Trojan/CWS Combo Removal: Remove Trojan/CWS Combo Easily
What is Trojan/CWS Combo
Download WiperSoft Antispyware Malware Remediation Tool
Remove Trojan/CWS Combo manually
Get Professional Support
Read Comments
Threat's profile
Name of the threat:
Command or file name:
Threat type:
Affected OS:
Trojan/CWS Combo
winupdate.exe
Spyware
Win32 (Windows XP, Vista, Seven, 8)
The US FTC (FTC) advised on the site to remove Trojan/CWS Combo, what to do when trying to fulfill Trojan/CWS Combo removal and assert from Trojan/CWS Combo with some seemly Trojan/CWS Combo removal tool. In 2006 Trojan/CWS Combo was intended one of the most numerous malicious programs running on system making an emergent dure necessity in Trojan/CWS Combo removal tools that would make apt to remove Trojan/CWS Combo and fulfill seemly Trojan/CWS Combo removals. Publicity is also a method Trojan/CWS Combo tracks user conduct and habits. Trojan/CWS Combo that acts as website proxy or Browser Helper Object can surrogate HTML links with the ones to Trojan/CWS Combo manager WWW site. Trojan/CWS Combo removal tools inspect the information contents of the system registry, computer PC files and installed programs and remove Trojan/CWS Combo that uncovers itself. Steve Gibson initiated in the new class of growing Trojan/CWS Combo removal tools.
Trojan/CWS Combo intrusion method
Trojan/CWS Combo copies its file(s) to your hard disk. Its typical file name is winupdate.exe. Then it creates new startup key with name Trojan/CWS Combo and value winupdate.exe. You can also find it in your processes list with name winupdate.exe or Trojan/CWS Combo. Also, it can create folder with name Trojan/CWS Combo under C:\Program Files\ or C:\ProgramData.
If you have further questions about Trojan/CWS Combo, please call us on the phone below. It is toll free. Or you can use programs to remove Trojan/CWS Combo automatically below.
Download Spyhunter by Enigma Software
Download this advanced removal tool and solve problems with Trojan/CWS Combo and winupdate.exe (download of fix will start immediately):
Download WiperSoft Antispyware to remove Trojan/CWS Combo
* WiperSoft Antispyware was developed to remove threats like Trojan/CWS Combo in automatic mode. Remover has active module to protect PC from hijackers, trojans, ransomware and other viruses. Trial version of SpyHunter provides detection of computer viruses for FREE. To remove malware, you have to purchase the full version of Spyhunter.
Features of WiperSoft Antispyware
Removes all files created by viruses.
Removes all registry entries created by viruses.
You can activate System and Network Guards and forget about malware.
Can fix browser problems and protect browser settings.
Removal is guaranteed - if SpyHunter fails ask for FREE support.
24/7 Spyware Helpdesk Support included into the package.
Download Spyhunter Remediation Tool by Enigma Software
Download antimalware designed specifically to remove threats like Trojan/CWS Combo and winupdate.exe (download of fix will start immediately):
Download AntiMalware to remove Trojan/CWS Combo
Features of Spyhunter Remediation Tool
Removes all files created by Trojan/CWS Combo.
Removes all registry entries created by Trojan/CWS Combo.
Fixes browser redirection and hijack if needed.
"Toolbar Remover" tool will help you get rid of unwanted browser extensions.
Removal is guaranteed - if Spyhunter Remediation Tool fails ask for FREE support.
24/7 Helpdesk Support and 5 hours of Remote Support via GoToAssist included into the package.
Let our support team solve your problem with Trojan/CWS Combo and repair Trojan/CWS Combo right now!
Call us using the number below and describe your problem with Trojan/CWS Combo. Support team will offer you solution in several minutes and give a step-by-step instruction on how to remove Trojan/CWS Combo. Trouble-free tech support with over 10 years experience removing malware.
1-877-219-8984
Threat's description and solution are developed by
Security Stronghold security team.
Here you can also learn:
Technical details of Trojan/CWS Combo threat.
Manual Trojan/CWS Combo removal.
