Oletko vieläkään kokeillut poistoa spybotilla tai adawarella?
Sen lisäksi kannattaa kokeilla HiJackThis-ohjelmaa.
Helppoa tapaa ei tuon jo mainitun linkin lisäksi taida olla.
http://koti.mbnet.fi/pattaya1/hijackthis.htm
Tuolla ohjeet ja hijackthis:in lataus. Ohjelma todennäköisesti löytää kaikki seuraavaksi mainitut kohdat, mutta jos haluat varmistua siitä, mitä olet poistamassa, tarkista lista.
!! Käytä omalla riskillä ja tee varmuuskopiot tärkeistä tiedostoista !!
Poista seuraavat prosessit koneeltasi
spywarequakeinstaller.exe
spywarequake.exe
uninst.exe
dfrgsrv.exe
mssearchnet.exe
nvctrl.exe
ishost.exe
ismon.exe
isnotify.exe
issearch.exe
spy-quake2.exe
win3.tmp.exe
win9.tmp.exe
SpywareQuakeInstaller[1].exe
win5.tmp.exe
winF.tmp.exe
win17.tmp.exe
win8.tmp.exe
win12.tmp.exe
win6.tmp.exe
win7.tmp.exe
9.tmp.exe
win18.tmp.exe
win13.tmp.exe
Poista seuraavat merkinnät rekisteristä
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunSpywareQuake
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorer
E2CA7CD1-1AD9-F1C4-3D2A-DC1A33E7AF9D
661173EE-FA31-4769-97D4-B556B5D09BDA
4DA4616D-7E6E-4FD9-A2D5-B6C535733E22
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallSpywareQuake
CurrentVersionAppPathsSpywareQuake.exe:"%programfiles%SpywareQuakeSpywareQuake.exe"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows
CurrentVersionRunSpywareQuake:"%programfiles%SpywareQuakeSpywareQuake.exe/h"
CurrentVersionUninstallSpywareQuakeDisplayName:"SpywareQuake2.0"
CurrentVersionUninstallSpywareQuakeUninstallString:"%programfiles%SpywareQuakeuninst.exe"
CurrentVersionUninstallSpywareQuakeDisplayIcon:"%programfiles%SpywareQuakeSpywareQuake.exe"
CurrentVersionUninstallSpywareQuakeDisplayVersion:"2.0"
CurrentVersionUninstallSpywareQuakeNSIS:StartMenuDir:"SpywareQuake"
CurrentVersionUninstallSpywareQuakeURLInfoAbout:"http://www.spywarequake.com"
CurrentVersionUninstallSpywareQuakePublisher:"SpywareQuake.com"
HKEY_LOCAL_MACHINESOFTWARESpywareQuakerefid:"1"
HKEY_LOCAL_MACHINESOFTWARESpywareQuakeLanguage:"1033"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunSpyQuake2.com
SOFTWAREMicrosoftWindowsCurrentVersionExplorerSharedTaskSchedulerEA26CE12-DE64-A1C5-9A4F-FC1A64E6AC2E
SOFTWAREMicrosoftWindowsCurrentVersionExplorerSharedTaskSchedulerAC1B4DA2-12FA-31F2-1A7D-CD2B14E6AD4E
5B55C4E3-C179-BA0B-B4FD-F2DB862D6202
2DD8D482-8F1C-4180-AA8E-9D5819E5F2EA
411F83B1-A0EC-4155-AF99-0137F5EFB270
4E3645AF-7A81-4F83-9B8C-1E4F930D873F
61032A65-2371-4C89-B5BB-DF73090FB5EA
66189AF2-7726-46E8-8628-0F95AB854792
7A2F6251-6C99-4DA5-9827-954EB45DCB82
82C6C396-DD7B-4CE5-B668-C0087D1F3A1F
853E0D78-F4C2-47CB-A3F5-A774DA60DFCD
94786C47-EB3F-4BD5-A66B-0D49E2C90541
9989A9BC-9828-467E-AF06-E3B279E6E97B
B2B3702A-5425-489E-A3AF-EDCCAFEBA019
C1C56112-2B2E-4D3C-8CFC-7E10C77FACEF
D01D4AAB-22C5-427F-A941-C4B65A3D8A23
DDB0D689-FAE0-4165-9F7C-877602F9DD66
E5AD5BD5-C710-45E0-ABD3-E770FE85DAE8
EB5CA3AF-26C1-467B-9A55-2820E0451AAB
5E05EA9F-1EA7-4D0B-A09B-D5E29EC758B9
MicrosoftWindowsCurrentVersionApp PathsSpy-Quake2.exe
SpyQuake2.com
89e4aaba-3b21-49b3-b922-8ca35193c68e
