I have received a message that is stuck on my taskbar, its a red circle with
a diagonal line through it which flashes to a blue circle with a question
mark, then a small box appears at bottom of screen telling me my system has
detected virus activity which might cause critical system failure and to
install ANTIMALWARE. I cannot right click but when I left click it wants me
to install SPYWARE QUAKE, I started to install and my norton program said IT
was spyware and not to install it. I have done many virus and security scans
and came up with nothing. I also dont find anything in my programs list for
it.I just want to get rid of it I cannot do a system restore back far enough
to get rid of it.

Re: ANTIMALWARE by David

David
Sat Sep 16 13:29:25 CDT 2006

From: "camaro6079" <camaro6079@discussions.microsoft.com>

| I have received a message that is stuck on my taskbar, its a red circle with
| a diagonal line through it which flashes to a blue circle with a question
| mark, then a small box appears at bottom of screen telling me my system has
| detected virus activity which might cause critical system failure and to
| install ANTIMALWARE. I cannot right click but when I left click it wants me
| to install SPYWARE QUAKE, I started to install and my norton program said IT
| was spyware and not to install it. I have done many virus and security scans
| and came up with nothing. I also dont find anything in my programs list for
| it.I just want to get rid of it I cannot do a system restore back far enough
| to get rid of it.



Two part reply..

Perform Part 1 then perform Part 2.

If the first two parts don't work, perform the alternate section.

It is suggested that you execute each tool in Normal Mode then in Safe Mode.



Part 1
-----------

Use noahdfear's SmitFraud, SpyAxe, SpyFalcon, et. al., removal tool -- SmitRem.exe
http://noahdfear.geekstogo.com/click%20counter/click.php?id=1

http://www.bleepingcomputer.com/forums/topic43659.html


Part 2
-----------

Download SmitFraud.exe from the URL --
http://www.ik-cs.com/programs/virtools/SmitFraud.exe

Execute; SmitFraud.exe { Note: You must accept the default of C:\McAfee }
Choose; Unzip
Choose; Close

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to enable WGET.EXE to download the needed McAfee related files.

Execute; c:\mcafee\clean.bat
{ or Double-click on 'Clean Link' in c:\mcafee }

A final report in HTML format called C:\mcafee\Normal_ScanReport.HTML or
C:\mcafee\Safe_ScanReport.HTML will be generated. At the end of the scan, it will be
displayed in your browser (Opera, FireFox or Internet Explorer). However, if you are using
WinXP, Win2K or Win2003 your system will be left in a state where you will have to manually
shutdown/reboot the PC. On Win9x/ME platforms the report will not be shown in your bowser
but your PC will automatically be shutdown. It is suggested that you move the report out of
c:\mcafee before performing another scan.

It would be best to scan in both Safe Mode and in Normal Mode and save a copy of the HTML
report for each session.


ALTERNATE:

Part 1
-----------

Secured2K's SpyAxe, PSGuard, Smitfraud, Sinnaka and Alemod removal tool.

http://secured2k.home.comcast.net/tools/AntiPuper.exe

http://forums.mcafeehelp.com/viewtopic.php?t=65072


Part 2
-----------

S!ri's SmitfraudFix
http://siri.urz.free.fr/Fix/SmitfraudFix_En.php


Please Copy and Paste the contents of the HTML Log files;
C:\mcafee\Normal_ScanReport.HTML & C:\mcafee\Safe_ScanReport.HTML in your reply.

* * * Please report back your results * * *


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Re: ANTIMALWARE by Ze

Ze
Sat Sep 16 16:03:22 CDT 2006

PLEASE NOTE:
I /HIGHLY/ recommend you follow the ^above guy's^ instructions. if you
wish to remove it manually, however, (VERY DANGEROUS!) go to Safe Mode
and:

Remove Spyware Quake processes:
spywarequakeinstaller.exe
spywarequake.exe
uninst.exe
dfrgsrv.exe
mssearchnet.exe
nvctrl.exe
ishost.exe
ismon.exe
isnotify.exe
issearch.exe
spy-quake2.exe