Download Trojan/CWS Combo Removal Tool.
How to remove Trojan/CWS Combo manually?
This problem can be solved manually by deleting all registry keys and files connected with Trojan/CWS Combo, removing it from starup list and unregistering all corresponding DLLs. Additionally missing DLL's should be restored from distribution in case they are corrupted by Trojan/CWS Combo.
To get rid of Trojan/CWS Combo, you should:
1. Kill the following processes and delete the appropriate files:
- dnscleaner.exe
- neted32.dll
- 10915.exe
- 13681.exe
- 1QmvvWFJ.exe
- 216.dll
- 2T.exe
- 2vrpbq.exe
- 4savwfms.exe
- 64 Extra Drv.exe
- 6EyPsi0rf.exe
- 6nat9u00.exe
- 6XE3SZPMIJ.DLL
- 6xo4svc841f.dll
- 8hjrgyophlthd.exe
- abexaxch.exe
- abi.exe
- AChkr.exe
- ActPanel.exe
- ACTSHEXT.EXE
- acvt.exe
- adabr.exe
- addrk.exe
- adgdcjaf.exe
- adsnds74.exe
- adverrovag.exe
- aeuw.exe
- ajctres2.exe
- ajpf.dll
- aklvzp.exe
- al-popup-jerry bailey.html
- aleuqvgg.exe
- alfcmk.exe
- all.exe
- allbeautifulgirls.exe
- Amok upload.exe
- aMQCAwBN.exe
- apieb.exe
- apilh32.exe
- apiol.exe
- apius32.exe
- apizh.exe
- appjq32.exe
- appta32.exe
- APPZP32.EXE
- ati3d1ag.exe
- atlby32.exe
- ATLTO.EXE
- atlyz32.dll
- atrace34.exe
- autoheal.exe
- avojcjkr.exe
- awd71fra.exe
- awinrar.exe
- axuhsh.exe
- azgnehkb.exe
- Bash third.exe
- bbyiuwbo.exe
- belh.exe
- bhbypc.exe
- bionggb.exe
- bird tons glue.exe
- Blue Defy.exe
- bmrvpn.exe
- Body obj.dll
- BOOTVID1.exe
- Bows The.exe
- buildsend.exe
- bvqqozgb.exe
- Byao.exe
- Byte dvd.exe
- bzoybt.exe
- camocx81.exe
- CAPESNPN.exe
- CCBBOPB.DLL
- CDM05411.exe
- cdoacm.exe
- cdrah.ini
- chiiyc.exe
- cijmjc.exe
- cjeqlc.exe
- ckbn.dll
- ckihfc.exe
- clb72706.exe
- clipg.exe
- cmcder.exe
- cmwh.exe
- Cnz2.exe
- crmt.exe
- CSRSSW.EXE
- CTFMONSS.EXE
- ctkpic.exe
- cuclnp.exe
- cvahopez.exe
- cvszje.exe
- cvuocd.exe
- cwdiali.exe
- cyygwbsp.exe
- d3aq.exe
- d3cr32.exe
- d3dl.exe
- d3ga32.exe
- d3kh.exe
- D3MJ32.EXE
- d3sd.exe
- d88gm5lfo6491thd.exe
- dacm.dll
- dajet.exe
- daven.exe
- dblswwr.exe
- dciuirt.exe
- ddar.exe
- DefaultArmyPoke.exe
- dggbub.exe
- dhculc.exe
- dhknqu.exe
- disablecaps.exe
- dje.dll
- dkv.exe
- dline.exe
- Dractx.exe
- draw cdrom.exe
- drmv2clt.exe
- dvdppp.exe
- dwcg2.exe
- dylpab.exe
- e002lado1d0c.dll
- e0eqgo3t.exe
- ebcheckw.exe
- eber.exe
- ebsglgy.exe
- EEIZA.exe
- eetjanxq.exe
- eghwjc.exe
- eivvihdl.exe
- ejkcom.exe
- elersf.exe
- EN2232V.exe
- EPEQF.EXE
- erfdiskp.exe
- erfh013p.exe
- esbecr.exe
- eserstart.exe
- essdc.exe
- evqn.exe
- ewfepc.exe
