spyware removal instructions

PeopleOnPage removal

Spyware PeopleOnPage Information
Name: PeopleOnPage
Category: Hijacker
Date: 2005-04-22
Dangerous: Yes
PeopleOnPage is one of Hijacker spywares.
Finding it on your computer means that your computer is infected with Hijacker and crucial data could be endangered or even lost.
PeopleOnPage description by publisher:
POP! is a US-incorporated business with its headquarters in Seattle, Washington. The company is the 1st to develop the technology necessary to make one-on-one chatting possible on any web-site on the world wide web - not just on specialist chat sites or on sites with added chat features. So for the 1st time ever, instead of having to visit a particular community or dating web-site to chat, you can TAKE chat to any web-site. To get started, you simply download a basic item of software to let you see the proany file of other POP! users on the same site as you - whichever site that happens to be. Then, if you wanna contact them, you simply click to email or chat with them, right there & then.
This Hijacker is also known as:
Adware/Envolo - named by Panda.
eopleOnage Bar - named by a.
POP.

>> Delete PeopleOnPage automatically - Download Spyware Doctor

PeopleOnPage Removal Instructions
Kill the following processes
cpr.exe, cxtpls.exe, popsrv184.exe, auf0.exe, autoupdate.exe, auto_update_install.exe, popsrv140.exe, popsrv146.exe, popsrv205.exe, sysmonc.exe, sysmong.exe, sysmonn.exe, sysmono.exe, aprload.exe, load.exe, auto_update_uninstall.exe, bi5.exe, auto_update_uninstall.exe
Unregister the following DLLs and reboot
ace.dll, atl.dll, cxtpls.dll, pop184.dll, pop205.dll, pophook3.dll, proxystub.dll, wingenerics.dll.
libexpat.dll in Program Files\aproposclient\
pop161.dll, pop167.dll, pophook.dll in Program Files\pop\
libexpat.dll in Program Files\stomps~1\spywar~1\tempfiles\
Delete these registry entries
HKEY_CLASSES_ROOT\apropos.client
HKEY_CLASSES_ROOT\apropos.client.1.1
HKEY_CLASSES_ROOT\clsid\{a1558b18-f76c-40fe-b358-9e47449f3cfe}
HKEY_CLASSES_ROOT\clsid\{a2872b10-39f2-42df-9335-7dd38cf75255}
HKEY_CLASSES_ROOT\clsid\{a4a58a2c-b039-432b-8bc1-dca7ac0757dc}
HKEY_CLASSES_ROOT\clsid\{b3be5046-8197-48fb-b89f-7c767316d03c}
HKEY_CLASSES_ROOT\clsid\{d5580d6f-0e5f-4bdb-9cdf-f8ee68beb008}\implemented categories
HKEY_CLASSES_ROOT\interface\{a1558b18-f76c-40fe-b358-9e47449f3cfe}
HKEY_CLASSES_ROOT\interface\{a2872b10-39f2-42df-9335-7dd38cf75255}
HKEY_CLASSES_ROOT\interface\{a7d0472e-c1fc-4d8f-aba1-98a7692561bf}
HKEY_CLASSES_ROOT\popad.server
HKEY_CURRENT_USER\software\microsoft\internet explorer\explorer bars\{8023a3e7-ab95-4c23-8313-0be9842cc70e}
HKEY_CURRENT_USER\software\microsoft\internet explorer\toolbar\webbrowser\{645fd3bc-c314-4f7a-9d2e-64d62a0fdd78}
HKEY_LOCAL_MACHINE\software\autoloader
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{d5580d6f-0e5f-4bdb-9cdf-f8ee68beb008}\contains\files\c:\winnt\downloaded program files\aprload.bin
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{d5580d6f-0e5f-4bdb-9cdf-f8ee68beb008}\contains\files\c:\winnt\downloaded program files\load.exe
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{d5580d6f-0e5f-4bdb-9cdf-f8ee68beb008}\contains\files\c:\winnt\downloaded program files\monpop.exe
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{d5580d6f-0e5f-4bdb-9cdf-f8ee68beb008}\contains\files\c:\winnt\downloaded program files\pop225.dll
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{d5580d6f-0e5f-4bdb-9cdf-f8ee68beb008}\contains\files\c:\winnt\downloaded program files\pophook4.dll
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{d5580d6f-0e5f-4bdb-9cdf-f8ee68beb008}\contains\files\c:\winnt\downloaded program files\popsrv225.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/monpop.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/downloaded program files/aprload.bin\{d5580d6f-0e5f-4bdb-9cdf-f8ee68beb008}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/downloaded program files/load.exe\{d5580d6f-0e5f-4bdb-9cdf-f8ee68beb008}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\pop
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls\c:\windows\downloaded program files\monpop.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\amserver
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\autoupdate
HKEY_LOCAL_MACHINE\software\pop\files\c:\windows\downloaded program files\aprload.bin
HKEY_LOCAL_MACHINE\software\pop\files\c:\windows\downloaded program files\aprload.exe
HKEY_LOCAL_MACHINE\software\pop\files\c:\windows\downloaded program files\load.exe
HKEY_LOCAL_MACHINE\software\pop\files\c:\windows\downloaded program files\pop.inf
HKEY_LOCAL_MACHINE\software\pop\files\c:\windows\downloaded program files\pop225.dll
HKEY_LOCAL_MACHINE\software\pop\files\c:\windows\downloaded program files\pophook4.dll
HKEY_LOCAL_MACHINE\software\pop\files\c:\windows\downloaded program files\popsrv225.exe
HKEY_USERS\.default\software\microsoft\internet explorer\explorer bars\{8023a3e7-ab95-4c23-8313-0be9842cc70e}
HKEY_USERS\.default\software\microsoft\internet explorer\toolbar\webbrowser\{645fd3bc-c314-4f7a-9d2e-64d62a0fdd78}
HKEY_USERS\.default\software\pop
Remove the following files
ace.dll, atl.dll, cpr.exe, cxtpls.dll, cxtpls.exe, pop.inf, pop184.dll, pop205.dll, pophook3.dll, popsrv184.exe, proxystub.dll, sysmonn.exe, sysmono.exe, wingenerics.dll.
auf0.exe in Documents and Settings\UserName\local settings\temp\
autoupdate.exe, setup.inf in Documents and Settings\UserName\local settings\temp\autoupdate0\
auto_update_install.exe in Documents and Settings\UserName\locals~1\temp\autoupdate0\
libexpat.dll in Program Files\aproposclient\
pop161.dll, pop167.dll, pophook.dll, popsrv140.exe, popsrv146.exe, popsrv205.exe, sysmonc.exe, sysmong.exe in Program Files\pop\
libexpat.dll in Program Files\stomps~1\spywar~1\tempfiles\
activeinstall2.inf, aprload.exe, load.exe in Windows\downloaded program files\
auto_update_uninstall.exe, auto_update_uninstall.log, bi5.exe in Windows\system32\
auto_update_uninstall.exe in Windows\windows\system32\
Remove the following directories
Program Files\autoupdate

Bookmark PeopleOnPage page

 Previous Spyware: Remove Pentium_Bug Next Spyware: Remove PeopleOnPage.Apropos