|
Ezula removal
Spyware Ezula Information |
Name: Ezula
Category: Adware
Date: 2005-05-25
Dangerous: Yes
|
Ezula is a software that allows its users to look-up any dictionary word or phrase. It uses databases of Active Encyclopedia and Active Dictionary to retrieve results for users. However, it comes bundled with adware applications, that hijack search pages from search engines like Google or MSN. It also may display excessive pop-ups with advertisements related to what target user is searching.
>> Delete Ezula automatically - Download Spyware Doctor
Ezula Removal Instructions |
Kill the following processes
ezstub.exe, sepinst.exe, cucu.exe, funcade_icmediax_install.exe, mmod.exe, mmttil.exe, sett.exe, se.exe, sed.exe, uninst.exe, uninstall.exe, gojpuses.exe, gridtwo.exe, help anti.exe, link 01 live.exe, qiopzbor.exe, dogmfcd.exe, apev.exe, unwise.exe, wo.exe, sedk.exe, iconz.exe, preinsln.exe, antispy.exe, aqzh0g6.exe, atl76681.exe, avwav072.exe, bidispl9.exe, cdfview4.exe, cmpbk321.exe, esad8.exe, ezpopstub.exe, hotelc.exe, ifojzc.exe, jel387h.exe, splashspot games.exe, tfing.exe, vbbm8.exe, wrgkf2.exe, yzrokmen.exe, zibk.exe, woinstall.exe
|
Unregister the following DLLs and reboot
9uv.dll, chcon.dll, eabh.dll, seng.dll.
chpon.dll, eapbh.dll, sepng.dll in Program Files\web offer\
sepng.dll in Program Files\weboff~1\
amtxprxy.dll, araamon.dll, auaamon.dll, aud.dll, book.dll, cdcore.dll, cdrules.dll, cdsync.dll, coreak.dll, mmview_ouch.dll, msrev23.dll, msrev43.dll, rulesak.dll, sicon.dll, ss.dll, sysfile.dll, thin.dll, updak.dll in Windows\system32\
|
Delete these registry entries
HKEY_CLASSES_ROOT\appid\{0818d423-6247-11d1-abee-00d049c10000}
HKEY_CLASSES_ROOT\appid\{0dc5cd7c-f653-4417-aa43-d457be3a9622}
HKEY_CLASSES_ROOT\bho.incredifindbho.1\clsid
HKEY_CLASSES_ROOT\bho.incredifindbho\clsid
HKEY_CLASSES_ROOT\bho.incredifindbho\curver
HKEY_CLASSES_ROOT\clsid\{00320615-b6c2-40a6-8f99-f1c52d674fad}
HKEY_CLASSES_ROOT\clsid\{1115bae4-62c1-00f9-699a-573366dc900}\{b740471d-0554-fd37-0643-9d563903067}\8whww3zulo4aweqd
HKEY_CLASSES_ROOT\clsid\{25630b47-53c6-4e66-a945-9d7b6b2171ff}
HKEY_CLASSES_ROOT\interface\{a42dc659-33b5-409e-a433-650ac42ecca4}
HKEY_CLASSES_ROOT\interface\{a8516f49-8046-4295-8ee9-c59d5041c9e2}
HKEY_CLASSES_ROOT\interface\{a986f4db-792e-4571-8974-0bb6e024766f}
HKEY_CLASSES_ROOT\interface\{af286cea-635d-40c5-a891-b40a0f520539}
HKEY_CLASSES_ROOT\interface\{af286cea-635d-40c5-a891-b40a0f520539}\isepsearch
HKEY_CLASSES_ROOT\interface\{af286cea-635d-40c5-a891-b40a0f520539}\proxystubclsid\{00020424-0000-0000-c000-000000000046}
HKEY_CLASSES_ROOT\interface\{af286cea-635d-40c5-a891-b40a0f520539}\proxystubclsid32\{00020424-0000-0000-c000-000000000046}
HKEY_CLASSES_ROOT\interface\{af286cea-635d-40c5-a891-b40a0f520539}\typelib\{4e627a1e-bc4b-4faf-8de8-1d9a54d37da3}
HKEY_CLASSES_ROOT\interface\{bccab53d-0895-40c3-a942-a03538ce227a}
HKEY_CLASSES_ROOT\interface\{bd6f129a-08db-4cc5-a75a-f2ab79e55b6e}