- exrlww.exe
- fbczbuqe.exe
- fgtvis.exe
- fhrkvcdk.exe
- File vga.exe
- flane.dll
- flashksk.exe
- flashshl.dll
- flwvn.exe
- fmszd.exe
- fndE91lHE.exe
- fnpefsee.exe
- ftnrdn.exe
- gbqnut.exe
- gcfkdm.exe
- ghov.exe
- githolbu.exe
- gjsxubad.exe
- gK0HNJCcd.exe
- gtkn.exe
- gtwatch.exe
- gvdcn.exe
- hardc.exe
- hdejmk.exe
- hgkhgca.dll
- hhnt.exe
- hixitgf.exe
- hmbbij.dll
- hmbmkol.exe
- holdreadme.exe
- hoobyg.exe
- hqiklg.exe
- hrofgg.exe
- hsaveao.exe
- htmdefy.exe
- huhff.exe
- hupcnwj.exe
- hw6rh.exe
- hwmico.exe
- ibglit.exe
- iconw.exe
- idgenp.exe
- Idk277g.exe
- idr_17b.exe
- idsn.exe
- iebq.exe
- iegu.exe
- iehf.exe
- ieiv.exe
- iemr.exe
- ieoq.exe
- ietlbass.dll
- ietlbass32.dll
- ightsl.exe
- iinaba.dll
- ijhrbqr.exe
- ijqnqqdn.exe
- ijsbsj.exe
- ikivnp.exe
- iloveyou.exe
- ipgnutqz.exe
- ipgr.exe
- ippk32.exe
- IPRD32.EXE
- iprpai.exe
- ipsvmsnap.dll
- isbkups.exe
- ishu.exe
- javaew.exe
- javafy.exe
- javajg.exe
- javaqq.exe
- javaxz32.exe
- javaye32.exe
- jbeqjm.exe
- JBPER.DLL
- jckp.dll
- jgmetm.exe
- jhevfxad.exe
- Jndhtaf.exe
- jqwd.exe
- jspdrv.exe
- jugspoke.exe
- jzersvq.exe
- kalvewt32.exe
- kalvogh32.exe
- kkatrpv.exe
- kkjmmc.exe
- klcvpt.exe
- kmofo.txt:qrbel
- Kn1mj0.exe
- krniqth.exe
- KrxH5g.exe
- kxatgv.exe
- kxilolgl.exe
- LAZVLFDP.EXE
- LDKoO9K.exe
- ldpr54rop.exe
- LEBC.DLL
- lem.dll
- lfmvices.exe
- lhggtc.exe
- listreal.exe
- ljfdmg.exe
- llckyjsgp.lib
- lmnkx.exe
- lpqctfrm.exe
- lrsvtmf.exe
- lsiuiojz.exe
- lz3rslvr.exe
- MDDCME.DLL
- Meruoq.exe
- mfcsh.exe
- mfcsu32.exe
- mfcuq.exe
- mfcwl32.exe
- microsoft office.lnk
- misswc.exe
- Mobr9V4O.exe
- modrcl32.exe
- mplam6.exe
- mprocessor.exe
- MpsOn.exe
- msbfqp.com
- mseb32.exe
- msmsgrxp.exe
- msqyux.com
- msrev41.dll
- msriexec16.exe
- msrore.exe
- mswu.exe
- msxv32.exe
- mtduic.exe
- mtuj.exe
- mtzj63f.exe
- mv8.exe
- mviewd.exe
- mvxitgmc.dll
- neft.exe
- netfs32.exe
- netgr.exe
- netim.exe
- netng32.exe
- netoa32.exe
- netoj32.exe
- netsnd.exe
- netwizh.exe
- NETWP32.EXE
- ngqmmjds.exe
- ngzaha.exe
- nicodeu.exe
- nkpolgb.exe
- nnkckka.dll
- nO9.exe
- noktzc.exe
- ntddetect.exe
- NTDW32.EXE
- ntjc32.dll
- ntlanui2.exe
- ntlr.exe
- ntnd32.exe
- ntnut32.exe
- ntsl32.exe
- ntsysl.exe
- nwxab.exe
- nyhuv.exe
- o4svl32.exe
- obj cast skip.exe
- ogonuil.exe
- ohgtg.exe
- oiykxv.exe
- ole2nls.exe
- ompois.exe
- onbgrcf.exe
- OOUO.EXE
- opbffcx.exe
- orphk.dll
- orsc.exe
- otmvta.exe
- ouor.exe
- owdn.exe
- owns film city.exe
- oxgxut.exe
- p0z8y.dll
- pbefh.dll
- pboptions.exe
