ActualNames Removal Instructions Description: ActualNames software is an address bar search hijacker that targets the Internet Explorer, Netscape and AOL browsers. Actual Names also seems to contain components to interfere with the sending of mail from various applications and web sites. Bundled with KazaaMate. Suspected also to be installed by ActiveX drive-by download from some pop-ups. ActualNames is a security threat because it can download unsigned code from its controlling server and execute that code.
Warning:
This page provides ActualNames removal information "AS IS" without a warranty of any kind. You are advised not to use this information if you are not aware of what you are doing. It must be noted that wrongly using the below given information to remove ActualNames from you PC may generated unexpected results. You must take a registry back and create a System Restore Point before following the below given instructions.
Important Instructions:
Please do not delete any directory unless you are sure that it is related with ActualNames . Check 'C:\Program Files\', 'C:\Temp', 'C:\Tmp', 'C:\Documents and Settings\(your profile name) \Local Settings\Temp' and/or 'C:\Documents and Settings\All Users\Local Settings\Temp' for these directories. These directories may also exists in 'C:\Windows' directory but deleting a legitimate directory from 'C:\Windows' or sub directories may result in system failure so make sure you have found what you were looking for before deleting any directory. Always use 'System Restore' before following spyware removal instructions.
Files created by ActualNames must be removed either by using Add / Remove Programs Utility or simply deleting them using Windows Explorer. Note that some EXE files that are running i.e. processes, will not be deleted unless you use Task Manager to kill these processes.
Please take a registry backup using 'regedit.exe' or create a system restore point using 'System Restore Utility' before following these steps. Note that removing legitimate registry entries may result in a system crash.
Remove these directories:
BrowseProxy %programfilesdir% \ AdvSearch cache
Remove these files:
%systemdir% \ spredirect.dll %programfilesdir% \ AdvSearch \ spredirect.dll cliner.exe %programfilesdir% \ AdvSearch \ finddll.dll findservice.exe mailbook.exe %programfilesdir% \ AdvSearch \ mailbookproxy.dll mydll.dll %programfilesdir% \ AdvSearch \ nn7dll.dll %programfilesdir% \ AdvSearch \ nndll.dll regsvr32.exe %programfilesdir% \ AdvSearch \ update.exe updater.exe updaterproxy.dll %programfilesdir% \ AdvSearch \ unins000.exe unins000.dat pluginst.dll %windir%/DownloadedProgramFiles \ wuinst.dll pluginst.dll %windir% \ DownloadedProgramFiles \ redir.inf
Remove these registry keys:
HKEY_CLASSES_ROOT \ \ spredirect.ieobject.1 spredirect.ieobject HKEY_CLASSES_ROOT \ \ advsearch.alarit.lion.addrbook.1 advsearch.alarit.lion.addrbook AdvSearch.AlarIT.LioN.Updater HKEY_CLASSES_ROOT \ \ AdvSearch.AlarIT.LioN.Updater.1 PlugInst.Installer HKEY_CLASSES_ROOT \ \ PlugInst.Installer.1 HKEY_LOCAL_MACHINE \ Software \ Classes \ spredirect.ieobject.1 spredirect.ieobject HKEY_LOCAL_MACHINE \ Software \ Classes \ advsearch.alarit.lion.addrbook.1 HKEY_LOCAL_MACHINE \ Software \ Classes \ advsearch.alarit.lion.addrbook AdvSearch.AlarIT.LioN.Updater HKEY_LOCAL_MACHINE \ Software \ Classes \ AdvSearch.AlarIT.LioN.Updater.1 PlugInst.Installer PlugInst.Installer.1 HKEY_LOCAL_MACHINE \ Software \ OliviaCorp \ AdvSearch OliviaCorp HKEY_CLASSES_ROOT \ CLSID \ {33403499-E238-4F35-8F5A-7F53D24FF9E2} HKEY_CLASSES_ROOT \ CLSID \ {80751B22-3FB8-4ED9-B029-E6F568BB48A8} {92C7D65C-52F3-4545-8A35-213D730DB1ED} HKEY_CLASSES_ROOT \ CLSID \ {B9CD23F0-086D-4190-9C04-FBFA1EA09FF8} {DEE456F3-A075-4F60-BEA0-8748D0917701} {BF4B360B-1717-4BEA-8C5B-6936DE82E8F6} HKEY_CLASSES_ROOT \ typelib \ {92C7D65C-52F3-4545-8A35-213D730DB1ED} {300D6635-E419-47E3-9642-6D73337684CD} {4CD051DD-AA90-4C5C-BD55-EA52969BE48B} HKEY_CLASSES_ROOT \ TypeLib \ {7197649B-548D-41C0-B2C1-45E1D402594A} {B9CD23F0-086D-4190-9C04-FBFA1EA09FF8} HKEY_CLASSES_ROOT \ Interface \ {33403499-E238-4F35-8F5A-7F53D24FF9E2} HKEY_CLASSES_ROOT \ Interface \ {9D81BC42-475C-4EEC-9ACE-07886D014C9D} {7AF14230-D19F-482D-8668-53FC571B2017} HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ {33403499-E238-4F35-8F5A-7F53D24FF9E2} {80751B22-3FB8-4ED9-B029-E6F568BB48A8} {92C7D65C-52F3-4545-8A35-213D730DB1ED} HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ {B9CD23F0-086D-4190-9C04-FBFA1EA09FF8} {DEE456F3-A075-4F60-BEA0-8748D0917701} HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ {BF4B360B-1717-4BEA-8C5B-6936DE82E8F6} HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ TypeLib \ {92C7D65C-52F3-4545-8A35-213D730DB1ED} {300D6635-E419-47E3-9642-6D73337684CD} HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ TypeLib \ {4CD051DD-AA90-4C5C-BD55-EA52969BE48B} HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ TypeLib \ {7197649B-548D-41C0-B2C1-45E1D402594A} {CFC87851-657D-439B-9B00-3DAE4238FB1F} HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ Interface \ {B9CD23F0-086D-4190-9C04-FBFA1EA09FF8} {33403499-E238-4F35-8F5A-7F53D24FF9E2} {9D81BC42-475C-4EEC-9ACE-07886D014C9D} HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ Interface \ {7AF14230-D19F-482D-8668-53FC571B2017} AdvSearch_is1 HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Ext \ Stats \ {92c7d65c-52f3-4545-8a35-213d730db1ed} HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ Explorer \ BrowserHelperObjects \ {92c7d65c-52f3-4545-8a35-213d730db1ed} %windir%/dhsigned.ocx HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ ModuleUsage \ %windir%/DownloadedProgramFiles/wuinst.dll {BF4B360B-1717-4BEA-8C5B-6936DE82E8F6}
Remove these registry key values:
Copyright © 2004-2006 PCPrivacySolutions.com - All rights reserved.
We do not endorse any of the companies, products, or services mentioned on this website. Each product or service is the trademark of their respective company and all information is provided as opinions only.