HKEY_CLASSES_ROOT\interface\{c03351a3-6755-11d4-8a73-0050da2ee1be}
HKEY_CLASSES_ROOT\interface\{c0f88e9e-dceb-4655-968a-ae508a677c39}
HKEY_CLASSES_ROOT\interface\{c4fee4a6-4b8b-11d4-8a6d-0050da2ee1be}
HKEY_CLASSES_ROOT\interface\{d7eac2d8-2d52-4010-a4ad-dfdf60c1706c}
HKEY_CLASSES_ROOT\interface\{ef0372dc-f552-11d3-8528-0050dab79376}
HKEY_CLASSES_ROOT\interface\{ef0372de-f552-11d3-8528-0050dab79376}
HKEY_CLASSES_ROOT\interface\{efa52460-8822-4191-ba38-facdd2007910}
HKEY_CLASSES_ROOT\interface\{fb82ccd5-174b-4379-bc37-72d9b5adaeda}
HKEY_CLASSES_ROOT\software\classes\quicksearch.searchband
HKEY_CLASSES_ROOT\typelib\{0dc5cd7c-f653-4417-aa43-d457be3a9622}
HKEY_CLASSES_ROOT\typelib\{370f6327-41c4-4fa6-a2df-1ba57ee0fbb9}
HKEY_CLASSES_ROOT\typelib\{4e627a1e-bc4b-4faf-8de8-1d9a54d37da3}\1.0\0\win32\c:\program files\sep\sep.dll
HKEY_CLASSES_ROOT\typelib\{4e627a1e-bc4b-4faf-8de8-1d9a54d37da3}\1.0\flags\0
HKEY_CLASSES_ROOT\typelib\{4e627a1e-bc4b-4faf-8de8-1d9a54d37da3}\1.0\helpdir\c:\program files\sep\
HKEY_CLASSES_ROOT\typelib\{4e627a1e-bc4b-4faf-8de8-1d9a54d37da3}\1.0\sep 1.0 type library
HKEY_CLASSES_ROOT\typelib\{5e594162-60a9-487d-84b8-dbdd716cb862}
HKEY_CLASSES_ROOT\typelib\{8992b6ca-b8c9-4aed-bf89-0a17f6296a06}
HKEY_CLASSES_ROOT\typelib\{9cfa26c0-81da-4c9d-a501-f144a4a000fa}
HKEY_CLASSES_ROOT\typelib\{9cfa26c1-81da-4c9d-a501-f144a4a000fa}
HKEY_CLASSES_ROOT\typelib\{baf13496-8f72-47a1-9cee-09238efc75f0}
HKEY_CLASSES_ROOT\typelib\{eb5e961f-f519-303c-9744-0d4376b1b0b5}
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\ezwo
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce\web offer
HKEY_CURRENT_USER\software\web offer
HKEY_LOCAL_MACHINE\software\classes\typelib\{8a044396-5da2-11d4-b185-0050dab79376}
HKEY_LOCAL_MACHINE\software\coupondeals
HKEY_LOCAL_MACHINE\software\interads
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\explorer bars\{50b4d2b3-723f-41b3-aec4-0bd66f0f45ff}
HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\explorer bars\{a166c1b0-5cdb-447a-894a-4b9fd7149d51}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9cfa26c0-81da-4c9d-a501-f144a4a000fa}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\internet settings\user agent\post platform\{b47b2b1f-0c0f-47bd-ad5d-219f2688fb72}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\sesync
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shell extensions\approved\{8e953c77-dfad-4e26-9c21-49d6f1625c62}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\amyshorse.zip\displayname
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\amyshorse.zip\uninstallstring
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\dmo\displayname
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\dmo\uninstallstring
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\web offer
HKEY_LOCAL_MACHINE\software\updater\{8d15a72d-62e0-4733-b057-0a81b4ffeb3d}
HKEY_LOCAL_MACHINE\software\updater\{8d15a72d-62e0-4733-b057-0a81b4ffeb3d}\installdate
HKEY_LOCAL_MACHINE\software\updater\{8d15a72d-62e0-4733-b057-0a81b4ffeb3d}\trackguid