- pc32.exe
- pcdljkb.dll
- pdf2bb2.dll
- pead.exe
- pilmx.dll
- PLJB.DLL
- pmssig.exe
- pnj.dll
- pntolm.exe
- popupdefence.dll
- preInMPP.exe
- psexesvc.exe
- ptuilc.exe
- pxrtmgri.exe
- pyglew.exe
- pzabbv.exe
- qadm.exe
- qarbpvmc.exe
- qbfwbk.exe
- qdgrx.exe
- qecfxp.exe
- qgcr6bpgz.exe
- qJd1.exe
- qlgt.exe
- qnkf.exe
- qorwefzf.exe
- qpicxqkd.exe
- qpwnhxdg.dll
- qvwp.exe
- qwagntdr.exe
- qwetcm.exe
- qzdsxo.exe
- qzkt.exe
- qzzktc.exe
- raoxkvmb.exe
- rbkfcu.exe
- rdnviax.exe
- rect exit.exe
- regs flaw.dll
- replacer.exe
- restun.exe
- riqmkmebl.exe
- rofijgv.exe
- rounstlP.exe
- roxkih.exe
- ryhlzo.exe
- scansdisk.exe
- schk32.exe
- scmzit.exe
- scr win body.exe
- sdckill.exe
- sdkbv32.dll
- sdkcf.exe
- secure.exe
- setfgi.dll
- setup ace keep.exe
- sfjpxlt.exe
- SHOMW.exe
- silentapp.exe
- sjtes40m.exe
- skip face.exe
- skttbost.exe
- slyrwnwb.exe
- snmp32w.exe
- SnuQDCP5.exe
- spbde40m.exe
- Srtv.exe
- ssrunscript.exe
- start boob.exe
- svcimsdo.exe
- swgznc.exe
- swreso.exe
- swtv.exe
- sxml3am.exe
- sxs.exe
- SxxrR5Uy.exe
- sxyt.exe
- syf9524v.exe
- sysbz.exe
- sysmtd32.exe
- sysqe32.exe
- SYSSP32.DLL
- systy32.exe
- SYSZA32.EXE
- szargjor.exe
- tah.exe
- tblwdrg.exe
- texmr.exe
- tgqdnyb.exe
- thrt.exe
- tio412n.exe
- tJfwzpS.exe
- tkkhxpcl.exe
- tpbbqc.exe
- tpmchz.exe
- tpz.exe
- trustras.exe
- tss.exe
- tthk90wl.exe
- tukfy.exe
- twsaim.exe
- tyjdvxqt.exe
- tzbmfi.exe
- u99xki.exe
- ubtt.exe
- uhjejc.exe
- Uit99525.exe
- ujytob.exe
- ulxrvb.exe
- umdetup.exe
- up base view.exe
- UpdInstall.exe
- usrsapi.exe
- utczctux
- uwqgvqc.exe
- vcjqxe.exe
- vct32163.exe
- vfswue.exe
- vgmto8q.exe
- vgxncfev.exe
- vtdqkzf.exe
- vtmg.dll
- vub.exe
- wadpxay.exe
- wcbrcc.exe
- wcfkpvdf.exe
- winb.dll
- windp32.exe
- winld.exe
- winmsdc.exe
- winpack.exe
- WINWH.EXE
- wjjnewa.exe
- wmdevice.exe
- wpeROape.exe
- wuwqow.exe
- wwjatmq.exe
- wzcsapi.exe
- xboglc.exe
- xenbse32.exe
- Xhrmy.exe
- xmuogc.exe
- xyn.exe
- xywfsc.exe
- yhilfm.exe
- ylbwqddi.exe
- ylkp.exe
- ylwjol.exe
- ypbrgbj.exe
- yqjywccd.dll
- yrkl.exe
- yrqlea.exe
- ywivgg.exe
- ywokvd.exe
- yxcd.exe
- yzuvglkd.exe
- zapkxzkg5.exe
- zbtqyc.exe
- zdjhjp.exe
- ZLWt.exe
- znzubvs.exe
- zpfujj.exe
- zqruknk.exe
- zrkiic.exe
- zsxcwiac.exe
- zunarmx.exe
- zxgenvtw.exe
Warning: you should delete only those files which checksums are listed as malicious. There may be valid files with the same names in your system. We recommend you to use WiperSoft Antispyware Malware Remediation Tool for safe problem solution.
