Fastsearchweb manual removal:
Kill processes:
subsys.exe
Delete registry values:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Default_Page_URL=[blank page]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Default_Search_Page=[blank page]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page=[blank page]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar=[long string]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page=[long string]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Use Custom Search URL=0x1
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Use Search Asst=no
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\Customize_Search=[blank page]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\Default_Search_URL=[blank page]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\SearchAssistant=[long string]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page=[blank page]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Search Bar=[long string]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Search Page=[long string]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Use Custom Search URL=0x1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Use Search Asst=no
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search\SearchAssistant=[long string]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{06ABAA2D-34AB-4902-A326-409BD9B9A7A5}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19E25DD9-89F9-49FD-A5FC-1B7862BB8167}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{69063189-5F20-4361-BB5F-30EF8526284D}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D825EF86-59BB-46EA-924F-12088D928D6C}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\Apartment={06ABAA2D-34AB-4902-A326-409BD9B9A7A5}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\Apartment={0EC7A55C-77D4-40E9-A4A0-9463B12B31E5}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\Freshbar={06ABAA2D-34AB-4902-A326-409BD9B9A7A5}
Unregister DLLs:rcpie.dll
Delete files:susbsys.exe, iecust.dll, protect32.dll, rcpie.dll
Misc:[blank page] is the about:blank address.
[long string] is an obfuscated address of the %System%\rcpie.dll/sp.html file.
All Fastsearchweb files can be found in the default system directory, which is one of the following: C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32.
Post Comment: