spyware removal instructions

CWS.Svcinit removal

Spyware Svcinit Information
Name: CWS.Svcinit
Category: Homepage Hijacker
Date: 2004-01-09
Dangerous: Yes
CWS.Svcinit belongs to Homepage Hijacker spyware category.
Changes homepage to xwebsearch.biz & ´http:////´ Xwebsearch.biz is reachable, but the site is down. It is hosted by Linkey Ltd, Russian Federation. It's presense means that your computer is infected with malicious software and is insecure.
This Homepage Hijacker is also known as:
Backdoor.Sinit.c - named by Kaspersky.
Backdoor.Sinit.f - named by Kaspersky.
Backdoor/Sinit - named by Computer Associates.
Backdoor/SVC.58880 - named by Computer Associates.
Bck/Initsvc.B - named by Panda.
Bck/Initsvc.C - named by Panda.
Bck/Initsvc.D - named by Panda.
Bck/Initsvc.E - named by Panda.
Win32.Sinit.A - named by Computer Associates.
Win32.Sinit.B - named by Computer Associates.
Win32.Sinit.C - named by Computer Associates.
Win32.Sinit.E - named by Computer Associates.
Win32/Fakesvc.C trojan - named by Eset.
Win32/FakeSvc.C!Trojan - named by Computer Associates.
Win32/Sinit.A trojan - named by Eset.
Win32/Sinit.C!Trojan - named by Computer Associates.

>> Delete CWS.Svcinit automatically - Download Spyware Doctor

CWS.Svcinit Removal Instructions
Kill the following processes
sinit-20030929_unpacked.exe, sinit-20031008.exe, sinit-20031008_unpacked.exe, sinit-20031010.exe, sinit-20031010_unpacked.exe, sinit-20031022_unpacked.exe, mssys.exe, svcinit.exe, svcpack.exe, svcinit.exe, svcpack.exe
Delete these registry entries
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\mssys
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices\svc service
Remove the following files
sinit-20030929_unpacked.exe, sinit-20031008.exe, sinit-20031008_unpacked.exe, sinit-20031010.exe, sinit-20031010_unpacked.exe, sinit-20031022_unpacked.exe.
mssys.exe in Windows\
svcinit.exe, svcpack.exe in Windows\system32\
svcinit.exe, svcpack.exe in Windows\system\

Bookmark CWS.Svcinit page

 Previous Spyware: Remove CWS.Svchost32  Next Spyware: Remove CWS.Sys