**Trial version of SpyHunter provides detection of computer viruses for FREE. To remove malware, you have to purchase the full version of Spyhunter.
2. Delete the following malicious folders:
- %appdata%\16 Multi Thunk Four\
- %favorites%\i-lookup favorites\
- %programfiles%\{vxtuuxr\
- %programfiles%\antecurbfile\
- %programfiles%\dupeth~1\
- %programfiles%\gluedefy\
- %programfiles%\mprocessor\
- %programfiles%\saveba~1\
- %programfiles%\closef~1\
- temp%\
- %appdata%\PROGRA~1\
- %system%\hcwc\
- %windows%\repair\
- %system%\services\
- %programfiles%\allbeautifulgirls\
- Documents and Settings\All Users\Application Data\BASENOUNARMYMPEG\
- %appdata%\HEARTS~1\
- %appdata%\GLOBAL~1\
- Documents and Settings\All Users\Application Data\That sect remote frag\
- %programfiles%\WIPETI~1\
- %appdata%\THATVG~1\
- %appdata%\Flaw Eggs Amen Each\
- %programfiles%\Izbnj\
- Documents and Settings\All Users.WINDOWS\Application Data\glue chic bore build\
- %windows%\cursors\
- %profile%\locals~1\temp\
- %appdata%\AXISFI~1\
- %programfiles%\support.com\charter\bin\
- Documents and Settings\All Users\Application Data\Wave roam grid bits\
- %appdata%\meta heck default mp3\
- %programfiles%\dataca~1\
- %programfiles%\bagspr~1\
- Documents and Settings\All Users\Application Data\Proxy inter book for\
- %system%\ctrdppa\
- %programfiles%\Injyr\
- Documents and Settings\All Users\Application Data\The blue 4 01\
- %windows%\mshosts\
- %programfiles%\thiskn~1\
- %programfiles%\ultimate popup defence pro\
- Documents and Settings\All Users\Application Data\flaw sign regs keep\
- %programfiles%\idolnu~1\
- %programfiles%\realba~1\
- Documents and Settings\All Users.WINDOWS\Application Data\default copy cash city\
- %appdata%\THUNKH~1\
- %programfiles%\launch manager\
- %system%\ikjxl\
3. Delete the following malicious registry entries and\or values:
- Key: CLSID\{13f90341-ad79-4a9f-9b57-0234675670d6}
- Key: CLSID\{1e1b2879-88ff-11d2-8d96-d7acac97972f}
- Key: CLSID\{29a38549-af6f-11d4-89d6-bc1dfd912b00}
- Key: CLSID\{4e7bd74f-2b8d-469e-a58d-8f6fa787ad2d}
- Key: CLSID\{5cf8a355-f8c6-4883-9c25-49d01a7d25be}
- Key: CLSID\{75b3573b-a881-4d03-9d55-eecba889ac24}
- Key: CLSID\{920cb957-3665-45e5-92e9-a37b58af2758}
- Key: CLSID\{97847d03-bd75-43d2-bf56-74d59b54b81e}
- Key: CLSID\{A9A674BF-771F-42E5-A440-D20DDA85A862}
- Key: CLSID\{d879a0f1-2b3b-4409-8879-fad6e49e1ea9}
- Key: CLSID\{f36c1198-fc6b-4012-9928-dfa76fb56cc3}
- Key: CLSID\{fa040b34-fbe9-4bef-9d85-f90becaaca99}
- Key: CLSID\{fc4c5eae-66ee-11d4-bc67-0000e8e582d2}
- Key: typelib\{0d4ef487-bbb7-4d83-b064-88126e45d4f0}
- Key: software\bssgglgllllfrie
- Key: software\classes\clsid\{13f90341-ad79-4a9f-9b57-0234675670d6}
- Key: software\classes\clsid\{1e1b2879-88ff-11d2-8d96-d7acac97972f}
- Key: software\classes\clsid\{29a38549-af6f-11d4-89d6-bc1dfd912b00}
- Key: software\classes\clsid\{4e7bd74f-2b8d-469e-a58d-8f6fa787ad2d}
- Key: software\classes\clsid\{5cf8a355-f8c6-4883-9c25-49d01a7d25be}
- Key: software\classes\clsid\{75b3573b-a881-4d03-9d55-eecba889ac24}
- Key: software\classes\clsid\{97847d03-bd75-43d2-bf56-74d59b54b81e}
- Key: software\classes\clsid\{d879a0f1-2b3b-4409-8879-fad6e49e1ea9}
- Key: software\classes\clsid\{f36c1198-fc6b-4012-9928-dfa76fb56cc3}
