POSt 2
Response 2 said
Response Number 2
Name: DSE
Date: April 11, 2006 at 00:39:49 Pacific
Subject: can someone help me plz
Reply:
Also use SpywareQuake removal instructions. SpywareQuake is not only a rogue, but also a trojan that will re-install itself if not removed completely.
hey tanx for ur post ohz
This is what I did and the results can u or anyone else help me with this please id apriciate heapz and taNx in advanced
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SpywareQuake ( not found not their didn’t exist)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{E2CA7CD1-1AD9-F1C4-3D2A-DC1A33E7AF9D} (found and deleted)
HKEY_CLASSES_ROOT\Typelib\{661173EE-FA31-4769-97D4-B556B5D09BDA} (did not find doesn’t exist..)
HKEY_CURRENT_USER\Software\Classes\CLSID\{E2CA7CD1-1AD9-F1C4-3D2A-DC1A33E7AF9D} (didn’t find didn’t exist)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4DA4616D-7E6E-4FD9-A2D5-B6C535733E22}(found twice 2 different locations ) other location was :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objectsa\{4DA4616D-7E6E-4FD9-A2D5-B6C535733E22}
So I deleted both to be safe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareQuake (didn’t find)
Help: how to remove registry entries
Unregister DLLs:
stickrep.dll couldn’t find anywere
Help: how to unregister malicious DLLs
Delete files:
dfrgsrv.exe, mssearchnet.exe(found<-and deleted), nvctrl.exe(found<-and deleted), spywarequake.exe, stickrep.dll, sq.ini, hp[X].tmp, ld[X].tmp nothing else was found
Help: how to remove harmful files
Delete directories:
C:\Program Files\SpywareQuake not their didn’t exist
C:\Windows\System\1024 couldn’t find
C:\Windows\System32\1024 found and deleted
C:\Winnt\System32\1024 no such folder
C:\Documents and Settings\[Current User]\Start Menu\Programs\SpywareQuake couldn’t find a folder named SpywareQuake so didn’t exist..?
At first when I read these instructions I didn’t get it so I downloaded the spywarequake removal program from link right above these instructions it was optional and ended up being Spyware Doctor 3.8 program
I didn’t use it I tried instructions first
I looked and found mssearchnet.exe and deleted it immediately and the popup on my taskbar bottom right next to my time dissapered and then I searched for the other files only found nvctrl.exe an del that 2, After that I ran spyware doctor and found 65infections which I couldn’t clean coz I had to register so I went bak to manuall removal and I removed the reg keys I could find from list above scanned my comp the way response 1 asked and then ran spyware doctor and found 35 infections remaining I couldn’t save the log file so I typed out the list also as backup for me buh can u tell me if their anything else I can do about these id appreciate it tanx in advanced…
ISTbar Location: HKCU\Software\Microsoft\Windows\\CurrentVersion\Ext\Stats\{7C559105-9ECF-42B8-B3F7-832E75EDD959}
HKCU\Software\Microsoft\Windows\\CurrentVersion\Ext\Stats\{7C559105-9ECF-42B8-B3F7-832E75EDD959}##
HKCU\Software\Microsoft\Windows\\CurrentVersion\Ext\Stats\{7C559105-9ECF-42B8-B3F7-832E75EDD959}iexplore
HKCU\Software\Microsoft\Windows\\CurrentVersion\Ext\Stats\{7C559105-9ECF-42B8-B3F7-832E75EDD959}iexplore##
HKCU\Software\Microsoft\Windows\\CurrentVersion\Ext\Stats\{7C559105-9ECF-42B8-B3F7-832E75EDD959}iexplore##Type
HKCU\Software\Microsoft\Windows\\CurrentVersion\Ext\Stats\{7C559105-9ECF-42B8-B3F7-832E75EDD959}iexplore##Count
HKCU\Software\Microsoft\Windows\\CurrentVersion\Ext\Stats\{7C559105-9ECF-42B8-B3F7-832E75EDD959}iexplore##Time
HKCU\Software\Microsoft\Windows\\CurrentVersion\Ext\Stats\{7C559105-9ECF-42B8-B3F7-832E75EDD959}iexplore##Blocked
PSGuard Desktop Hijaker :
C:\Documents and Settings\All Users\Start Menu\Security Troubleshooting.url
C;\Documents and Settings\F\Favourites\Antivirus Test Online.url
C:\Windows\System32\ot.ico
C:\Windows\System32\ts.ico
Trojan popuper :
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run##Kernel32.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\BrowserObjectsA
‘ ‘ ‘ ‘ ObjectsA##
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run##wininet.dll
C:\Windows\System32\ncompat.tlb
HKCU\Software\Microsoft\Windows\\CurrentVersion\Ext\Stats\{4DA4616D-7E6E-4FD9-A2D5-B6C535733E22}
HKCU\Software\Microsoft\Windows\\CurrentVersion\Ext\Stats\{4DA4616D-7E6E-4FD9-A2D5-B6C535733E22}##
HKCU\Software\Microsoft\Windows\\CurrentVersion\Ext\Stats\{4DA4616D-7E6E-4FD9-A2D5-B6C535733E22}iexplore
HKCU\Software\Microsoft\Windows\\CurrentVersion\Ext\Stats\{4DA4616D-7E6E-4FD9-A2D5-B6C535733E22}iexplore##
HKCU\Software\Microsoft\Windows\\CurrentVersion\Ext\Stats\{4DA4616D-7E6E-4FD9-A2D5-B6C535733E22}iexplore##Type
HKCU\Software\Microsoft\Windows\\CurrentVersion\Ext\Stats\{4DA4616D-7E6E-4FD9-A2D5-B6C535733E22}iexplore##Count
HKCU\Software\Microsoft\Windows\\CurrentVersion\Ext\Stats\{4DA4616D-7E6E-4FD9-A2D5-B6C535733E22}iexplore##Time
TrojAn.Startpage.ADH :
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run#nvctrl.exe
Backdoor.Retro64 :
HKCU\Software\Microsoft\Windows\\CurrentVersion\Ext\Stats\{288C5F13-7E52-4ADA-A32E-F5BF9D125F99}
HKCU\Software\Microsoft\Windows\\CurrentVersion\Ext\Stats\{288C5F13-7E52-4ADA-A32E-F5BF9D125F99}##
HKCU\Software\Microsoft\Windows\\CurrentVersion\Ext\Stats\{288C5F13-7E52-4ADA-A32E-F5BF9D125F99}iexplore
HKCU\Software\Microsoft\Windows\\CurrentVersion\Ext\Stats\{288C5F13-7E52-4ADA-A32E-F5BF9D125F99}iexplore##
HKCU\Software\Microsoft\Windows\\CurrentVersion\Ext\Stats\{288C5F13-7E52-4ADA-A32E-F5BF9D125F99}iexplore##Type
HKCU\Software\Microsoft\Windows\\CurrentVersion\Ext\Stats\{288C5F13-7E52-4ADA-A32E-F5BF9D125F99}iexplore##Count
HKCU\Software\Microsoft\Windows\\CurrentVersion\Ext\Stats\{288C5F13-7E52-4ADA-A32E-F5BF9D125F99}iexplore##Time
HKCU\Software\Microsoft\Windows\\CurrentVersion\Ext\Stats\{288C5F13-7E52-4ADA-A32E-F5BF9D125F99}iexplore##Blocked
Trojan.Zlob.AP :
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run##Kernel32.dll
Common Components for windupdates
Windupdates.com
These are the problems which were detected with Spyware Doctor 3.8
Are these also reg keys? Or can they be removed and cleared any other way?
Would aprieciate help