|
How to Remove SpywareQuake |
SpywareQuake looks like a legitimate application for removal of
spyware, but it's installed by a trojan in an attempt to trick you into
buying it. SpywareQuake will also pop-up fake alerts that resemble
system alerts in another attempt to get you to buy it. Do not buy
SpywareQuake. Remove it.
Removal Instructions:
- Print out these instructions as we will need to close every window that is open later in the fix.
- Download FixSQ.reg to your desktop by right clicking on the following link and then selecting Save Link As or Save File as, depending on your browser.
- Confirm that the file FixSQ.reg now resides on your desktop as we will need it later.
- Download smitRem.exe ©noahdfear, and save the file to your desktop.
- Double click on the file to extract it to it's own folder on the desktop.
- If you look on your desktop you will now see a folder called smitRem.
- Go to your desktop and double click on the FixSQ.reg file that you downloaded earlier. When it asks if you would like to merge the information, press the Yes button and then the OK button.
- Next, please reboot your computer into SafeMode by doing the following:
- Restart your computer.
- After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
- Select the first option, to run Windows in Safe Mode.
- When you are at the logon prompt, log in as an Administrator.
- When your computer has started in SafeMode and you see the desktop.
- Click on Start > Control Panel > Double-click on the Add or Remove Programs icon.
- Find the entry for SpywareQuake and double-click on it. Follow the prompts to uninstall the program, but do not allow it to reboot the computer if it asks.
- Delete the following files and folders (Do not be concerned if this folder does not exist):
- C:\Windows\System32\stickrep.dll <-- File
- C:\Windows\System32\suprox.dll.bad <-- File
- C:\Windows\System32\xenadot.dll.bad <-- File
- C:\WINDOWS\System32\nvctrl.exe <-- File
- C:\WINDOWS\System32\dfrgsrv.exe <-- File
- C:\WINDOWS\System32\mssearchnet.exe <-- File
- C:\WINDOWS\System32\sivudro.dll <-- File
- C:\Program Files\SpywareQuake <-- Folder
- Close all Windows.
- Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
- If there is an uninstaller present for an infection that smitRem removes it will start this uninstaller.
- Simply click on the Uninstall
button and allow the uninstaller to finish. When it is completed, it
will close automatically and smitRem will prompt you to continue. Now
you should press any key to continue.
- Wait for the tool to complete and Disk Cleanup to finish.
- The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed.
- Next go to Control Panel click Display > Desktop > Customize Desktop > Web > Uncheck "Security Info" if present.
Optional: Use this step only if your computer still seems infected:
- Reboot your system back into Normal Mode and perform an online scan with Panda ActiveScan
- Once you are on the Panda site click the Scan your PC button.
- A new window will open...click the Check Now button.[list]
- Enter your Country
- Enter your State/Province
- Enter your e-mail address and click send
- Select either Home User or Company
- Click the big Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
- When the download is complete, click on Local Disks to start the scan
- When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
Thank you Geektogo.com (Grinler, Miekiemoes and Flrman1)
|