Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This forum contains self-help guides on removing common malware and viruses. These guides can be advanced so please use them at your own risk.
If after following the self-help guide, or you can not find an appropriate guide, then you can receive step-by-step instructions directly from one of our experts by following the instructions in this topic: Preparation Guide For Use Before Posting A Hijackthis Log
![]() ![]() |
Mar 25 2006, 12:53 PM
Post
#1
|
|
![]() Bleep Bleep! ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 28,175 Joined: 24-January 04 From: USA Member No.: 3 |
How to remove SpywareQuaked and SpywareQuake (Removal Instructions) What this program does: SpywareQuaked and SpywareQuake is a anti-spyware program that is known to issue fake warnings on your computer in order to manipulate you into buying its full commercial version. The program is generally installed by a Trojan that automatically downloads and installs the program. An image of the program is below: ![]() SpywareQuake Program If you are infected with this program you will receive warnings in your task bar stating that you are infected with spyware and to run its special anti-spyware tool. This tool turns out to be the commercial version of SpywareQuake and SpywareQuaked. These warnings are fake and are a goad to have you buy the commercial version of this software. This version is slightly different than the previous variants (SpywareStrike, SpyAxe, SpyFalcon, etc) in that the alerts do not look like Windows Security alerts but are rather a square that appears from your taskbar. An example of this alert is below: ![]() SpywareQuake Fake alert Tools Needed for this fix:
Symptoms in a HijackThis Log: O4 - HKLM\..\Run: [SpywareQuake] C:\Program Files\SpywareQuake\SpywareQuake.exe /h O4 - HKLM\..\Run: [SpyQuake2.com] C:\Program Files\SpyQuake2.com\Spy-Quake2.exe /h O4 - HKLM\..\Run: [SpywareQuaked] C:\Program Files\SpywareQuaked\SpywareQuaked.exe /h Add/Remove Programs control panel entry: SpywareQuake SpywareQuake 2.0 SpywareQuake 2.1 SpyQuake2.com 2.3 SpywareQuaked 2.4 Guide Updates: 07/03/06 - Revised guide to include information on the new version SpyQuake2.com 2.3. Updated image, symptoms, and Add/Remove Programs entry of Spyware Quake to reflect new version as well 11/18/07 - Guide updated to include the new (?) variant SpywareQuaked Choose the removal method you would like to use:
Automated Removal Instructions for SpywareQuaked and SpywareQuake:
If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below: Preparation Guide For Use Before Posting A Hijackthis Log Manual Removal Instructions for SpywareQuaked and SpywareQuake: These steps may appear to be long and daunting. They are, though, quite easy to do and consist of so many steps only because I have written them in an extremely detailed manner.
Your computer should now be free of the SpywareQuaked and SpywareQuake infection. If you are still having problems with your computer after completing these instructions, then please follow the steps outlined in the topic linked below: Preparation Guide For Use Before Posting A Hijackthis Log This is a self-help guide. Use at your own risk. BleepingComputer.com can not be held responsible for problems that may occur by using this information. If you would like help with any of these fixes, you can post a HijackThis log in our HijackThis Logs and Analysis forum. If you have any questions about this self-help guide then please post those questions in our AntiVirus, Firewall and Privacy Products and Protection Methods forum and someone will help you. -------------------- Lawrence
|
|
|
|
Mar 25 2006, 12:55 PM
Post
#2
|
|
![]() Bleep Bleep! ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 28,175 Joined: 24-January 04 From: USA Member No.: 3 |
Current infection dll is c:\windows\system32\stickrep.dll.
Thanks Miekiemoes and Flrman1 for the malware info/regfile. -------------------- Lawrence
|
|
|
|
Mar 27 2006, 04:32 PM
Post
#3
|
|
![]() Bleep Bleep! ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 28,175 Joined: 24-January 04 From: USA Member No.: 3 |
Update...added instructions for using an automated removal tool, roguescanfix, by Beamerke.
