/index.php?page=donate).
Threat Details:
Categories:
adware
Description:
Ad.QvodPlayer installs a chinese video player and adware applications, e.g. BaiduBar.
Removal Instructions:
Desktop:
Please remove the following files from your desktop.
To check where they are pointing to, right-click them and choose "Properties" from the context menu appearing.
Shortcuts named "QvodPlayer" and pointing to "E:\Program Files\QvodPlayer\QvodPlayer.exe".
Important: There are more desktop links that cannot be safely described in simple words. Please use Spybot-S&D (http://www.safer-networking.org/index.php?page=spybotsd) to remove them.
Quicklaunch area:
Important: There are more quicklaunch items that cannot be safely described in simple words. Please use Spybot-S&D (http://www.safer-networking.org/index.php?page=spybotsd) to remove them.
Autorun:
Please use Spybot-S&D (http://www.safer-networking.org/index.php?page=spybotsd), RunAlyzer (http://www.safer-networking.org/index.php?page=runalyzer) or msconfig.exe to remove the following autorun entries.
Entries named "Kuaiwan" and pointing to "?<$PROGRAMFILES>\Kuaiwan\Kuaiwan.exe*".
Entries named "QvodPlayer" and pointing to "<$SYSDRIVE>\Program Files\QvodPlayer\QvodTerminal.exe".
Installed Software List:
You can try to uninstall products with the names listed below; for items identified by other properties or to avoid malware getting active again on uninstallation, use Spybot-S&D (http://www.safer-networking.org/index.php?page=spybotsd) or RunAlyzer (http://www.safer-networking.org/index.php?page=runalyzer) to locate and get rid of these entries.
Products that have a key or property named "Kuaiwan".
Products that have a key or property named "QvodPlayer".
Files:
Please use Windows Explorer or another file manager of your choice to locate and delete these files.
The file at "<$COMMONAPPDATA>\KuaiWan\AppInfo.xml".
The file at "<$COMMONAPPDATA>\KuaiWan\User.ini".
The file at "<$PROGRAMFILES>\Kuaiwan\skin\DefaultSkin.xml".
The file at "<$PROGRAMFILES>\Kuaiwan\skin\DefaultSkin\MainTab\Thumbs.db".
The file at "<$PROGRAMFILES>\Kuaiwan\skin\DefaultSkin\WebGameTab\Thumbs.db".
The file at "<$SYSDRIVE>\desktop.ini".
The file at "<$SYSDRIVE>\Program Files\QvodPlayer\AddIn\ASBarBroker.exe".
The file at "<$SYSDRIVE>\Program Files\QvodPlayer\QvodCfg.ini".
The file at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\Default\volumep.bmp".
The file at "<$SYSDRIVE>\Program Files\QvodPlayer\Tip\PopMessage.xml".
The file at "<$SYSDRIVE>\Program Files\QvodPlayer\Tip\QvodTip.exe".
The file at "<$SYSDRIVE>\Program Files\QvodPlayer\Tip\QvodTips.dll".
Make sure you set your file manager to display hidden and system files. If Ad.QvodPlayer uses rootkit technologies, use the rootkit scanner integrated into Spybot-S&D (http://www.safer-networking.org/index.php?page=spybotsd) 2.x or our Total Commander anti-rootkit plugins (http://forums.spybot.info/downloads.php?id=3).
You will have to use a global search for files without a name specified. Be extra careful, because just the name might not be enough to identify files!
Important: There are more files that cannot be safely described in simple words. Please use Spybot-S&D (http://www.safer-networking.org/index.php?page=spybotsd) to remove them.
Folders:
Please use Windows Explorer or another file manager of your choice to locate and delete these folders.
The directory at "<$APPDATA>\qvodaddr".
The directory at "<$COMMONAPPDATA>\KuaiWan".
The directory at "<$COMMONPROGRAMFILES>\QvodPlayer\Codecs".
The directory at "<$COMMONPROGRAMFILES>\QvodPlayer".
The directory at "<$PROGRAMFILES>\Kuaiwan\skin\DefaultSkin\insert".
The directory at "<$PROGRAMFILES>\Kuaiwan\skin\DefaultSkin\key".
The directory at "<$PROGRAMFILES>\Kuaiwan\skin\DefaultSkin\MainTab".