Remove Spyware Quake registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SpywareQuake
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
E2CA7CD1-1AD9-F1C4-3D2A-DC1A33E7AF9D
661173EE-FA31-4769-97D4-B556B5D09BDA
4DA4616D-7E6E-4FD9-A2D5-B6C535733E22
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareQuake
CurrentVersion\AppPaths\SpywareQuake.exe\:"%programfiles%\SpywareQuake\SpywareQuake.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run\SpywareQuake:"%programfiles%\SpywareQuake\SpywareQuake.exe/h"
CurrentVersion\Uninstall\SpywareQuake\DisplayName:"SpywareQuake2.0"
CurrentVersion\Uninstall\SpywareQuake\UninstallString:"%programfiles%\SpywareQuake\uninst.exe"
CurrentVersion\Uninstall\SpywareQuake\DisplayIcon:"%programfiles%\SpywareQuake\SpywareQuake.exe"
CurrentVersion\Uninstall\SpywareQuake\DisplayVersion:"2.0"
CurrentVersion\Uninstall\SpywareQuake\NSIS:StartMenuDir:"SpywareQuake"
CurrentVersion\Uninstall\SpywareQuake\URLInfoAbout:"http://www.spywarequake.com"
CurrentVersion\Uninstall\SpywareQuake\Publisher:"SpywareQuake.com"
HKEY_LOCAL_MACHINE\SOFTWARE\SpywareQuake\refid:"1"
HKEY_LOCAL_MACHINE\SOFTWARE\SpywareQuake\Language:"1033"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SpyQuake2.com


Unregister Spyware Quake DLL files:
ywbicim.dll
wfkduei.dll
hvnwm.dll
imfdfcj.dll
yhbdupd.dll
stickrep.dll
sivudro.dll
xenadot.dll
dvdcap.dll
suprox.dll
msvcp71.dll
msvcr71.dll
autodisc32.dll
bpvcou.dll
dnefhw.dll
erxbx.dll
guxxa.dll
gvfsc.dll
hvcycg.dll
hzclqhc.dll
jevtxpg.dll
kkqfb.dll
lwpfwjb.dll
mzoeut.dll
ofcukiz.dll
ornzq.dll
oybgrql.dll
pmnqguh.dll
rmzdzx.dll
tnvocyn.dll
qrucmr.dll
vhywj.dll
viwpzla.dll
vpxnk.dll
xuefh.dll
yfysupa.dll
yephk.dll
yvvdj.dll
zlara.dll
fhmfes.dll
jpqet.dll
viruxz.dll
vwlummc.dll


Detect and Delete these Spyware Quake files:
spywarequakeinstaller.exe
spywarequake.exe
uninst.exe
ywbicim.dll
wfkduei.dll
hvnwm.dll
imfdfcj.dll
yhbdupd.dll
stickrep.dll
sivudro.dll
xenadot.dll
dvdcap.dll
suprox.dll
msvcp71.dll
msvcr71.dll
dfrgsrv.exe
mssearchnet.exe
nvctrl.exe
spywarequake2.0website.lnk
spywarequake2.0.lnk
uninstallspywarequake2.0.lnk
blacklist.txt
ref.dat
spywarequake.url
sq.ini
english.ini
hp[X].tmp
ld[X].tmp
autodisc32.dll
bpvcou.dll
dnefhw.dll
erxbx.dll
guxxa.dll
gvfsc.dll
hvcycg.dll
hzclqhc.dll
jevtxpg.dll
kkqfb.dll
lwpfwjb.dll
mzoeut.dll
ofcukiz.dll
ornzq.dll
oybgrql.dll
pmnqguh.dll
rmzdzx.dll
tnvocyn.dll
qrucmr.dll
vhywj.dll
viwpzla.dll
vpxnk.dll
xuefh.dll
yfysupa.dll
yephk.dll
yvvdj.dll
zlara.dll
ishost.exe
ismon.exe
isnotify.exe
issearch.exe
spy-quake2.exe
fhmfes.dll
jpqet.dll
viruxz.dll
vwlummc.dll