Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Spywarequake


  • Please log in to reply
1 reply to this topic

#1 sambofan

sambofan

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:03:11 AM

Posted 01 August 2006 - 10:21 AM

Hi

I found this forum while searching for info on spywarequake, which has taken over my computer lol.

It happened this morning after installing what i thought was a codec. I uninstalled it with add remove programmes. Then found this site, then followed the instructions for removal. I scanned with Panda online at the end like it said.

And that came up with this:


Incident Status Location

Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Deb\Cookies\deb@ad.yieldmanager[1].txt
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Deb\Cookies\deb@adopt.hbmediapro[2].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Deb\Cookies\deb@advertising[1].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Deb\Cookies\deb@atdmt[1].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Deb\Cookies\deb@atwola[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Deb\Cookies\deb@belnk[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Deb\Cookies\deb@dist.belnk[2].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Deb\Cookies\deb@drivecleaner[1].txt
Spyware:Cookie/Malwarewipe Not disinfected C:\Documents and Settings\Deb\Cookies\deb@malwarewipe[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Deb\Cookies\deb@stats.drivecleaner[2].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Deb\Cookies\deb@tribalfusion[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Deb\Cookies\deb@www.drivecleaner[1].txt
Spyware:Cookie/SpywareQuake Not disinfected C:\Documents and Settings\Deb\Cookies\deb@www.spywarequake[2].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Deb\Desktop\smitRem\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Deb\Desktop\smitRem.exe[smitRem/Process.exe]

The log from roguescanfix said:

Export SharedTaskScheduler key
------------------------------
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"bestreak"="{874443fe-aa33-4ebf-a6ac-73208787e62d}"


sharedtaskkey: 874443fe-aa33-4ebf-a6ac-73208787e62d
---------------------------------------------------
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{874443fe-aa33-4ebf-a6ac-73208787e62d}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{874443fe-aa33-4ebf-a6ac-73208787e62d}\InProcServer32]
@="C:\\WINDOWS\\system32\\viruxz.dll"
"ThreadingModel"="Apartment"

After doing all that i still have the virus alerts in the bottom right of my taskbar.

Could anyone tell me how to get rid of this?

Deb

BC AdBot (Login to Remove)

 


#2 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,780 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:10:11 PM

Posted 01 August 2006 - 12:36 PM

Welcome to Bleeping Computer

We have a self-help section for removing common malware.

Did you already use the self-help tutorial How to remove SpywareQuake and SpyQuake2.com and follow all the directions? Some of the entries in the Panda scan point to the tools in this guide.

Edited by quietman7, 01 August 2006 - 12:42 PM.

.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users