The directory at "<$PROGRAMFILES>\Kuaiwan\skin\DefaultSkin\webgame".
The directory at "<$PROGRAMFILES>\Kuaiwan\skin\DefaultSkin\WebGameTab".
The directory at "<$PROGRAMFILES>\Kuaiwan\skin\DefaultSkin".
The directory at "<$PROGRAMFILES>\Kuaiwan\skin".
The directory at "<$PROGRAMFILES>\Kuaiwan".
The directory at "<$PROGRAMS>\QVOD".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\AddIn".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Codecs".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Lang".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Lyrics".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\Aluminum".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\Blue".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\Dark".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\Default".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\Exalted".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\Gray".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\MediaPlayer".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\MiNi".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\Navy".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\new_ccch".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\new_gysd".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\new_lskj".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\new_ly".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\new_QuickTimer".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\new_sl".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\new_xlxl".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\new_yh".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\new_yryh".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\new_zcl".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\Simple".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin\Simple2".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Skin".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Tip".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer\Viewdata".
The directory at "<$SYSDRIVE>\Program Files\QvodPlayer".
Make sure you set your file manager to display hidden and system files. If Ad.QvodPlayer uses rootkit technologies, use our RootAlyzer (http://forums.spybot.info/downloads.php?id=8) or our Total Commander anti-rootkit plugins (http://forums.spybot.info/downloads.php?id=3).
You will have to use a global search for files without a name specified. Be extra careful, because just the name might not be enough to identify folders!
Registry:
You can use regedit.exe (included in Windows) to locate and delete these registry entries.
A key in HKEY_CLASSES_ROOT\ named "KWCheck.KuaiWan.1", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "KWCheck.KuaiWan", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "QVOD", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "QVODADD", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "Qvodbt", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "QVODCHA", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "QvodInsert.QvodCtrl.1", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "QvodInsert.QvodCtrl", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.3g2", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.3gp", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.3gp2", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.3gpp", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.aac", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.ac3", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.aif", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.aifc", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.aiff", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.amr", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.amv", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.ape", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.asf", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.asx", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.au", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.avi", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.bik", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.cda", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.csf", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.cue", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.d2v", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.dsa", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.dsm", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.dss", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.dsv", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.dts", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.dvd", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.evo", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.f4v", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.flac", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.flc", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.fli", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.flv", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.ivf", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.m1v", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.m2p", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.m2ts", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.m2v", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.m3u", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.m4a", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.m4b", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.m4p", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.m4v", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mac", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mid", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.midi", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mkv", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mod", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mov", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mp2", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mp3", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mp4", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mp5", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mpa", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mpe", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mpeg", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mpg", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mpga", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mts", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.mvx", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.ogg", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.ogm", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.pm2", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.pmp", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.pmp2", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.pss", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.pva", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.qmv", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.qpl", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.qsed", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.qt", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.ra", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.ram", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.rat", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.rm", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.rmi", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.rmvb", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.roq", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.rp", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.rpm", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.rsc", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.rt", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.smil", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.smk", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.smv", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.swf", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.tim", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.tp", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.tpr", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.ts", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.tta", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.ttpl", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.vg2", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.vid", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.vob", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.vp6", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.vp7", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.wav", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.wm", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.wma", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.wmp", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.wmv", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.wmx", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.wpl", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "qvodplayer.wv", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "QVODSEA", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "ShareModule.QvodShare.1", plus associated values.
A key in HKEY_CLASSES_ROOT\ named "ShareModule.QvodShare", plus associated values.
Delete the registry key "{00000001-4FEF-40D3-B3FA-E0531B897F98}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{007FC171-01AA-4B3A-B2DB-062DEE815A1E}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{0180E49C-13BF-46DB-9AFD-9F52292E1C22}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{02AFA80F-4BEE-41FD-8572-214B58A9EF90}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{03D82D06-49E2-4E37-9670-BCAB4DBC642D}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{04FE9017-F873-410E-871E-AB91661A4EF7}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{0512B874-44F6-48F1-AFB5-6DE808DDE230}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{05F983EC-637F-4133-B489-5E03914929D7}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{0912B4DD-A30A-4568-B590-7179EBB420EC}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{09571A4B-F1FE-4C60-9760-DE6D310C7C31}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{0B390488-D80F-4A68-8408-48DC199F0E97}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{0C56B154-43F7-48A0-87B2-E9ACC8E1E471}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{0E9D4BF7-CBCB-46C7-BD80-4EF223A3DC2B}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{0F40E1E5-4F79-4988-B1A9-CC98794E6B55}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{11CC93E4-0BE6-4f8f-82AA-D577FB955B05}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{1365BE7A-C86A-473C-9A41-C0A6E82C9FA3}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{164A68B6-3F90-47C2-85A7-1E4D8952EF0A}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{1932C124-77DA-4151-99AA-234FEA09F463}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{1ADD57B8-A7A9-4518-B9B5-862590FF9EB4}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4}" at "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\".
