spyware removal instructions

CWS.GonnaSearch removal

Spyware GonnaSearch Information
Name: CWS.GonnaSearch
Category: Search Hijacker
Date: 2004-01-30
Dangerous: Yes
CWS.GonnaSearch is one of Search Hijacker spywares.
Installs three browser helper objects without permission, & hijacks to www.gonnasearch.com Finding it on your computer means that your computer is infected with Search Hijacker and crucial data could be endangered or even lost.
CWS.GonnaSearch description by publisher:
Here is what the vendor says about themselves at www.going tosearch.com/about.html (June 23, 2004): "Coming Soon"
>> Delete CWS.GonnaSearch automatically - Download Spyware Doctor

CWS.GonnaSearch Removal Instructions
Kill the following processes
install.exe, install.exe, install.exe
Unregister the following DLLs and reboot
autosearch.dll, autose~1.dll, searchaddon.dll, search~1.dll, toolbar.dll, webinfo.dll in Program Files\internet explorer\toolbar\
autosearch.dll, autose~1.dll, mgs_32.dll, searchaddon.dll, search~1.dll, toolbar.dll, webinfo.dll in Program Files\intern~1\toolbar\
mgs_32.dll in Windows\system32\
Delete these registry entries
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser\{92f02779-6d88-4958-8ad3-83c12d86adc7}
HKEY_LOCAL_MACHINE\software\classes\autosearch.autosearchobj
HKEY_LOCAL_MACHINE\software\classes\autosearch.autosearchobj\clsid
HKEY_LOCAL_MACHINE\software\classes\autosearch.autosearchobj\curver
HKEY_LOCAL_MACHINE\software\classes\clsid\{150fa160-130d-451f-b863-b655061432ba}
HKEY_LOCAL_MACHINE\software\classes\clsid\{799a370d-5993-4887-9df7-0a4756a77d00}
HKEY_LOCAL_MACHINE\software\classes\clsid\{92f02779-6d88-4958-8ad3-83c12d86adc7}
HKEY_LOCAL_MACHINE\software\classes\clsid\{a55581dc-2cdb-4089-8878-71a080b22342}
HKEY_LOCAL_MACHINE\software\classes\clsid\{e7afff2a-1b57-49c7-bf6b-e5123394c970}
HKEY_LOCAL_MACHINE\software\classes\interface\{3d11cbe7-1eee-4c8f-ab5c-a4cf7939f1f1}
HKEY_LOCAL_MACHINE\software\classes\interface\{7142c3e1-1fe1-4a2a-b882-681dc7db0d30}
HKEY_LOCAL_MACHINE\software\classes\interface\{a1376d2c-12eb-472b-9c8c-db24448d3c91}
HKEY_LOCAL_MACHINE\software\classes\ml.iehlprobj
HKEY_LOCAL_MACHINE\software\classes\ml.iehlprobj\clsid
HKEY_LOCAL_MACHINE\software\classes\ml.iehlprobj\curver
HKEY_LOCAL_MACHINE\software\classes\searchaddon.ieobject
HKEY_LOCAL_MACHINE\software\classes\searchaddon.ieobject\clsid
HKEY_LOCAL_MACHINE\software\classes\searchaddon.ieobject\curver
HKEY_LOCAL_MACHINE\software\classes\softomate.ietoolbar
HKEY_LOCAL_MACHINE\software\classes\softomate.ietoolbar\clsid
HKEY_LOCAL_MACHINE\software\classes\softomate.ietoolbar\curver
HKEY_LOCAL_MACHINE\software\classes\softomate.softomateobj
HKEY_LOCAL_MACHINE\software\classes\softomate.softomateobj\clsid
HKEY_LOCAL_MACHINE\software\classes\softomate.softomateobj\curver
HKEY_LOCAL_MACHINE\software\classes\typelib\{7e68f5f3-782c-4bcd-88df-1e3d6350de4c}
HKEY_LOCAL_MACHINE\software\classes\typelib\{a65529dd-4833-4784-a594-205f4a50267a}
HKEY_LOCAL_MACHINE\software\classes\typelib\{c1947e81-7036-4ac8-ac09-906224f6f4fc}
HKEY_LOCAL_MACHINE\software\classes\typelib\{f7825d95-cdd7-4e73-bfdc-846de0f336be}
HKEY_LOCAL_MACHINE\software\classes\webinfo.webinfoobj
HKEY_LOCAL_MACHINE\software\classes\webinfo.webinfoobj\clsid
HKEY_LOCAL_MACHINE\software\classes\webinfo.webinfoobj\curver
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{1ae2f26c-8e23-4930-a68d-9e681a764001}\bandclsid
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{1ae2f26c-8e23-4930-a68d-9e681a764001}\buttontext
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{1ae2f26c-8e23-4930-a68d-9e681a764001}\clsid
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{1ae2f26c-8e23-4930-a68d-9e681a764001}\default visible
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{1ae2f26c-8e23-4930-a68d-9e681a764001}\hoticon
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{1ae2f26c-8e23-4930-a68d-9e681a764001}\icon
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{1ae2f26c-8e23-4930-a68d-9e681a764001}\menustatusbar
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{1ae2f26c-8e23-4930-a68d-9e681a764001}\menutext
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{799a370d-5993-4887-9df7-0a4756a77d00}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{a55581dc-2cdb-4089-8878-71a080b22342}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{799a370d-5993-4887-9df7-0a4756a77d00}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{799a370d-5993-4887-9df7-0a4756a77d00}\displayname
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{799a370d-5993-4887-9df7-0a4756a77d00}\uninstallstring
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{a55581dc-2cdb-4089-8878-71a080b22342}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{a55581dc-2cdb-4089-8878-71a080b22342}\displayname
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{a55581dc-2cdb-4089-8878-71a080b22342}\size
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{a55581dc-2cdb-4089-8878-71a080b22342}\uninstallstring
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{e7afff2a-1b57-49c7-bf6b-e5123394c970}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{e7afff2a-1b57-49c7-bf6b-e5123394c970}\displayname
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\{e7afff2a-1b57-49c7-bf6b-e5123394c970}\uninstallstring
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\softomate.softomateobjietoolbar\displayname
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\softomate.softomateobjietoolbar\uninstallstring
Remove the following files
avp32.exe-1432e758.pf, basis.xml, gstb.exe-0691e3df.pf, install.exe-29dfbb9e.pf, ping.exe-31216d26.pf, tb_buttons.xml, tb_commands.xml, tb_settings.xml, tmpinst.exe-2b141db4.pf, tmpinst1.exe-2e79a0e5.pf, tmpinst2.exe-0b51ed5b.pf, toolbar.crc.
about.html, autosearch.dll, autose~1.dll, error.html, options.html, searchaddon.dll, search~1.dll, toolbar.dll, webinfo.dll in Program Files\internet explorer\toolbar\
about.html, autosearch.dll, autose~1.dll, error.html, install.exe, mgs_32.dll, options.html, searchaddon.dll, search~1.dll, toolbar.dll, webinfo.dll in Program Files\intern~1\toolbar\
install.exe in Windows\drivers\audio\
install.exe in Windows\drivers\video\
mgs_32.dll in Windows\system32\
Remove the following directories
Program Files\internet explorer\toolbar

Bookmark CWS.GonnaSearch page

 Previous Spyware: Remove CWS.find-help Next Spyware: Remove CWS.GoogleMS