| CWS.GonnaSearch removal| Spyware GonnaSearch Information |
|---|
Name: CWS.GonnaSearch Category: Search Hijacker Date: 2004-01-30 Dangerous: Yes | CWS.GonnaSearch is one of Search Hijacker spywares. Installs three browser helper objects without permission, & hijacks to www.gonnasearch.com Finding it on your computer means that your computer is infected with Search Hijacker and crucial data could be endangered or even lost.
CWS.GonnaSearch description by publisher: Here is what the vendor says about themselves at www.going tosearch.com/about.html (June 23, 2004): "Coming Soon" >> Delete CWS.GonnaSearch automatically - Download Spyware Doctor
| CWS.GonnaSearch Removal Instructions |
|---|
Kill the following processes install.exe, install.exe, install.exe | Unregister the following DLLs and reboot autosearch.dll, autose~1.dll, searchaddon.dll, search~1.dll, toolbar.dll, webinfo.dll in Program Files\internet explorer\toolbar\ autosearch.dll, autose~1.dll, mgs_32.dll, searchaddon.dll, search~1.dll, toolbar.dll, webinfo.dll in Program Files\intern~1\toolbar\ mgs_32.dll in Windows\system32\
| Delete these registry entries HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser\{92f02779-6d88-4958-8ad3-83c12d86adc7} HKEY_LOCAL_MACHINE\software\classes\autosearch.autosearchobj HKEY_LOCAL_MACHINE\software\classes\autosearch.autosearchobj\clsid HKEY_LOCAL_MACHINE\software\classes\autosearch.autosearchobj\curver HKEY_LOCAL_MACHINE\software\classes\clsid\{150fa160-130d-451f-b863-b655061432ba} HKEY_LOCAL_MACHINE\software\classes\clsid\{799a370d-5993-4887-9df7-0a4756a77d00} HKEY_LOCAL_MACHINE\software\classes\clsid\{92f02779-6d88-4958-8ad3-83c12d86adc7} HKEY_LOCAL_MACHINE\software\classes\clsid\{a55581dc-2cdb-4089-8878-71a080b22342} HKEY_LOCAL_MACHINE\software\classes\clsid\{e7afff2a-1b57-49c7-bf6b-e5123394c970} HKEY_LOCAL_MACHINE\software\classes\interface\{3d11cbe7-1eee-4c8f-ab5c-a4cf7939f1f1} HKEY_LOCAL_MACHINE\software\classes\interface\{7142c3e1-1fe1-4a2a-b882-681dc7db0d30} HKEY_LOCAL_MACHINE\software\classes\interface\{a1376d2c-12eb-472b-9c8c-db24448d3c91} HKEY_LOCAL_MACHINE\software\classes\ml.iehlprobj HKEY_LOCAL_MACHINE\software\classes\ml.iehlprobj\clsid HKEY_LOCAL_MACHINE\software\classes\ml.iehlprobj\curver HKEY_LOCAL_MACHINE\software\classes\searchaddon.ieobject HKEY_LOCAL_MACHINE\software\classes\searchaddon.ieobject\clsid HKEY_LOCAL_MACHINE\software\classes\searchaddon.ieobject\curver HKEY_LOCAL_MACHINE\software\classes\softomate.ietoolbar HKEY_LOCAL_MACHINE\software\classes\softomate.ietoolbar\clsid HKEY_LOCAL_MACHINE\software\classes\softomate.ietoolbar\curver HKEY_LOCAL_MACHINE\software\classes\softomate.softomateobj HKEY_LOCAL_MACHINE\software\classes\softomate.softomateobj\clsid HKEY_LOCAL_MACHINE\software\classes\softomate.softomateobj\curver HKEY_LOCAL_MACHINE\software\classes\typelib\{7e68f5f3-782c-4bcd-88df-1e3d6350de4c} HKEY_LOCAL_MACHINE\software\classes\typelib\{a65529dd-4833-4784-a594-205f4a50267a} HKEY_LOCAL_MACHINE\software\classes\typelib\{c1947e81-7036-4ac8-ac09-906224f6f4fc} HKEY_LOCAL_MACHINE\software\classes\typelib\{f7825d95-cdd7-4e73-bfdc-846de0f336be} HKEY_LOCAL_MACHINE\software\classes\webinfo.webinfoobj HKEY_LOCAL_MACHINE\software\classes\webinfo.webinfoobj\clsid HKEY_LOCAL_MACHINE\software\classes\webinfo.webinfoobj\curver HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{1ae2f26c-8e23-4930-a68d-9e681a764001}\bandclsid HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{1ae2f26c-8e23-4930-a68d-9e681a764001}\buttontext HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{1ae2f26c-8e23-4930-a68d-9e681a764001}\clsid HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{1ae2f26c-8e23-4930-a68d-9e681a764001}\default visible HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{1ae2f26c-8e23-4930-a68d-9e681a764001}\hoticon HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{1ae2f26c-8e23-4930-a68d-9e681a764001}\icon HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{1ae2f26c-8e23-4930-a68d-9e681a764001}\menustatusbar HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{1ae2f26c-8e23-4930-a68d-9e681a764001}\menutext HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{799a370d-5993-4887-9df7-0a4756a77d00} HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{a55581dc-2cdb-4089-8878-71a080b22342} HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{799a370d-5993-4887-9df7-0a4756a77d00} HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{799a370d-5993-4887-9df7-0a4756a77d00}\displayname HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{799a370d-5993-4887-9df7-0a4756a77d00}\uninstallstring HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{a55581dc-2cdb-4089-8878-71a080b22342} HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{a55581dc-2cdb-4089-8878-71a080b22342}\displayname HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{a55581dc-2cdb-4089-8878-71a080b22342}\size HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{a55581dc-2cdb-4089-8878-71a080b22342}\uninstallstring HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{e7afff2a-1b57-49c7-bf6b-e5123394c970} HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{e7afff2a-1b57-49c7-bf6b-e5123394c970}\displayname HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{e7afff2a-1b57-49c7-bf6b-e5123394c970}\uninstallstring HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\softomate.softomateobjietoolbar\displayname HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\softomate.softomateobjietoolbar\uninstallstring
| Remove the following files avp32.exe-1432e758.pf, basis.xml, gstb.exe-0691e3df.pf, install.exe-29dfbb9e.pf, ping.exe-31216d26.pf, tb_buttons.xml, tb_commands.xml, tb_settings.xml, tmpinst.exe-2b141db4.pf, tmpinst1.exe-2e79a0e5.pf, tmpinst2.exe-0b51ed5b.pf, toolbar.crc. about.html, autosearch.dll, autose~1.dll, error.html, options.html, searchaddon.dll, search~1.dll, toolbar.dll, webinfo.dll in Program Files\internet explorer\toolbar\ about.html, autosearch.dll, autose~1.dll, error.html, install.exe, mgs_32.dll, options.html, searchaddon.dll, search~1.dll, toolbar.dll, webinfo.dll in Program Files\intern~1\toolbar\ install.exe in Windows\drivers\audio\ install.exe in Windows\drivers\video\ mgs_32.dll in Windows\system32\
| Remove the following directories Program Files\internet explorer\toolbar
|
Bookmark CWS.GonnaSearch page
|