Delete the registry key "{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4}" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\".
Delete the registry key "{1F71651E-65D2-40BF-AC44-275D11927D99}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{20E9DE6B-87D5-4E85-8BB0-038284A6C44D}" at "HKEY_CLASSES_ROOT\TypeLib\".
Delete the registry key "{212CA6D1-E9BB-41cf-BF77-06E000F403A8}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{238D0F23-5DC9-45A6-9BE2-666160C324DD}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{24FA7933-FE18-46A9-914A-C2AA0DBACE93}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{2566F758-FE4A-4691-9F93-30AF685BB403}" at "HKEY_CLASSES_ROOT\TypeLib\".
Delete the registry key "{2627A1B6-F8FF-4E9C-9422-4908E8D1DFE9}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{2F09858D-D67F-4F8B-8DE8-666666CB9FAD}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{32E2BDD6-8812-42c3-A907-B9587C148EE3}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{363F46BE-27B4-4C8D-99E7-B1E049B84376}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{37991D68-42A3-40E3-8C05-037170E1A42A}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{3BB3828F-9787-48A7-A894-6ADE46C64737}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{3CCC052E-BDEE-408A-BEA7-90914EF2964B}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{3E3ECA90-4D6A-4344-98C3-1BB95BF24038}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{3FD0479E-D6B9-4629-9496-509D3D070918}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{412C98D0-B46E-4FFA-92E1-4016782EE0AB}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{432F118C-DB79-4561-9799-CC95EA78208B}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{46E00789-37CA-4278-8907-02088898B6B0}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{47E792CF-0BBE-4F7A-859C-194B0768650A}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{48B51CD7-D8FA-4452-B00C-5BBFDE92B9AB}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{49590BC9-6DD5-4E44-AD4C-E8FCB7131EC4}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{4DB2B5D9-4556-4340-B189-AD20110D953F}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{50DDA33E-C529-4343-9689-338ADC793BB5}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{525F116F-04AD-40A2-AE2F-A0C4E1AFEF98}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{533B0507-1869-4503-B61C-DA4842EEB800}" at "HKEY_CLASSES_ROOT\TypeLib\".
Delete the registry key "{53D9DE0B-FC61-4650-9773-74D13CC7E582}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{545A00C2-FCCC-40B3-9310-2C36AE64B0DD}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{54A35221-2C8D-4A31-A5DF-6D809847E393}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{5593CF36-190B-4A47-A4DD-9680093DBA1D}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{55DA30FC-F16B-49FC-BAA5-AE59FC65A150}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{5711D95F-0984-4A22-8FF8-90A954958D0C}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{57A5353F-2725-440c-BBBC-DB20A1C8A57D}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{5905A0A9-A82C-4A7B-8418-FC1F6D1AD5DB}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{59A0DB73-0287-4C9A-9D3C-8CFF39F8E5DB}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{5BC26A00-5101-47d7-A5DB-AB6AAC44F51B}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{60765CF5-01C2-4EE7-A44B-C791CF25FEA0}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{61F47056-E400-43D3-AF1E-AB7DFFD4C4AD}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{64697678-0000-0010-8000-00AA00389B71}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{64F2005C-6CF5-4652-B94F-600360B15B27}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{650DE05E-5CD3-44F8-BA20-A5BB91FC61E6}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{66EA14E6-E2B3-433D-923E-EE401CADBBD9}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{6B97CB13-A992-4970-8864-4F32E845B7B4}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{6D3688CE-3E9D-42F4-92CA-8A11119D25CD}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{6E756F73-15A3-4ECE-98C0-D9CD2744F5A8}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{6F6C6F63-0000-0010-8000-00AA00389B71}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{7139E26A-49CA-4344-B063-C702858627D9}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{75878923-D1ED-49AF-B550-BC993578292E}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{760A8F35-97E7-479D-AAF5-DA9EFF95D751}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{765035B3-5944-4A94-806B-20EE3415F26F}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{78302E8C-3C6F-267C-2E0D-1D37BF7E3D64}" at "HKEY_LOCAL_MACHINE\SOFTWARE\".
