SpywareQuake icon on system tray bottom right of screen

Discussion in 'Malware Help (A Specialist Will Reply)' started by djquillin, Apr 19, 2006.

  1. djquillin

    djquillin Private E-2

    I have an icon from SpywareQuake only in my "system tray" the part by the clock that shows active programs. I DID NOT get all the software loaded onto my computer because I never have "opened" the alert window that says my computer was infected. I did however follow your instructions for the removal of SpywareQuake. I also checked for the files you said to kill, checked the registry for the files you said to delete, checked for the dll's and all the rest of the instructions. NO files mentioned in those instructions were found on my computer. I just can't get rid of the annoying pop up that tells me I'm infected. Any other suggestions? I have a Toshiba 1905-S301, 40gig HD, 1024 Ram and pentium4 processor at 2.0ghz. Any ideas would be appreciated. Thanks
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    When did you do the procedure? It was just updated today. Also where is the requested log.
     
  3. djquillin

    djquillin Private E-2

    Did the procedure last night. Didn't see info about log, but you know I'm new to this, so direct me to the procedure for doing the log. Thanks
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  5. djquillin

    djquillin Private E-2

    I beleive the smitfiles.txt are attached. Let me know
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay it found SpywareQuake issues, so how are things working now!

    Did you locate the file the procedure asked you to delete (xenadot.dll)?
     
  7. djquillin

    djquillin Private E-2

    I tried to delete xenadot.dll in both regular and safe mode. All I get is "Cannot Delete xenadot: Access is Denied. Any thing else I can do, the icon is still present. thanks
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  9. djquillin

    djquillin Private E-2

    Sorry for the delay, attached find the runkeys.txt requested and I wait to hear from you with next suggestion. thanks
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks to me like your are not following the SpywareQuake Removal Procedure procedure properly. I still see the registry keys and the xenadot.dll file. It seems like you are not running the registry patch and attempting the delete of the file at the various points in the procedure.

    Try the procedure again and make sure your follow the steps exactly as written and make sure that registry patch successfully adds to the registry. If you are getting any error messages, you must tell me.
     
  11. djquillin

    djquillin Private E-2

    Thank you, I thought I had followed the procedure exactly as written, but I will try it once more and notify you of any problems or error messages.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well if you are following it exactly and it is not working, this will be good information for us to use to modify the procedure for this xenadot.dll form of the infection. So thanks for retrying it! ;)
     
  13. djquillin

    djquillin Private E-2

    Well, I guess that's why I'm a private E2. I reran according to your instruction and things went well. I must have missed a step the first time. In the rerun I found these things. 1. At Add/Remove programs, Spyware Quake was not found in currently installed programs. 2. Stickrep.dll and suprox.dll were not found. 3. After reboot, Stickrep.dll and suprox.dll were still not found. 4. C:\Program Files\Spyware Quake not found. 5. C:\Windows\System\1024 not found. 6. C:\Windows\system32\1024 not found. 7. C:\Documents and Settings........\Start Menu\programs\Spyware Quake not found. I also at this time noticed I DID NOT have the icon in my systray that was previously causing all the problems. I did however take it upon myself to look for the Xenadot.dll you asked me to delete last night. I found it in C:\Windows\System32 and deleted it with no problem (hope this was the thing to do). I have not attached the smitfiles.txt at this point since I seem to be OK, do you want them anyway? Thanks I will repost if this thing comes back for some reason and I can't remove it following your instructions I now have. Let me know if you would like me to do any more for you. Thanks Again
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Great! That is why xenadot.dll is listed in the procedure to delete (along with other files if found). It is the most recent version of the infection.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  15. djquillin

    djquillin Private E-2

    Just to recover one item, maybe because I missed a step last night, but last night when I found Xenadot.dll I could not delete it, access denied. Just wanted to restate that, it was probably my failure to correctly follow your instructions, Thanks again. I will now tackle Step 1 as you said to do.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The procedure actually did ask in several spots (three to be exact) to delete and if it fails it is tried again at two other points after reboots. At least that is how it used to read. Just tonight I modified it to rename the files at the first point and then later there are two points where the renamed files are deleted.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds