Re: Removal of SpywareStrike v2.5
- From: "David H. Lipman" <DLipman~nospam~@Verizon.Net>
- Date: Mon, 9 Jan 2006 09:30:05 -0500
From: <Frank_X_Rizzo@xxxxxxxxxxx>
| This site was helpful in removing the beast.
| http://www.2-spyware.com/remove-spywarestrike.html
| I post it here for others to benefit, as I spent hours trying to fix
| it.
|
| The following did not even notice it at all
| * MS AntiSpyware Did not fix
| * AVG
|
| LavaSoft AdAware could find some stuff, but could not keep it from
| coming back
| Doctor Spyware could see it, but wanted $$$ to actualy delete...after
| all I heard, I am dissappointed with that BS
|
| Use Killbox to remove all obstinant files...all the files below refuse
| to be deleted normally
|
| SpywareStrike manual removal:
| Kill processes:
| mssearchnet.exe, nvctrl.exe, spywarestrike.exe
| Help: how to kill malicious processes
|
| Delete registry values:
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SpywareStrike
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser
| Helper Objects\{27150F81-0877-42E9-AF13-55E5A3439A26}
| Help: how to remove registry entries
|
| Delete files:
| mssearchnet.exe, nvctrl.exe, spywarestrike.exe, netwrap.dll, hp[X].tmp
| Help: how to remove harmful files
|
| Delete directories:
| C:\Program Files\SpywareStrike
|
| Misc:
| [X] is a set of four random characters. These can be either digits or
| letters.
|
| Exact file location:
| spywarestrike.exe - C:\Program Files\SpywareStrike
| mssearchnet.exe, nvctrl.exe, netwrap.dll, hp[X].tmp -
| C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
|
| --FrankX
It should be noted that the above has been fully scripted and is built into the utilities in
"Part 1" and "Part 2" below...
Two part reply..
Perform Part 1 then perform Part 2.
If the first two parts don't work, perform the alternate utility.
It is suggested that you execute each tool in Normal Mode then in Safe Mode.
Part 1
-----------
Use noahdfear's SmitFraud and SpyAxe removal tool -- SmitRem.exe
http://noahdfear.geekstogo.com/click%20counter/click.php?id=1
http://www.bleepingcomputer.com/forums/topic36868.html
Part 2
-----------
Download SmitFraud.exe from the URL --
http://www.ik-cs.com/programs/virtools/SmitFraud.exe
Execute; SmitFraud.exe { Note: You must accept the default of C:\McAfee }
Choose; Unzip
Choose; Close
NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to enable WGET.EXE to download the needed McAfee related files.
Execute; c:\mcafee\clean.bat
{ or Double-click on 'Clean Link' in c:\mcafee }
A final report in HTML format called C:\mcafee\ScanReport.HTML will be generated. At the
end of the scan, it will be displayed in your browser (Opera, FireFox or Internet Explorer).
It is suggested that you move the report out of c:\mcafee before performing another scan.
Please Copy and Paste the contents of the HTML Log file; C:\mcafee\ScanReport.HTML in your
reply.
* * * Please report back your results * * *
--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm
.
- Follow-Ups:
- Re: Removal of SpywareStrike v2.5
- From: moolovescrisps
- Re: Removal of SpywareStrike v2.5
- References:
- Re: Removal of SpywareStrike v2.5
- From: Frank_X_Rizzo
- Re: Removal of SpywareStrike v2.5
- Prev by Date: RE: SearchWWW is Back!
- Next by Date: Re: SearchWWW is Back!
- Previous by thread: Re: Removal of SpywareStrike v2.5
- Next by thread: Re: Removal of SpywareStrike v2.5
- Index(es):
Relevant Pages
|