Delete the registry key "{78766964-0000-0010-8000-00AA00389B71}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{7A33CE9E-4F33-4B4E-B263-6AEEAB6C3DC2}" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\".
Delete the registry key "{7B63A013-DC2C-462E-9292-CAF8C867100F}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{7B6F8B69-0925-48F1-AE78-7506D6C3972C}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{7CA71B1E-A67D-4D54-A200-FA47605483A7}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{7E493C9A-2E54-4F25-9B9A-D3C4DEBFCB62}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{803E8280-F3CE-4201-982C-8CD8FB512004}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{86708513-5A2E-424f-AB46-F4BE3F82954F}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{87271B4E-1726-4CED-AF0D-BE675621FD29}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{87BBB4ED-1767-4b7e-821C-7C4657E439D4}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{895322C5-84A1-450C-8478-C57793CAE86F}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{89B2C28D-779F-4704-AD29-113B0977E8A5}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{8E8B4A31-408B-4929-86A4-A9FA9F01BA43}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{8E9922F0-B775-45B8-B650-941BEA790EEB}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{8F43B7D9-9D6B-4F48-BE18-4D787C795EEA}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{90A9B7D2-3794-45EA-9E23-140E3938D2D9}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{90C7D10E-CE9A-479B-A238-1A0F2396DE43}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{91878E42-FC03-4785-B513-1F9E613D1027}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{93A22E7A-5091-45EF-BA61-6DA26156A5D0}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{941A4793-A705-4312-8DFC-C11CA05F397E}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{94C3E4BB-A261-4A83-B437-EA6F7A28CA68}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{94C3E4BB-A261-4A83-B437-EA6F7A28CA68}" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\".
Delete the registry key "{96CE7B0D-06B3-42E2-8DB7-CFC6CF0121F6}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{9736D831-9D6C-4E72-B6E7-560EF9181001}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{9852A670-F845-491B-9BE6-EBD841B8A613}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{99735894-CAF4-488B-8275-B8CB1998216E}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{99AA8908-FC7F-4815-B023-3BC2F5F8D372}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{99D9DC39-90DE-41D3-AECA-345D7F1B9540}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{9A6E096E-4588-3E32-F06C-69F6B8784825}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{9A6E096E-4588-3E32-F06C-69F6B8784825}" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\".
Delete the registry key "{9A98ADCC-C6A4-449E-A8B1-0363673D9F8A}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{9B2DBA95-39D2-4537-8BBF-CED535E8DE56}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{9F44453E-1E46-4D5C-B57C-112FF2EDAE82}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{9FF48807-E133-40AA-826F-9B2959E5232D}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{A0606860-51BE-4CF6-99C0-7CE5F78AC2D8}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{A28F324B-DDC5-4999-AA25-D3A7E25EF7A8}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{A36C253D-CEE4-4BCA-9CC2-E03CF6BBB054}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{A753A1EC-973E-4718-AF8E-A3F554D45C44}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{A8B25C0E-0894-4531-B668-AB1599FAF7F6}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{A94662D1-35FD-43d1-BDA3-172CE4D5C236}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{A975010E-D292-4A74-A9FF-E536C94C0647}" at "HKEY_CLASSES_ROOT\TypeLib\".
Delete the registry key "{AAA4AACD-FD95-4240-9C45-9EB98E5DAC52}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{ACD23F8C-B37E-4B2D-BA08-86CB6E621D6A}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{ACE4747B-35BD-4E97-9DD7-1D4245B0695C}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{AD461A96-4DB8-4C6E-BF23-84D682ADC382}" at "HKEY_CLASSES_ROOT\TypeLib\".