- Key: software\classes\clsid\{fc4c5eae-66ee-11d4-bc67-0000e8e582d2}
- Key:
software\microsoft\code store database\distribution units\{00000ef1-0786-4633-87c6-1aa7a44296da}
- Key:
software\microsoft\code store database\distribution units\{9c691a33-7dda-4c2f-be4c-c176083f35cf}
- Key:
software\microsoft\code store database\distribution units\{bd11a280-2e73-11cf-b6cf-00aa00a74daf}
- Key:
software\microsoft\code store database\distribution units\{d61570b1-61e1-6851-cbf7-b7915cbdfa4e}
- Key: software\microsoft\windows\currentversion\explorer\browser helper objects
\{13f90341-ad79-4a9f-9b57-0234675670d6}
- Key: software\microsoft\windows\currentversion\explorer\browser helper objects
\{1e1b2879-88ff-11d2-8d96-d7acac97972f}
- Key: software\microsoft\windows\currentversion\explorer\browser helper objects
\{29a38549-af6f-11d4-89d6-bc1dfd912b00}
- Key: software\microsoft\windows\currentversion\explorer\browser helper objects
\{4e7bd74f-2b8d-469e-a58d-8f6fa787ad2d}
- Key: software\microsoft\windows\currentversion\explorer\browser helper objects
\{5a04c6ca-9f26-4a84-b5c4-e67e817d9bc7}
- Key: software\microsoft\windows\currentversion\explorer\browser helper objects
\{97847d03-bd75-43d2-bf56-74d59b54b81e}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{A9A674BF-771F-42E5-A440-D20DDA85A862}
- Key: software\microsoft\windows\currentversion\explorer\browser helper objects
\{d879a0f1-2b3b-4409-8879-fad6e49e1ea9}
- Key: software\microsoft\windows\currentversion\explorer\browser helper objects
\{f36c1198-fc6b-4012-9928-dfa76fb56cc3}
- Key: software\microsoft\windows\currentversion\explorer\browser helper objects
\{fa040b34-fbe9-4bef-9d85-f90becaaca99}
- Key: software\microsoft\windows\currentversion\explorer\browser helper objects
\{fc4c5eae-66ee-11d4-bc67-0000e8e582d2}
- Key:
software\microsoft\internet explorerinternet0%\URLSearchHooks\{1204A789-0139-F9B1-BF9E-4BECFF8288F8}
- Key:
software\microsoft\internet explorerinternet0%\URLSearchHooks\{FA239BAA-E441-30B6-0ABB-3EAAF567B877}
- Key: CLSID\{422CB822-000B-4721-8B75-693145DB8154}
- Key: CLSID\{5a04c6ca-9f26-4a84-b5c4-e67e817d9bc7}
- Key: CLSID\{9C0B8641-9AC7-11D8-9961-00E00128BE47}
- Key: CLSID\{9E592E9C-2A67-4124-9973-D463E7223803}
- Key: Interface\{422CB822-000B-4721-8B75-693145DB8154}
- Key: Interface\{9C0B8641-9AC7-11D8-9961-00E00128BE47}
- Key: Interface\{9E592E9C-2A67-4124-9973-D463E7223803}
- Key: Interface\{A9A674BF-771F-42E5-A440-D20DDA85A862}
- Key: SOFTWARE\Classes\CLSID\{1CB13C88-96B6-11d6-9AF5-D12D26EE1F36}
- Key: SOFTWARE\Classes\CLSID\{8FB4C800-6AFD-11D9-B4DD-0040C13A1371}
- Key: SOFTWARE\Classes\CLSID\{A673D519-E680-499E-AA66-255D3A7214A1}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{039A2790-6CCF-4A57-A5EB-856D6F5CDD7C}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{1A94240C-29A6-4669-844C-D6C33E5816D4}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{386FBB8D-E1E9-4D92-9A54-E07205BA73B1}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{3FF1357C-9436-0D95-D054-10557CF37B6D}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{422CB822-000B-4721-8B75-693145DB8154}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{42393D69-260C-406E-A1C6-0EE8DFE2E3E5}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{483094D2-1A36-49D3-A4ED-702E2BB26313}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{4C1B116F-2860-46db-8E6C-B4BFC4DFD683}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{5742F79A-1D91-42c4-990C-B46CF55A6478}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{6CD2385E-C763-5FC5-D970-65550D812C12}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{73662C48-BA2F-4287-93B0-ADEA0EAD3A0D}
