ActualNames manual removal:
Kill processes:
findservice.exe, mailbook.exe, cliner.exe, update.exe, updater.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BrowseProxy
HKEY_CLASSES_ROOT\AdvSearch.AlarIT.LioN.Updater
HKEY_CLASSES_ROOT\AdvSearch.AlarIT.LioN.Updater.1
HKEY_CLASSES_ROOT\CLSID\{33403499-E238-4F35-8F5A-7F53D24FF9E2}
HKEY_CLASSES_ROOT\CLSID\{80751B22-3FB8-4ED9-B029-E6F568BB48A8}
HKEY_CLASSES_ROOT\CLSID\{92C7D65C-52F3-4545-8A35-213D730DB1ED}
HKEY_CLASSES_ROOT\CLSID\{B9CD23F0-086D-4190-9C04-FBFA1EA09FF8}
HKEY_CLASSES_ROOT\CLSID\{DEE456F3-A075-4F60-BEA0-8748D0917701}
HKEY_CLASSES_ROOT\Interface\{33403499-E238-4F35-8F5A-7F53D24FF9E2}
HKEY_CLASSES_ROOT\Interface\{92C7D65C-52F3-4545-8A35-213D730DB1ED}
HKEY_CLASSES_ROOT\Interface\{B9CD23F0-086D-4190-9C04-FBFA1EA09FF8}
HKEY_CLASSES_ROOT\TypeLib\{300D6635-E419-47E3-9642-6D73337684CD}
HKEY_CLASSES_ROOT\TypeLib\{7197649B-548D-41C0-B2C1-45ED402594A}
HKEY_CLASSES_ROOT\TypeLib\{4CD051DD-AA90-4C5C-BD55-EA52969BE48B}
Delete files:findservice.exe, mailbook.exe, cliner.exe, update.exe, updater.exe, finddll.dll, mailbookproxy.dll, mydll.dll, nndll.dll, nn7dll.dll, updaterproxy.dll, spredirect.dll, unins000.exe
Delete directories:C:\Program Files\AdvSearch
ActualNames/BrowseProxy is also a severe security hole as it allows any web site to execute arbitrary programs.
Post Comment: