Free Spyware Scan!
   Internet Security Suite
   Norton AntiVirus 2006
   Anti-Spyware from CA
   Secure private data!

Digital River oneNetwork 2.0 - Make Money!

2Search Removal Instructions

Description: 
Remove Spyware

Spyware Threat Level

2Search is an adware that is implemented as Interent Explorer browser helper object. 2Search monitors URLs visited by Internet Explorer and displays similar URLs to the user. This adware also hijacks your host file and redirect browser search requests to its controlling server.

CA - eTrust PestPatrol Anti-Spywar

Warning: 
  • This page provides 2Search removal information "AS IS" without a warranty of any kind. You are advised not to use this information if you are not aware of what you are doing. It must be noted that wrongly using the below given information to remove 2Search from you PC may generated unexpected results. You must take a registry back and create a System Restore Point before following the below given instructions.

Important Instructions: 
  1. Please do not delete any directory unless you are sure that it is related with 2Search. Check 'C:\Program Files\', 'C:\Temp', 'C:\Tmp', 'C:\Documents and Settings\(your profile name)\Local Settings\Temp' and/or 'C:\Documents and Settings\All Users\Local Settings\Temp' for these directories. These directories may also exists in 'C:\Windows' directory but deleting a legitimate directory from 'C:\Windows' or sub directories may result in system failure so make sure you have found what you were looking for before deleting any directory. Always use 'System Restore' before following spyware removal instructions.
  2. Files created by 2Search must be removed either by using Add / Remove Programs Utility or simply deleting them using Windows Explorer. Note that some EXE files that are running i.e. processes, will not be deleted unless you use Task Manager to kill these processes.
  3. Please take a registry backup using 'regedit.exe' or create a system restore point using 'System Restore Utility' before following these steps. Note that removing legitimate registry entries may result in a system crash.

Symantec's Norton Internet Security 2006

Remove these directories: 
  1. %programfilesdir% \ 2Search
  2. TheGuard

Remove these files: 
  1. %systemdir% \ 007guard.exe
  2. %systemdir% \ 2searchinstaller.exe
  3. date.dat
  4. %programfilesdir% \ 2Search \ main.exe
  5. getst.exe
  6. plugin.dll
  7. %programfilesdir% \ 2Search \ svchost.exe
  8. uninstall.exe
  9. %programfilesdir% \ 2Search \ defaultne.txt
  10. %programfilesdir% \ 2Search \ 2search.dll
  11. get.exe
  12. %programfilesdir% \ TheGuard \ the007guard.ocx
  13. the007installer.exe

Remove these registry keys: 
  1. IEsearch.clsIESpy
  2. HKEY_CLASSES_ROOT \ \ GoogleCatch.clsIESpy
  3. The007Guard.The007GuardCtrl.1
  4. {4508E20C-ACAD-11D2-9FC0-00550076E06F}
  5. HKEY_CLASSES_ROOT \ TypeLib \ {20048BB0-DB68-11CF-9CAF-00AA006CB425}
  6. {68E774CB-72D1-4A52-B55B-C0B1011E013B}
  7. HKEY_CLASSES_ROOT \ TypeLib \ {4508E20A-ACAD-11D2-9FC0-00550076E06F}
  8. HKEY_CLASSES_ROOT \ Interface \ {9C33138E-0581-4C28-A943-BC238A68208C}
  9. {F79A1360-2754-43F3-8297-8A39408BE2BF}
  10. HKEY_LOCAL_MACHINE \ software \ classes \ IEsearch.clsIESpy
  11. GoogleCatch.clsIESpy
  12. The007Guard.The007GuardCtrl.1
  13. HKEY_LOCAL_MACHINE \ software \ classes \ CLSID \ {4508E20C-ACAD-11D2-9FC0-00550076E06F}
  14. {20048BB0-DB68-11CF-9CAF-00AA006CB425}
  15. HKEY_LOCAL_MACHINE \ software \ classes \ TypeLib \ {68E774CB-72D1-4A52-B55B-C0B1011E013B}
  16. HKEY_LOCAL_MACHINE \ software \ classes \ TypeLib \ {4508E20A-ACAD-11D2-9FC0-00550076E06F}
  17. {9C33138E-0581-4C28-A943-BC238A68208C}
  18. HKEY_LOCAL_MACHINE \ software \ classes \ Interface \ {F79A1360-2754-43F3-8297-8A39408BE2BF}
  19. %programfilesdir% \ TheGuard
  20. %programfilesdir% \ 2Search
  21. HKEY_LOCAL_MACHINE \ SOFTWARE \ WinRARSFX \ %programfilesdir% \ TheGuard
  22. %programfilesdir% \ 2Search
  23. 2Search
  24. HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Uninstall \ theguard
  25. 2Search
  26. HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Uninstall \ theguard
  27. HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Ext \ Stats \ {4508E20C-ACAD-11D2-9FC0-00550076E06F}
  28. {4508E20C-ACAD-11D2-9FC0-00550076E06F}
  29. HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ BrowserHelperObjects \ {4508E20C-ACAD-11D2-9FC0-00550076E06F}

Remove these registry key values: 
  1. svchost
  2. svchost
  3. HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ Run \ 2Search
  4. svchost


Home  |  Spyware  |  Sitemap  |  Contact Us  |  Need Help  |  Links  |  Web  |  Tela Links  |  Site Links

Copyright © 2004-2006 PCPrivacySolutions.com - All rights reserved.

We do not endorse any of the companies, products, or services mentioned on this website. Each product or
service is the trademark of their respective company and all information is provided as opinions only.