Remove ActualNames. Description and removal instructions

 
Title: ActualNames

Type: Browser Hijackers
Severity scale:ActualNames severity is 30  (30 / 100)
 
ActualNames is an address bar search hijacker which targets IE, Netscape and AOL browsers. ActualNames seems to contain components to interfere with sending of e-mail from various applications and web sites. Bundled with KazaaMate. Suspected also to be installed by ActiveX drive-by download from some pop-ups. ActualNames has the ability to update itself via the Internet. It includes the uninstaller.

From the publisher: As Web users type your company's keywords in their browser's address box, they will be taken straight to your site.




ActualNames properties:
• Connects itself to the internet
• Stays resident in background

Automatic ActualNames removal:

remover for ActualNames

ActualNames manual removal:

Kill processes:
findservice.exe, mailbook.exe, cliner.exe, update.exe, updater.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BrowseProxy
HKEY_CLASSES_ROOT\AdvSearch.AlarIT.LioN.Updater
HKEY_CLASSES_ROOT\AdvSearch.AlarIT.LioN.Updater.1
HKEY_CLASSES_ROOT\CLSID\{33403499-E238-4F35-8F5A-7F53D24FF9E2}
HKEY_CLASSES_ROOT\CLSID\{80751B22-3FB8-4ED9-B029-E6F568BB48A8}
HKEY_CLASSES_ROOT\CLSID\{92C7D65C-52F3-4545-8A35-213D730DB1ED}
HKEY_CLASSES_ROOT\CLSID\{B9CD23F0-086D-4190-9C04-FBFA1EA09FF8}
HKEY_CLASSES_ROOT\CLSID\{DEE456F3-A075-4F60-BEA0-8748D0917701}
HKEY_CLASSES_ROOT\Interface\{33403499-E238-4F35-8F5A-7F53D24FF9E2}
HKEY_CLASSES_ROOT\Interface\{92C7D65C-52F3-4545-8A35-213D730DB1ED}
HKEY_CLASSES_ROOT\Interface\{B9CD23F0-086D-4190-9C04-FBFA1EA09FF8}
HKEY_CLASSES_ROOT\TypeLib\{300D6635-E419-47E3-9642-6D73337684CD}
HKEY_CLASSES_ROOT\TypeLib\{7197649B-548D-41C0-B2C1-45ED402594A}
HKEY_CLASSES_ROOT\TypeLib\{4CD051DD-AA90-4C5C-BD55-EA52969BE48B}
Delete files:
findservice.exe, mailbook.exe, cliner.exe, update.exe, updater.exe, finddll.dll, mailbookproxy.dll, mydll.dll, nndll.dll, nn7dll.dll, updaterproxy.dll, spredirect.dll, unins000.exe
Delete directories:
C:\Program Files\AdvSearch

Other programs to remove ActualNames:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 19/03/04
Information updated: 01/09/05

Additional resources related to ActualNames:

Attention: If you know or you have a website or page about ActualNames removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about ActualNames parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:


Comments from visitors:


1. by Little. 2004-03-04 18:46:00
ActualNames can silently download and execute arbitrary unsigned code from its controlling server actualnames.com, as a self-updating feature.

ActualNames/BrowseProxy is also a severe security hole as it allows any web site to execute arbitrary programs.


Related news:
Similar parasites:
Related articles: