spyware removal instructions

CWS.Feads removal

Spyware Feads Information
Name: CWS.Feads
Category: Hijacker
Date: 2005-01-01
Dangerous: Yes
CWS.Feads is a hijacker - whenever you browse internet hijacker may redirect you to one of its preset internet sites (usually to annoyingly show you some product for you to buy). Hijackers also ocasionally replace ads on the sites you intended to visit.
>> Delete CWS.Feads automatically - Download Spyware Doctor

CWS.Feads Removal Instructions
Kill the following processes
iefg32.exe, iegr32.exe, mfcuf32.exe, addkc32.exe, apiac.exe, apifb.exe, apigj.exe, apijn32.exe, apivt.exe, appsh.exe, appwn32.exe, atlfs32.exe, crvl.exe, d3cq.exe, d3fd32.exe, d3fl32.exe, d3nr32.exe, d3ue.exe, d3zg.exe, ipyx32.exe, mfckb.exe, mfcui32.exe, msnc32.exe, mszv32.exe, ntwg.exe, ntwn.exe, ntyk32.exe, ntyo32.exe, sdkev.exe, sdkrr32.exe, sysea.exe, sysjq.exe, syskr.exe, syslr.exe, addgp32.exe, addwh32.exe, apica.exe, apioe.exe, apivy.exe, appio.exe, appis32.exe, appjc32.exe, appoe32.exe, atlhy.exe, atlkt32.exe, atlpv32.exe, crby32.exe, crcz.exe, crko.exe, crsw32.exe, d3fm.exe, d3gj.exe, d3ul32.exe, iefi.exe, iefy.exe, ieug32.exe, iewe32.exe, ipgs.exe, iphj32.exe, ippy.exe, ipst32.exe, mfcgt32.exe, mfcqc32.exe, mfcuo.exe, msph32.exe, netjh32.exe, ntdx.exe, sdkdh.exe, sdkhb32.exe, sdkly.exe, winga.exe, winlo.exe, winns32.exe, winyw32.exe, winmc.exe, winnj32.exe
Unregister the following DLLs and reboot
mfcgy32.dll, uvmjb.dll.
atlrl32.dll, ipog.dll, mfcbm32.dll in Windows\
adddx.dll, mssz32.dll in Windows\system32\
Delete these registry entries
HKEY_CLASSES_ROOT\clsid\{2a6a75c2-3c67-5e95-eba8-28a462abd792}
HKEY_CLASSES_ROOT\clsid\{4700f4b2-eb75-07ef-2853-5b264bd6e7db}
HKEY_CLASSES_ROOT\clsid\{53a6ba45-5944-1b2a-c008-fb29ecdce63c}
HKEY_CLASSES_ROOT\clsid\{6ca3def1-f477-8ca2-64fd-b558a4257b4a}
HKEY_CLASSES_ROOT\clsid\{89abe5c0-3767-80d7-a957-8cc68dc6199b}
HKEY_CLASSES_ROOT\clsid\{a69b7d98-9dac-21c6-7adb-7ff21d28cec1}
HKEY_CLASSES_ROOT\clsid\{af324411-fe23-2928-2624-6e2035e4f460}
HKEY_CLASSES_ROOT\clsid\{b6bcb9ce-7fa1-f173-041b-e367563bb601}
HKEY_CLASSES_ROOT\clsid\{c668ea18-2d58-b7ff-b81a-5dfb1e599256}
HKEY_CLASSES_ROOT\clsid\{e897b7a0-ebe4-3a18-7dd3-77e65116b006}
HKEY_CLASSES_ROOT\clsid\{f452fa15-98c9-bd51-ac62-418e0c391ec0}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{4700f4b2-eb75-07ef-2853-5b264bd6e7db}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{a69b7d98-9dac-21c6-7adb-7ff21d28cec1}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{e897b7a0-ebe4-3a18-7dd3-77e65116b006}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{f452fa15-98c9-bd51-ac62-418e0c391ec0}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\mfckb.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\addgp32.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\addkc32.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\apiac.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\apica.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\apifb.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\apijn32.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\apioe.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\apivt.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\apivy.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\appio.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\appjc32.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\appsh.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\appwn32.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\atlhy.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\atlkt32.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\atlpv32.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\crko.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\crvl.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\d3cq.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\d3fd32.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\d3fm.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\d3gj.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\d3nr32.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\d3ul32.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\d3zg.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\iefi.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\iewe32.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\iphj32.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\ippy.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\javaaj.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\javahn32.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\javaov.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\javary32.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\javava32.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\javawa.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\mfcgt32.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\mfcqc32.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\mfcui32.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\msph32.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\mszv32.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\netjh32.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\ntdx.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\ntwn.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\ntyo32.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\sdkev.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\sdkhb32.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\sdkrr32.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\sysea.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\sysjq.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\syskr.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\syslr.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\winga.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\winmc.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\winnj32.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\winyw32.exe
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_*008f*0010%af*00e5*0003*0017*001a*00a4*00b6*00c0*00a8
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy_*00bdo.#*017e*201a*201e*0081*00f5*00d8*00c2*00b4*001e*00e2
HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\legacy___ns_service_3
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\Å%afÕñÂÓ¿
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\__ns_service_3
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\¢o.#×éäü§°Ô┤Ô
Remove the following files
dict.dat, iefg32.exe, iegr32.exe, mfcgy32.dll, mfcuf32.exe, uvmjb.dll.
addkc32.exe, apiac.exe, apifb.exe, apigj.exe, apijn32.exe, apivt.exe, appsh.exe, appwn32.exe, atlfs32.exe, atlrl32.dll, crvl.exe, d3cq.exe, d3fd32.exe, d3fl32.exe, d3nr32.exe, d3ue.exe, d3zg.exe, ipog.dll, ipyx32.exe, mfcbm32.dll, mfckb.exe, mfcui32.exe, msnc32.exe, mszv32.exe, ntwg.exe, ntwn.exe, ntyk32.exe, ntyo32.exe, sdkev.exe, sdkrr32.exe, sysea.exe, sysjq.exe, syskr.exe, syslr.exe, winmc.exe, winnj32.exe in Windows\
adddx.dll, addgp32.exe, addwh32.exe, apica.exe, apioe.exe, apivy.exe, appio.exe, appis32.exe, appjc32.exe, appoe32.exe, atlhy.exe, atlkt32.exe, atlpv32.exe, crby32.exe, crcz.exe, crko.exe, crsw32.exe, d3fm.exe, d3gj.exe, d3ul32.exe, iefi.exe, iefy.exe, ieug32.exe, iewe32.exe, ipgs.exe, iphj32.exe, ippy.exe, ipst32.exe, mfcgt32.exe, mfcqc32.exe, mfcuo.exe, msph32.exe, mssz32.dll, netjh32.exe, ntdx.exe, sdkdh.exe, sdkhb32.exe, sdkly.exe, winga.exe, winlo.exe, winns32.exe, winyw32.exe in Windows\system32\

Bookmark CWS.Feads page

 Previous Spyware: Remove CWS.Explorer32 Next Spyware: Remove CWS.find-help