-------------------- Lawrence
|
|
|
|
Apr 15 2006, 05:07 PM
Post
#4
|
|
![]() Bleep Bleep! ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 28,175 Joined: 24-January 04 From: USA Member No.: 3 |
Fix updated to include removal of the new file that issues the fake alerts. This file is :
C:\WINDOWS\system32\suprox.dll -------------------- Lawrence
|
|
|
|
Apr 18 2006, 02:33 PM
Post
#5
|
|
![]() Bleep Bleep! ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 28,175 Joined: 24-January 04 From: USA Member No.: 3 |
Once again, a new variant has been discovered thanks to Mark (Flrman1).
The new infection file is: C:\Windows\System32\xenadot.dll Removal instructions have been updated. -------------------- Lawrence
|
|
|
|
Apr 23 2006, 09:11 PM
Post
#6
|
|
![]() Bleep Bleep! ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 28,175 Joined: 24-January 04 From: USA Member No.: 3 |
Guide updated to remove the new variant.
This new file is : C:\WINDOWS\system32\sivudro.dll -------------------- Lawrence
|
|
|
|
May 3 2006, 04:41 PM
Post
#7
|
|
![]() Bleep Bleep! ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 28,175 Joined: 24-January 04 From: USA Member No.: 3 |
Guide updated to remove the new variant.
This new file is : C:\WINDOWS\system32\dvdcap.dll -------------------- Lawrence
|
|
|
|
May 10 2006, 12:01 PM
Post
#8
|
|
![]() Bleep Bleep! ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 28,175 Joined: 24-January 04 From: USA Member No.: 3 |
Guide updated to reflect new instructions for RogueScanFix.
-------------------- Lawrence
|
|
|
|
May 12 2006, 12:38 PM
Post
#9
|
|
![]() Bleep Bleep! ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 28,175 Joined: 24-January 04 From: USA Member No.: 3 |
Updated guide to reflect the latest SpywareQuake infector:
C:\WINDOWS\System32\autodisc32.dll -------------------- Lawrence
|
|
|
|
May 19 2006, 11:21 PM
Post
#10
|
|
![]() Bleep Bleep! ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 28,175 Joined: 24-January 04 From: USA Member No.: 3 |
Updated the instructions to include instructions on what to do if the removal tool does not remove SpywareQuake automatically.
-------------------- Lawrence
|
|
|
|
May 26 2006, 10:49 AM
Post
#11
|
|
![]() Bleep Bleep! ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 28,175 Joined: 24-January 04 From: USA Member No.: 3 |
Updated for the latest variant:
C:\\WINDOWS\\system32\\wfkduei.dll -------------------- Lawrence
|
|
|
|
May 30 2006, 09:53 AM
Post
#12
|
|
![]() Bleep Bleep! ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 28,175 Joined: 24-January 04 From: USA Member No.: 3 |
Guide updated for new variants:
C:\Windows\System32\yhbdupd.dll C:\Windows\System32\imfdfcj.dll C:\Windows\System32\hvnwm.dll -------------------- Lawrence
|
|
|
|
May 31 2006, 09:33 PM
Post
#13
|
|
![]() Bleep Bleep! ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 28,175 Joined: 24-January 04 From: USA Member No.: 3 |
Updated for new variant:
C:\Windows\System32\ywbicim.dll -------------------- Lawrence
|
|
|
|
Jun 2 2006, 03:37 PM
Post
#14
|
|
![]() Bleep Bleep! ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 28,175 Joined: 24-January 04 From: USA Member No.: 3 |
Updated for the two new variants:
C:\Windows\System32\vhywj.dll C:\Windows\System32\yfysupa.dll -------------------- Lawrence
|
|
|
|
Jun 7 2006, 02:31 PM
Post
#15
|
|
![]() Bleep Bleep! ![]() ![]() ![]() ![]() ![]() ![]() Group: Admin Posts: 28,175 Joined: 24-January 04 From: USA Member No.: 3 |
Various updates in the past few days.
-------------------- Lawrence
|
|
|
|