Delete the registry key "{AD92C6E6-997A-4E9E-9D7D-EDED6DE933FB}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{AF54DF04-9597-4B3D-947A-3A7A7F29C0E9}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{B3DE7EDC-0CD4-4d07-B1C5-92219CD475CC}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{B4DAEDB7-7F0E-434F-9AA3-B82B549A3680}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{B5A7D70F-AE96-4F83-B811-572CA3529323}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{B6EAE677-074B-43EA-9239-5E509F87C652}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{B7BCE5B0-2112-420A-BDFF-178995FBFCA2}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{B841F346-4835-4de8-AA5E-2E7CD2D4C435}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{B86F6BEE-E7C0-4D03-8D52-5B4430CF6C88}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{B8E20CD7-BAC2-4820-9AA6-1060B3AF25E2}" at "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\".
Delete the registry key "{BA327E17-6AE9-430B-8246-1A90208AD1D7}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{BAC04407-3588-42AA-93BE-6D3720E9FB28}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{BB9CDE7F-AF28-4205-9B3C-789FA7D0F29F}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{BD4FB4BE-809D-487b-ADD6-F7D164247E52}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{BDE0D9DF-288F-4286-906F-93197673B3A7}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{C1630673-8C58-481C-9F15-83F11D8B89F0}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{C204438D-6E1A-4309-B09C-0C0F749863AF}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{C29CE93C-3908-4DA7-A7DA-4968C3AF2AE8}" at "HKEY_CLASSES_ROOT\TypeLib\".
Delete the registry key "{C2D6D98F-09CA-4524-AF64-1049B5665C9C}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{C7E094E1-A326-4E33-824D-6598D399DA13}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{C8B9C208-9E5C-4F09-AED5-B21A273C4CCA}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{C9ECE7B3-1D8E-41F5-9F24-B255DF16C087}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{CE77C59C-CFD2-429F-868C-8B04D23F94CA}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{CEA8DEFF-0AF7-4DB9-9A38-FB3C3AEFC0DE}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{D02E3AB9-7796-40CB-BDFC-20D834FE1F75}" at "HKEY_CLASSES_ROOT\TypeLib\".
Delete the registry key "{D0430FE6-1621-41e4-A109-CA5B0C57FE1D}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{D2598A88-4035-4556-84A2-B0F76A544E92}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{D367878E-F3B8-4235-A968-F378EF1B9A44}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{D3D9D58B-45B5-48AB-B199-B8C40560AEC7}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{D48D1EB2-BF95-4EE1-BD69-9AD0515F050D}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{D6065CEC-BDEE-4C6D-BE53-DD27DFED2E75}" at "HKEY_CLASSES_ROOT\TypeLib\".
Delete the registry key "{D6A9B8CC-192D-4F00-8BF8-AD8774011B07}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{D6D61C19-8563-4e8e-B755-0589DA6A3077}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{D7AF1F00-A702-4D1B-8490-8B7E0CDC3DEF}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{D8DF27C0-209C-41EF-8AF9-30A0C2C13268}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{DB43B405-43AA-4f01-82D8-D84D47E6019C}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{DBF9000E-F08C-4858-B769-C914A0FBB1D7}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{DC257063-045F-4BE2-BD5B-E12279C464F0}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{df20ddfa-0d19-463a-ab46-e5d8ef6efd69}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{E117D42B-839C-498A-95DA-647BC90E2B8F}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{E21BE468-5C18-43EB-B0CC-DB93A847D769}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{E2B98EEA-EE55-4E9B-A8C1-6E5288DF785A}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{E3DEC0EB-13E4-45EE-8F2E-577A3ECAFCBD}" at "HKEY_CLASSES_ROOT\TypeLib\".
Delete the registry key "{E4C3B74F-0C02-4D4E-B932-F7A1889B3ABB}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{E5960BC4-A76B-4211-BEEC-9AEE2AF8AAE6}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{E9203D3F-6404-40aa-99CC-5267215B81A7}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{EBCBF283-A798-4BA1-A8E1-E9413927F715}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{ECCBA771-92F2-497b-98AA-5FAA0BAA2DF6}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{F0B801B1-A239-473B-B6B4-6AE3DB3ABBD3}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{F13D3732-96BD-4108-AFEB-E85F68FF64DC}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{F23B1F18-CB1A-47ED-A1FE-B60494A626D0}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{F3D0D36F-23F8-4682-A195-74C92B03D4AF}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{F4F4A9DC-D4B6-4145-8EBC-8E5099686237}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{F544E0F5-CA3C-47EA-A64D-35FCF1602396}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{F6E8FC04-8B05-48B1-9399-848229502A06}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{F9BC0421-BB5C-447D-8547-BB45AFA80A4D}" at "HKEY_CLASSES_ROOT\TypeLib\".