- Key: software\microsoft\windows\currentversion\explorer\browser helper objects
\{76F30C6C-4DFA-4092-8B75-1CCA31EC02FF}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{81D1BD81-5218-5EBA-1C22-2CF008BD699B}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{9084EE11-BDFB-4E47-AC1F-FE2E09779A81}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{90AC6A48-3C20-B126-8E7D-EFEF0381C98A}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{92C9C0BC-4A1E-4541-A244-2CD63754A5BD}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{98BEE562-A984-68F6-3C3D-5BA8C901DC71}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{9C0B8641-9AC7-11D8-9961-00E00128BE47}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{9C3F905D-AD42-4A7D-A0E5-0E129A70D5BF}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{9E592E9C-2A67-4124-9973-D463E7223803}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{B22E8FC3-DFE1-03EF-A9E8-5969A72242ED}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{B8D2C8BF-153D-46E3-96E3-E9423550019E}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{D44724B2-CD91-41AA-9DED-ED7647D143A2}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{D4D6E938-A715-0A71-38BD-176F21ADA2F9}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{D8F31A52-4A98-397B-48A7-1CA3B87C457E}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{E89E65D9-6496-47DF-BB32-7E939CF39D02}
- Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
\{E98DDD14-95AB-47D0-9C3E-B7E5F5880A48}
- Key: SOFTWARE\motoin
- Key: TypeLib\{422CB822-000B-4721-8B75-693145DB8154}
- Key: TypeLib\{9C0B8641-9AC7-11D8-9961-00E00128BE47}
- Key: TypeLib\{9E592E9C-2A67-4124-9973-D463E7223803}
- Key: TypeLib\{A9A674BF-771F-42E5-A440-D20DDA85A862}
- Key: voiddummy
- Key: software\microsoft\internet explorerinternet0%\toolbar
Value: {4e7bd74f-2b8d-469e-a58d-8f6fa787ad2d}
- Key: software\microsoft\internet explorerinternet0%\toolbar
Value: {5cf8a355-f8c6-4883-9c25-49d01a7d25be}
- Key: software\microsoft\internet explorerinternet0%\toolbar
Value: {75b3573b-a881-4d03-9d55-eecba889ac24}
- Key: software\microsoft\internet explorerinternet0%\toolbar\webbrowser
Value: {339BB23F-A864-48C0-A59F-29EA915965EC}
- Key: software\microsoft\internet explorerinternet0%\toolbar\webbrowser
Value: {4BF85800-B52A-C88D-3E1A-BC6726585FA5}
- Key: software\microsoft\internet explorerinternet0%\toolbar\webbrowser
Value: {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94}
- Key: software\microsoft\internet explorerinternet0%\URLSearchHooks
Value: {C47F26FB-2717-FEB3-9E41-FD54EB783896}
- Key:
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Value: {1DAA3154-C544-0EB2-8753-60550DF3794A}
- Key:
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
Value: {C8276581-6814-11D9-B4DD-0040469CF72B}
- Key: software\microsoft\windows\currentversion\runonce
Value: aol instent messenger
