WebPI manual removal:
Kill processes:
wssys.exe, ws.exe, ks.exe, mc.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\wssys
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Run\wssys
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\wssys
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GVBOX.GvboxCtrl.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ws.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4AA438A1-2530-11D2-9D84-00C04F7FB7C4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4AA438A4-2530-11D2-9D84-00C04F7FB7C4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6FBA474B-43AC-11CE-9A0E00AA0062BB4C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E7EDC300-766F-11CF-A64F-0020AF37425D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E7EDC301-766F-11CF-A64F-0020AF37425D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E7EDC302-766F-11CF-A64F-0020AF37425D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6FBA474BC-43AC-11CE-9A0E00AA0062BB4C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6FBA474D-43AC-11CE-9A0E00AA0062BB4C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Typelib\{6FBA474E-43AC-11CE-9A0E00AA0062BB4C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{E7EDC303-766F-11CF-A64F-0020AF37425D}
Delete files:wssys.exe, ws.exe, ks.exe, mc.exe, softkey.dll, sftmouse.dll, hooklib.dll, gvjpeg32.dll, ks.sys, diskspace.sys, gvbox.ocx, sysinfo.ocx
Delete directories:C:\Windows\wssys
C:\Winnt\wssys
Post Comment:
Attention: Use this form only if you have additional information about WebPI parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.