Spyware Quake+antim alware in system tray

Discussion in 'Malware Help (A Specialist Will Reply)' started by Zilulil, Mar 25, 2006.

  1. Zilulil

    Zilulil Private E-2

    When i logged on today there was a new icon in my system tray... It turned out to be antim alware (which i'm moderatly sure is bad). It keeps on popping up saying it's found virus's and sneaks a install of Spyware Quake past my Firewall when i'm booting up.
    I've followed all the directions and it's still not gone. Oh and for some reason the two internet scanners in the sticky won't activate for me. I've included a HiJack This log as an attachment.
     

    Attached Files:

  2. Zilulil

    Zilulil Private E-2

    Sorry to do double posts...but i just figured out how to get the online virus scan's working...so here is the bitdefender one...i hope i saved it correctly.

    Oh and some more info on the popup. It sits in my system tray and everyonce in a while pops up about how my system is critically infected with all sorts of things I know it doesn't have. And it installes SpywareQuake and trys to run it also.

    Oh and Avast isn't letting me run Panda and I dunno if I really want to deactivate it right now soo no panda.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run the below scanner inplace of Panda and attach the Ewido log

    Running Ewido Anti-Malware

    Afterwards also attach a new HJT log too since your first one appears to be from before the READ ME was run. Make sure you have first completed ALL steps in the READ ME (accept Panda).
     
  4. Zilulil

    Zilulil Private E-2

    Ok i ran the scanner and attached the log and the new HJT log. Also the popup thing still comes up in safe mode if that means anything and it seems to be slowing down my download speeds by a lot.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O20 - Winlogon Notify: winxcx32 - winxcx32.dll (file missing)
    After clicking Fix, exit HJT.
    Now reboot your PC once so we can be sure it is gone. And now from normal boot mode, post a new HJT log.

    Make sure you tell me how things are working now.
     
  6. Zilulil

    Zilulil Private E-2

    Nope it's still there...And because i didn't unplug my internet before rebooting it snuck Spyware Quake 2.0 back in before my firewall came back up. The HJT log is from before i uninstalled the Spyware Quake 2.0 again.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does Spyware Quake appear in Add/Remove programs?
    If so, can you uninstall it?

    What does
    mean?
     
  8. Zilulil

    Zilulil Private E-2

    yep i can uninstall it. But it comes back everytime i boot because of the thing in my system tray. And it's still there means the little popup sitting in my system tray trying to get me to buy Spyware Quake 2.0 and eating my bandwidth is still there
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay from now on do not uninstall it on your own! Only follow my steps.

    Run the steps in the below link and attach the requested log to your next message:

    Using GetRunKey

    Also do the below!
    • Now download smitRem.exe written by noahdfear and save the file to your Desktop.
    • Double click on the smitRem.exe file to extract it to it's own folder on the desktop. (this should be the default selection). Do not run the program yet! You just need to click the Start button which will extract the files to the SmitRem folder on your Desktop.
    • Now you will need to print or save these instructions locally (to a text file on your Desktop) for later reference. This is necessary because you must not have any browers open and must not connect to the internet while following the below steps.
    • Now disconnect your cable to the internet (physically unplug it).
    • After saving the instructions, reboot into Safe mode
    • Now once in safe mode, goto Add/Remove programs and uninstall Spyware Quake.
    • Run Windows Explorer by right clicking Start & Select Explore
    • Navigate to C:\Windows\system32
    • Look for the following two files dxmpp.dll and/or ginuerep.dll in the system32 folder and right click on them and select delete. If they will not delete now. We will retry later. However these may not even be found since you have a different form of this malware.
    • Now open the smitRem folder on your Deskop, double click on it to access the folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen. Wait for the tool to complete and disk cleanup to finish.
    • The tool will create a log named smitfiles.txt in the root of the drive that you ran the batch file on, eg; Local Disk C: or partition where your operating system is installed. Upload this file later after reboot.
    • Now reboot your system into normal mode.
    • If you had any problems deleting the dxmpp.dll and/or ginuerep.dll files, try it again now.
    • Also delete this folder if found: C:\Program Files\Spyware Quake
    • Reconnect your cable to the internet.
    • Now attached your smitfiles.txt log to a message and provide information about the steps above and what your current status is with Spyware Quake .
    • Also attach a current HijackThis log.
     