HKEY_LOCAL_MACHINE\software\updater\{8d15a72d-62e0-4733-b057-0a81b4ffeb3d}\versionnumber
HKEY_LOCAL_MACHINE\software\updater\cid
HKEY_LOCAL_MACHINE\software\updater\exename
HKEY_CLASSES_ROOT\clsid\{370f6354-41c4-4fa6-a2df-1ba57ee0fbb9}
HKEY_CLASSES_ROOT\clsid\{50b4d2b3-723f-41b3-aec4-0bd66f0f45ff}
HKEY_CLASSES_ROOT\clsid\{50b4d2b3-723f-41b3-aec4-0bd66f0f45ff}\implemented categories
HKEY_CLASSES_ROOT\clsid\{50b4d2b3-723f-41b3-aec4-0bd66f0f45ff}\implemented categories\{00021493-0000-0000-c000-000000000046}
HKEY_CLASSES_ROOT\clsid\{50b4d2b3-723f-41b3-aec4-0bd66f0f45ff}\inprocserver32\c:\windows\system32\shdocvw.dll
HKEY_CLASSES_ROOT\clsid\{50b4d2b3-723f-41b3-aec4-0bd66f0f45ff}\instance\initpropertybag\url
HKEY_CLASSES_ROOT\clsid\{50b4d2b3-723f-41b3-aec4-0bd66f0f45ff}\web offer bar
HKEY_CLASSES_ROOT\clsid\{6df5e318-6994-4a41-85bd-45ccada616f8}
HKEY_CLASSES_ROOT\clsid\{788c6f6f-c2ea-4a63-9c38-ce7d8f43bce4}
HKEY_CLASSES_ROOT\clsid\{78bcf937-45b0-40a7-9391-dcc03420db35}
HKEY_CLASSES_ROOT\clsid\{8940e505-72c6-44de-be85-1d746780efbf}
HKEY_CLASSES_ROOT\clsid\{9cfa26c0-81da-4c9d-a501-f144a4a000fa}
HKEY_CLASSES_ROOT\clsid\{a166c1b0-5cdb-447a-894a-4b9fd7149d51}
HKEY_CLASSES_ROOT\clsid\{a166c1b0-5cdb-447a-894a-4b9fd7149d51}\implemented categories
HKEY_CLASSES_ROOT\clsid\{a166c1b0-5cdb-447a-894a-4b9fd7149d51}\implemented categories\{00021494-0000-0000-c000-000000000046}
HKEY_CLASSES_ROOT\clsid\{a166c1b0-5cdb-447a-894a-4b9fd7149d51}\inprocserver32\c:\windows\system32\shdocvw.dll
HKEY_CLASSES_ROOT\clsid\{a166c1b0-5cdb-447a-894a-4b9fd7149d51}\instance\initpropertybag\url
HKEY_CLASSES_ROOT\clsid\{a166c1b0-5cdb-447a-894a-4b9fd7149d51}\web offer bar
HKEY_CLASSES_ROOT\clsid\{c256d608-29d9-bcf2-1c2a-6e01a66a8b51}
HKEY_CLASSES_ROOT\clsid\{e7a05400-4cfa-4df3-a643-e40f86e8e3d7}
HKEY_CLASSES_ROOT\clsid\{f75521b8-76f1-4a4d-84b1-9e642e9c51d0}
HKEY_CLASSES_ROOT\ezulaagent.ezulactrlhost.1\clsid
HKEY_CLASSES_ROOT\ezulaagent.ieobject.1\clsid
HKEY_CLASSES_ROOT\ezulaagent.plugprot.1\clsid
HKEY_CLASSES_ROOT\ezulaagent.toolbarband.1\clsid
HKEY_CLASSES_ROOT\ezulaagent.toolbarband\clsid
HKEY_CLASSES_ROOT\ezulabootexe.installctrl.1\clsid
HKEY_CLASSES_ROOT\ezulafsearcheng.ezulacode.1\clsid
HKEY_CLASSES_ROOT\ezulafsearcheng.ezulahash.1\clsid
HKEY_CLASSES_ROOT\ezulafsearcheng.ezulasearch.1\clsid
HKEY_CLASSES_ROOT\ezulafsearcheng.popupdisplay.1\clsid
HKEY_CLASSES_ROOT\ezulafsearcheng.resulthelper.1\clsid
HKEY_CLASSES_ROOT\ezulafsearcheng.searchhelper.1\clsid
HKEY_CLASSES_ROOT\ezulamain.ezulapopsearchpipe
HKEY_CLASSES_ROOT\ezulamain.ezulasearchpipe.1\clsid
HKEY_CLASSES_ROOT\ezulamain.trayiconm.1\clsid
HKEY_CLASSES_ROOT\f1.organizer.1\clsid
HKEY_CLASSES_ROOT\f1.organizer\clsid
HKEY_CLASSES_ROOT\f1.organizer\curver
HKEY_CLASSES_ROOT\interface\{241667a3-ec83-4885-84dd-c2daafc1c5ea}
HKEY_CLASSES_ROOT\interface\{25630b50-53c6-4e66-a945-9d7b6b2171ff}
HKEY_CLASSES_ROOT\interface\{370f6327-41c4-4fa6-a2df-1ba57ee0fbb9}