Delete the registry key "{F9D06915-85A0-442A-A465-5F3AAAFE059B}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{FBA5FB05-58C3-45CB-8B0D-C2313EA048CF}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{FBEDBA6C-44A2-43b9-BD49-20EB6E0C4E86}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{FF5DCC7A-7147-41E1-86E8-DD05ABD588BF}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "{FFFCC670-5CD4-4C09-952C-F53F46C2B1A7}" at "HKEY_CLASSES_ROOT\CLSID\".
Delete the registry key "Kuaiwan.exe" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\".
Delete the registry key "Kuaiwan" at "HKEY_CURRENT_USER\Software\".
Delete the registry key "KuaiWanInsert" at "HKEY_CURRENT_USER\Software\MozillaPlugins\".
Delete the registry key "madFlac" at "HKEY_CURRENT_USER\Software\".
Delete the registry key "QvodCDAudioOnArrival" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\".
Delete the registry key "QvodDVDMovieOnArrival" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\".
Delete the registry key "QvodMediaOnArrival" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\".
Delete the registry key "QvodMenu" at "HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\".
Delete the registry key "QvodPlayer.exe" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\".
Delete the registry key "QvodPlayer" at "HKEY_CURRENT_USER\Software\".
Delete the registry key "QvodPlayer" at "HKEY_CURRENT_USER\Software\CyberLink\Common\CLVSD\".
Delete the registry key "QvodPlayer" at "HKEY_LOCAL_MACHINE\SOFTWARE\".
Delete the registry value "(Default)" at "HKEY_CLASSES_ROOT\.dat\".
Delete the registry value "(Default)" at "HKEY_CLASSES_ROOT\.dvd\".
Delete the registry value "(Default)" at "HKEY_CLASSES_ROOT\.mov\".
Delete the registry value "(Default)" at "HKEY_CLASSES_ROOT\.torrent\".
Delete the registry value "(Default)" at "HKEY_CLASSES_ROOT\.wmp\".
Delete the registry value "qhtp" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Accepted Documents\".
Delete the registry value "qvod" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Accepted Documents\".
Delete the registry value "QvodCDAudioOnArrival" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\PlayCDAudioOnArrival\".
Delete the registry value "QvodDVDMovieOnArrival" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\PlayDVDMovieOnArrival\".
Delete the registry value "QvodMediaOnArrival" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\PlayMusicFilesOnArrival\".
Delete the registry value "QvodMediaOnArrival" at "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\PlayVideoFilesOnArrival\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.aif\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.aifc\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.aiff\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.asf\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.asx\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.au\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.avi\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.cda\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.ivf\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.m1v\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.m3u\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.mid\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.midi\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.mp2\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.mp3\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.mpa\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.mpe\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.mpeg\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.mpg\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.rat\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.rmi\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.rpm\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.swf\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.wav\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.wm\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.wma\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.wmv\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.wmx\".
Delete the registry value "qvodplayerbak" at "HKEY_CLASSES_ROOT\.wpl\".
If Ad.QvodPlayer uses rootkit technologies, use our RegAlyzer (http://www.safer-networking.org/index.php?page=regalyzer), RootAlyzer (http://forums.spybot.info/downloads.php?id=8) or our Total Commander anti-rootkit plugins (http://forums.spybot.info/downloads.php?id=3).
Browser:
The following browser plugins or items can either be removed directly in your browser, or through the help of e.g. Spybot-S&D (http://www.safer-networking.org/index.php?page=spybotsd) or RunAlyzer (http://www.safer-networking.org/index.php?page=runalyzer).
Please check your bookmarks for links to "kuaibo.com".
Final Words:
If neither Spybot-S&D nor self help did resolve the issue or you would prefer one on one help,
Please read these instructions (http://forums.spybot.info/showthread.php?t=288) before requesting assistance,
Then start your own thread in the Malware Removal Forum (http://forums.spybot.info/forumdisplay.php?f=22) where a volunteer analyst will advise you as soon as available.