- Key: software\microsoft\windows\currentversion\runonce
Value: hw6rh.exe
- Key: Software\Microsoft\Windows\CurrentVersion\RunOnce
Value: iehf32.exe
- Key: software\microsoft\windows\currentversion\runOnce
Value: javaew.exe
- Key: Software\Microsoft\Windows\CurrentVersion\RunOnce
Value: systy32.exe
- Key: software\microsoft\windows\currentversion\runonce
Value: u99xki.exe
Warning: if value is listed for some registry entries, you should only clear these values and leave keys with such values untouched. We recommend you to use WiperSoft Antispyware Malware Remediation Tool for safe problem solution.
4. Manually fix browser problems
Trojan/CWS Combo can affect your browsers which results in browser redirection or search hijack. We recommend you to use free option "Reset Browsers" under "Tools" in Spyhunter Remediation Tool to reset all the browsers at once. Mention that you need to remove all files and kill all processes belonging to Trojan/CWS Combo before doing this. To reset your browsers manually and restore your homepage perform the following steps:
Internet Explorer
If you use Windows XP, click Start, and then click Run. Type the following in the Open box without quotes, and press Enter: "inetcpl.cpl"
If you use Windows 7 or Windows Vista, click Start. Type the following in the Search box without quotes, and press Enter: "inetcpl.cpl"
Click the Advanced tab
In Reset Internet Explorer settings, click Reset. Click Reset in opened window again.
Select Delete personal settings checkbox to remove browsing history, search providers, homepage
After Internet Explorer finishes resetting, click Close in the Reset Internet Explorer Settings dialog box
Warning: In case this option will not work use free option Reset Browsers under Tools in Spyhunter Remediation Tool.
Google Chrome
Go to the installation folder of Google Chrome: C:\Users\"your username"\AppData\Local\Google\Chrome\Application\User Data.
In the User Data folder, look for a file named as Default and rename it to DefaultBackup.
Launch Google Chrome and a new clean Default file will be created.
Warning: This option might not work if in Google Chrome you use online synchronization between PCs. In this case use free option Reset Browsers under Tools in Spyhunter Remediation Tool.
Mozilla Firefox
Open Firefox
Go to Help > Troubleshooting Information in menu.
Click the Reset Firefox button.
After Firefox is done, it will show a window and create folder on the desktop. Click Finish.
Warning: This option will also clean all your account passwords for all websites. If you don't want it use free option Reset Browsers under Tools in Spyhunter Remediation Tool.
Information provided by: Aleksei Abalmasov
Here are the descriptions of problems connected with Trojan/CWS Combo and winupdate.exe we received earlier:
« Back to catalog
Problem Summary: Internet Explorer does not shut down when closed
computer was running slow. Found in the task manager that Internet Explorer was still running in back ground. Manually closed these processes for the Task Manager. Computer was running fine until the next time i visited internet explorer with the same results. From what i found that it is a trojan.cws problem
Problem was successfully solved. Ticket was closed.