210b4043-35ca-4aa0-8796-191f9663dfb3
EA26CE12-DE64-A1C5-9A4F-FC1A64E6AC2E
AC1B4DA2-12FA-31F2-1A7D-CD2B14E6AD4E
189518DF-7EBA-4D31-A7E1-73B5BB60E8D5
23D627FE-3F02-44CF-9EE1-7B9E44BD9E13
43CFEFBE-8AE4-400E-BBE4-A2B61BB140FB
5790B963-23C5-43C1-BCF5-01C9B5A3E44E
5D42DDF4-81EB-4668-9951-819A1D5BEFC8
76D06077-D5D3-40CA-B32D-6A67A7FF3F06
86C7E6C3-EC47-44E5-AA08-EE0D0A25895F
9283DAC1-43F5-4580-BF86-841F22AF2335
AE90CAFC-09D4-47F0-9E11-CE621C424F08
BA397E39-F67F-423F-BC6E-65939450093A
BEC8A83D-01D4-4F15-B8A9-4B4AB24253A7
C4EEDC19-992D-409A-B323-ED57D511AFA5
DD90F677-D205-4F70-9014-659614AABCB2
E3DF91F3-F24F-441E-9001-D61F36024322
F459EADB-5903-48D5-864C-2B7B46AB1424
FC4EDF66-0547-4F1A-AE96-7CFCAD711C90
MicrosoftWindowsCurrentVersionApp PathsSpywareQuake.exe
SpywareQuake
a43385f0-7113-496d-96d7-b9b550e3fcca
SoftwareMicrosoftInternet ExplorerToolbar 52b12f7-86fa-4921-8482-26c42316b522
052b12f7-86fa-4921-8482-26c42316b522
39f25b12-74ff-4079-a51f-1d70f5b08b84
755bbd1a-aa59-456c-afeb-b4c42c4dcb6f
SoftwareMicrosoftInternet ExplorerToolbarWebBrowser 52B12F7-86FA-4921-8482-26C42316B522
SoftwareMicrosoftInternet ExplorerToolbarWebBrowserFBEA0445-4C4A-4136-864A-C72A4A182A84
SOFTWAREMicrosoftInternet ExplorerToolbarfbea0445-4c4a-4136-864a-c72a4a182a84
fbea0445-4c4a-4136-864a-c72a4a182a84
Poista näiden DLL-tiedostojen rekisteröinti
ywbicim.dll
wfkduei.dll
hvnwm.dll
imfdfcj.dll
yhbdupd.dll
stickrep.dll
sivudro.dll
xenadot.dll
dvdcap.dll
suprox.dll
msvcp71.dll
msvcr71.dll
autodisc32.dll
bpvcou.dll
dnefhw.dll
erxbx.dll
guxxa.dll
gvfsc.dll
hvcycg.dll
hzclqhc.dll
jevtxpg.dll
kkqfb.dll
lwpfwjb.dll
mzoeut.dll
ofcukiz.dll
ornzq.dll
oybgrql.dll
pmnqguh.dll
rmzdzx.dll
tnvocyn.dll
qrucmr.dll
vhywj.dll
viwpzla.dll
vpxnk.dll
xuefh.dll
yfysupa.dll
yephk.dll
yvvdj.dll
zlara.dll
fhmfes.dll
jpqet.dll
viruxz.dll
vwlummc.dll
urroxtl.dll
Winwcd.dll
SafetyBar.dll
ixt0.dll
flx3.dll
Etsi ja poista seuraavat tiedostot
spywarequakeinstaller.exe
spywarequake.exe
uninst.exe
ywbicim.dll
wfkduei.dll
hvnwm.dll
imfdfcj.dll
yhbdupd.dll
stickrep.dll
sivudro.dll
xenadot.dll
dvdcap.dll
suprox.dll
msvcp71.dll
msvcr71.dll
dfrgsrv.exe
mssearchnet.exe
nvctrl.exe
spywarequake2.0website.lnk
spywarequake2.0.lnk
uninstallspywarequake2.0.lnk
blacklist.txt
ref.dat
spywarequake.url
sq.ini
english.ini
hp[X].tmp
ld[X].tmp
autodisc32.dll
bpvcou.dll
dnefhw.dll
erxbx.dll
guxxa.dll
gvfsc.dll
hvcycg.dll
hzclqhc.dll
jevtxpg.dll
kkqfb.dll
lwpfwjb.dll
mzoeut.dll
ofcukiz.dll
ornzq.dll
oybgrql.dll
pmnqguh.dll
rmzdzx.dll
tnvocyn.dll
qrucmr.dll
vhywj.dll
viwpzla.dll
vpxnk.dll
xuefh.dll
yfysupa.dll
yephk.dll
yvvdj.dll
zlara.dll
ishost.exe
ismon.exe
isnotify.exe
issearch.exe
spy-quake2.exe
fhmfes.dll
jpqet.dll
viruxz.dll
vwlummc.dll
SpyQuake2.com
SpywareQuake
SpyQuake2.com 2.3.lnk
SpyQuake2.com.lnk
SpyQuake2.com 2.3 Website.lnk
Uninstall SpyQuake2.com 2.3.lnk
win3.tmp.exe
win9.tmp.exe
SpywareQuakeInstaller[1].exe
SpywareQuake.lnk
win5.tmp.exe
winF.tmp.exe
urroxtl.dll
Winwcd.dll
SafetyBar.dll
ixt0.dll
win17.tmp.exe
win8.tmp.exe
flx3.dll
win12.tmp.exe
win6.tmp.exe
win7.tmp.exe
9.tmp.exe
win18.tmp.exe
win13.tmp.exe