HKEY_CLASSES_ROOT\interface\{370f6353-41c4-4fa6-a2df-1ba57ee0fbb9}
HKEY_CLASSES_ROOT\interface\{3a951af0-53f8-4803-a565-0e1dee4b11f5}
HKEY_CLASSES_ROOT\interface\{3a951af0-53f8-4803-a565-0e1dee4b11f5}\iband
HKEY_CLASSES_ROOT\interface\{3a951af0-53f8-4803-a565-0e1dee4b11f5}\proxystubclsid\{00020424-0000-0000-c000-000000000046}
HKEY_CLASSES_ROOT\interface\{3a951af0-53f8-4803-a565-0e1dee4b11f5}\proxystubclsid32\{00020424-0000-0000-c000-000000000046}
HKEY_CLASSES_ROOT\interface\{3a951af0-53f8-4803-a565-0e1dee4b11f5}\typelib\{4e627a1e-bc4b-4faf-8de8-1d9a54d37da3}
HKEY_CLASSES_ROOT\interface\{6e0ed53c-9908-49ed-b055-7cb31b162577}
HKEY_CLASSES_ROOT\interface\{788c6f6e-c2ea-4a63-9c38-ce7d8f43bce4}
HKEY_CLASSES_ROOT\interface\{78bcf936-45b0-40a7-9391-dcc03420db35}
HKEY_CLASSES_ROOT\interface\{7edc96e1-5dd3-11d4-b185-0050dab79376}
HKEY_CLASSES_ROOT\interface\{830d3aed-2fa9-454f-b266-d931862bbf34}
HKEY_CLASSES_ROOT\interface\{8c53bd8e-b12d-4c8f-ad0e-c9ddc39d1273}
HKEY_CLASSES_ROOT\interface\{8ebb1743-9a2f-11d4-8a7e-0050da2ee1be}
HKEY_CLASSES_ROOT\interface\{955cbf48-4313-4b1f-872b-254b7822ccf2}
HKEY_CLASSES_ROOT\interface\{9bcdd51b-4a7b-446c-8452-d32d38004582}
HKEY_CLASSES_ROOT\interface\{9cfa26c2-81da-4c9d-a501-f144a4a000fa}
HKEY_LOCAL_MACHINE\software\updater\install_dir
HKEY_LOCAL_MACHINE\software\updater\installdate
HKEY_LOCAL_MACHINE\software\updater\puid
HKEY_LOCAL_MACHINE\software\updater\versionnumber
|
Remove the following files
9uv.dll, basis.kwd, basis.rst, basisp.dst, basisp.kwd, basisp.pu, basisp.rst, chcon.dll, cucu.exe, eabh.dll, ezula.txt, gendis.ez, install.log, mmod.exe, mmttil.exe, paramp.ez, rwdsp.rst, sedk.exe, seng.dll, spec1.bsx, tvmx.bsx, wndbannnp.src.
ezstub.exe, sepinst.exe in c:\
bsx32.ini, funcade_icmediax_install.exe, winsock2.reg in Desktop\
sett.exe in Documents and Settings\UserName\application data\
se.exe, sed.exe, uninst.exe, uninstall.exe in Program Files\sed\
gojpuses.exe, gridtwo.exe, help anti.exe, link 01 live.exe, qiopzbor.exe in Program Files\third close jugs\
dogmfcd.exe in Program Files\user hold beep\
apev.exe, chpon.dll, eapbh.dll, sepng.dll, unwise.exe, wo.exe in Program Files\web offer\
sepng.dll in Program Files\weboff~1\
bsx32.ini, cjijjom.ini, conscorr.ini, digital signature 20040814.htm, iconz.exe, preinsln.exe, woinstall.exe in Windows\
amtxprxy.dll, antispy.exe, aqzh0g6.exe, araamon.dll, atl76681.exe, auaamon.dll, aud.dll, avwav072.exe, bidispl9.exe, book.dll, cdcore.dll, cdfview4.exe, cdrules.dll, cdsync.dll, cmpbk321.exe, coreak.dll, esad8.exe, ezpopstub.exe, hotelc.exe, ifojzc.exe, jel387h.exe, mmview_ouch.dll, msrev23.dll, msrev43.dll, rulesak.dll, sicon.dll, splashspot games.exe, ss.dll, sysfile.dll, tfing.exe, thin.dll, updak.dll, vbbm8.exe, wrgkf2.exe, yzrokmen.exe, zibk.exe in Windows\system32\
|
Remove the following directories
Program Files\ezula\images
Program Files\web offer
Windows\ezstub.exe
|
Bookmark Ezula page
Previous Spyware: Remove EZSearching |
Next Spyware: Remove Ezula TopText |
|