WebPI manual removal:
Kill processes:
wssys.exe, ws.exe, ks.exe, mc.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\wssys
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Run\wssys
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\wssys
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GVBOX.GvboxCtrl.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ws.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4AA438A1-2530-11D2-9D84-00C04F7FB7C4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4AA438A4-2530-11D2-9D84-00C04F7FB7C4}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6FBA474B-43AC-11CE-9A0E00AA0062BB4C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E7EDC300-766F-11CF-A64F-0020AF37425D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E7EDC301-766F-11CF-A64F-0020AF37425D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E7EDC302-766F-11CF-A64F-0020AF37425D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6FBA474BC-43AC-11CE-9A0E00AA0062BB4C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6FBA474D-43AC-11CE-9A0E00AA0062BB4C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Typelib\{6FBA474E-43AC-11CE-9A0E00AA0062BB4C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{E7EDC303-766F-11CF-A64F-0020AF37425D}
Delete files:wssys.exe, ws.exe, ks.exe, mc.exe, softkey.dll, sftmouse.dll, hooklib.dll, gvjpeg32.dll, ks.sys, diskspace.sys, gvbox.ocx, sysinfo.ocx
Delete directories:C:\Windows\wssys
C:\Winnt\wssys
Post Comment: