WeatherCast Description:Software that
brings ads to your computer. Such ads may or may
not be targeted, but are "injected" and/or popup,
and are not merely displayed within the form of
an ad-sponsored application.
Also known as: Trojan.Win32.VB.fk
WeatherCast Automatic Removal:
Using Spyware Doctor
to detect and remove WeatherCast AUTOMATICALLY!
Sponsored Links:
WeatherCast Manual Removal:
Follow these steps to remove WeatherCast from
your machine. Begin by backing up your
registry and your system, and/or setting a
Restore Point, to prevent trouble if you make a
mistake.
- Kill these running processes with Task
Manager:
programfilesdir+\aws\weathercast\remove.exe
programfilesdir+\aws\weathercast\weather.exe
programfilesdir+\weathercast\uninst.exe
programfilesdir+\weathercast\weather.exe
programfilesdir+\weathe~1\weather.exe
sync.exe
trojan.win32.vb.fk.exe
weatherupdate.exe
- Remove AutoRun Reference: Go to
the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run.
If you find the value weathercast,
delete it and reboot the machine
immediately. If you find the value , delete it
and reboot the machine immediately.
- Unregister these DLLs with Regsvr32, then reboot:
programfilesdir+\aws\weathercast\lfcmp10n.dll
programfilesdir+\aws\weathercast\lfimg10n.dll
programfilesdir+\aws\weathercast\ltdis10n.dll
programfilesdir+\aws\weathercast\ltfil10n.dll
programfilesdir+\aws\weathercast\ltkrn10n.dll
systemroot+\downloaded program
files\conflict.1\sndbmark.dll
systemroot+\downloaded program
files\conflict.2\sndbmark.dll
systemroot+\downloaded program files\sndbmark.dll
systemroot+\dowssnloaded program files\sndbmark.dll
systemroot+\temp\icd1.tmp\sndbmark.dll
- Remove these registry items (if present)
with RegEdit:
HKEY_CLASSES_ROOT\clsid\{fc327b3f-377b-4cb7-8b61-27cd69816bc3}
HKEY_CLASSES_ROOT\clsid\{fc327b3f-377b-4cb7-8b61-27cd69816bc3}
HKEY_CLASSES_ROOT\clsid\{fc327b3f-377b-4cb7-8b61-27cd69816bc}
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\weathercast
HKEY_CURRENT_USER\software\whenu
HKEY_LOCAL_MACHINE\software\microsoft\code
store database\distribution
units\{fc327b3f-377b-4cb7-8b61-27cd69816bc3}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage
\c:/windows/downloaded program files/sndbmark.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls
\c:\windows\downloaded program files\sndbmark.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall
\weathercast
HKEY_USERS\.default\software\microsoft\windows\currentversion\run\weathercast
HKEY_USERS\s-1-5-21-329068152-1677128483-854245398-500\software\microsoft\windows\currentversion\run\weathercast
- Remove these files (if present) with
Windows Explorer:
profilepath+\start menu\programs\weathercast
profilepath+\start menu\programs\weathercast\weathercast.lnk
programfilesdir+\aws\weathercast\lfcmp10n.dll
programfilesdir+\aws\weathercast\lfimg10n.dll
programfilesdir+\aws\weathercast\ltdis10n.dll
programfilesdir+\aws\weathercast\ltfil10n.dll
programfilesdir+\aws\weathercast\ltkrn10n.dll
programfilesdir+\aws\weathercast\remove.exe
programfilesdir+\aws\weathercast\weather.exe
programfilesdir+\weathercast\uninst.exe
programfilesdir+\weathercast\weather.exe
programfilesdir+\weathe~1\weather.exe
systemroot+\downloaded program
files\conflict.1\sndbmark.dll
systemroot+\downloaded program
files\conflict.2\sndbmark.dll
systemroot+\downloaded program files\saveinst.inf
systemroot+\downloaded program files\sndbmark.dll
systemroot+\dowssnloaded program files\sndbmark.dll
systemroot+\temp\icd1.tmp\sndbmark.dllsync.exe
trojan.win32.vb.fk.exe
weatherupdate.exe
- Remove these directories (if present) with
Windows Explorer:
commonprograms+\start menu\programs\weathercast
profilepath+\start menu\programs\weathercast
programfilesdir+\aws\weathercast
programfilesdir+\start
menu\programs\weathercast
programfilesdir+\weathercast
systemroot+\start menu\programs\weathercast
More
Removal Instructions for Adware/Spyware Programs -
'W'
|
(If you can not see the issued comment, please enable your browser to support javascript and refresh this page.)