  10. Zilulil

    Zilulil Private E-2

    Oh wow talk about odd...I restarted my computer to get the spyware thing to come back because i had uninstalled it again before you posted and i didn't know if that would matter. Also i wanted you to know that it didn't show up in add/remove but it did have it's own folder in start menu with an uninstall option. I needed to know if that mattered.
    But...when i rebooted the popup thing was gone...how odd...oh and here is the runkeys thing too.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below item bothers me. Does it mean anything to you:

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
    "{E2CA7CD1-1AD9-F1C4-3D2A-DC1A33E7AF9D}"="USB Ware"

    The Smitfraud family of malware (which includes Spyware Quake) does use the sharedtaskscheduler registry key to store their garbage. But valid stuff goes in this key too.

    Does it have anything to do with http://www.usb-ware.com/ or http://www.datastoragedrive.com/dvdburner/usbdvdburner/
     
  12. Zilulil

    Zilulil Private E-2

    No i have no idea what that is. My only guess that doesn't involve spyware is that they have something to do with my usb hub but i don't see why they would be there
     
  13. Zilulil

    Zilulil Private E-2

    sorry for having to post twice...hit post before i decided to add this. Should i go into safe mode and follow the instructions for the smitrem.exe or no. Oh and no i don't have anything that uses my usb ports exept a mouse
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes run Smitrem exactly as indicated with no connection to the internet and in safe mode.

    I'm leaning towards that registry key being malware but I'm not positive yet. So let's see what the above finds. It will show this registry key because it shows all entries in that key whether good or bad. But I want to see if it finds anything else.
     
  15. Zilulil

    Zilulil Private E-2

    Well the popup came back when i booted into safe mode. And it's still here after following all the steps..
    Here is the smitfiles log, a new runkeys log, and the HJT log
     

    Attached Files:

  16. Zilulil

    Zilulil Private E-2

    oh and the two files the instructions said to delete wern't there
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay new procedure to follow.

    First, make sure you have followed the steps in this link: How to view hidden, system files & folders!

    Now copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixquake.reg and then click save. it to your Desktop. We will use it later after a reboot into safe mode.


    • Now download smitRem.exe written by noahdfear and save the file to your Desktop.
    • Double click on the smitRem.exe file to extract it to it's own folder on the desktop. (this should be the default selection). Do not run the program yet! You just need to click the Start button which will extract the files to the SmitRem folder on your Desktop.
    • Now you will need to print or save these instructions locally (to a text file on your Desktop) for later reference. This is necessary because you must not have any browers open and must not connect to the internet while following the below steps.
    • Now disconnect your cable to the internet (physically unplug it).
    • After saving the instructions, reboot into Safe mode
    • Now once in safe mode, goto Add/Remove programs and uninstall Spyware Quake.
    • Now double-click on the fixquake.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    • Run Windows Explorer by right clicking Start & Select Explore
    • Navigate to C:\Windows\system32
    • Look for the following two files C:\WINDOWS\system32\stickrep.dll in the system32 folder and right click on it and select rename. Change the name to stickrep.DDD
    • Now open the smitRem folder on your Deskop, double click on it to access the folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen. Wait for the tool to complete and disk cleanup to finish.
    • The tool will create a log named smitfiles.txt in the root of the drive that you ran the batch file on, eg; Local Disk C: or partition where your operating system is installed. Upload this file later after reboot.
    • Now reboot your system into normal mode.
    • Also delete this folder if found: C:\Program Files\Spyware Quake
    • Reconnect your cable to the internet.
    • Now attached your smitfiles.txt log to a message and provide information about the steps above and what your current status is with Spyware Quake .
    • Also attach a current HijackThis log.
     
  18. Zilulil

    Zilulil Private E-2

    It looks like that may have done it. The file you said to rename was there and i renamed it. The thing in my system tray is not longer there.. But granted it's not shown up once before.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well it looks like my suspicion was correct about the USB Ware line.

    Your logs are clean now. I would now suggest you delete the file that we renamed. However I would appreciate it if you could put the file into a ZIP and upload it here as an attachment first. Then you can delete it.

    Note: I now added detection of this to my GetRunKey.bat script. New version has been uploaded to the link you downloaded the tool from earlier.
     
    Last edited: Mar 25, 2006
  20. Zilulil

    Zilulil Private E-2

    Here it is
     

    Attached Files:

  21. Zilulil

    Zilulil Private E-2

    Oh and glad i could help update you software lol :p
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks! I just added a new sticky cleaning procedure for it too.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds