SpywareStrike manual removal:
Kill processes:
mssearchnet.exe, nvctrl.exe, spywarestrike.exe, ss_setup.exe
Delete registry values:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SpywareStrike
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27150F81-0877-42E9-AF13-55E5A3439A26}
HKEY_CLASSES_ROOT\AppID\spywarestrike.exe
HKEY_CLASSES_ROOT\Interface\{2C15CDEA-3EF4-4405-90B0-19A1389B36ED}
HKEY_CLASSES_ROOT\Interface\{3115A433-3FA0-483B-AB01-2A61C951FE58}
HKEY_CLASSES_ROOT\Interface\{51FEFA9C-1D5A-41C4-81FE-8C0FBE9254F0}
HKEY_CLASSES_ROOT\Interface\{5CCC8D01-9F75-4F07-9ACF-DEB314176C79}
HKEY_CLASSES_ROOT\Interface\{5E7BF614-960B-4A1F-9236-9EC01AC4C5E2}
HKEY_CLASSES_ROOT\Interface\{66F0AC1C-DED5-4965-9E31-39788DF1B264}
HKEY_CLASSES_ROOT\Interface\{849E056A-D67A-431E-9370-2275F26D39B5}
HKEY_CLASSES_ROOT\Interface\{8B7AFBFD-631C-45BA-9145-F059EB58DD73}
HKEY_CLASSES_ROOT\Interface\{AFEB8519-0B8B-4023-8C15-FFB17D5225F9}
HKEY_CLASSES_ROOT\Interface\{BA9CC151-4581-438E-94AF-4C703201B7CA}
HKEY_CLASSES_ROOT\Interface\{BC74C336-FF2C-40C9-AD4E-3772C208406B}
HKEY_CLASSES_ROOT\Interface\{BDF00F24-A571-4392-95EC-04FDFF82A82C}
HKEY_CLASSES_ROOT\Interface\{C4E953E6-770E-4F59-A5E3-43E9F0D682E2}
HKEY_CLASSES_ROOT\Interface\{E0105E7C-D0C4-4DEA-AA21-B02F2960ECAF}
HKEY_CLASSES_ROOT\Interface\{ED39CB7C-1BF6-429B-A275-F183B4A3EFCB}
HKEY_CLASSES_ROOT\Interface\{F23AA637-31D5-4526-B5C6-9FF89E16202C}
HKEY_CLASSES_ROOT\TypeLib\{C1A4C0C9-DBD0-493A-93F8-0B05EDC96224}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{70F17C8C-1744-41B6-9D07-575DB448DCC5}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\spywarestrike.exe
HKEY_LOCAL_MACHINE\SOFTWARE\SpywareStrike
HKEY_LOCAL_MACHINE\SOFTWARE\Licenses\{0A4AF3E9A644EE5C8}
HKEY_LOCAL_MACHINE\SOFTWARE\Licenses\{IA4AF3E9A644EE5C8}
HKEY_LOCAL_MACHINE\SOFTWARE\Licenses\{K7C0DB872A3F777C0}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareStrike
Delete files:mssearchnet.exe, nvctrl.exe, spywarestrike.exe, ss_setup.exe, netwrap.dll, replmap.dll, wiatwain.dll, hp[X].tmp
Delete directories:C:\Program Files\SpywareStrike
C:\Documents and Settings\[Current User]\Start Menu\Programs\SpywareStrike
Post Comment:
Attention: Use this form only if you have additional information about SpywareStrike parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.
Comments from visitors:
1. by Guest. 2006-03-01 19:03:45
http://www.bleepingcomputer.com/forums/topic43659.html
BIG MISTAKE..it installed SpyFalcon >
im still running some virus/spyware checkers at the moment, but i got the darn popup to go away. thanks to everybody here, i couldnt have done it without you all.
baron
Thanks, and good luck.
1st: I created an additional admin. account on win. XP
2nd: I booted in safe mode
3rd: I went to the C/WINDOWS/SYSTEM32 file and put all files (VIEW) in detail mode.
4th: I clicked modified date row and all newest files modified were on top.
5th: right click each file that u think was created right before the Spyware strike was installed and check the creation date.
6th: Delete all the files that were created on the date u believe the spyware program was installed.
7th: Ironically, I did this check on all the WINDOWS files (view mode: detail) , and low and behold I found the WIATWAIN.DLL file in the TWAIN folder in WINDOWS folder...not in SYSTEM 32 folder... I deleted that too (even though it said it was created back acouple of years ago..possibly it was modified by spyware program...so delete it)...
8th: Reboot computer ( i accidently deleted a windows xp crit. file so i had to reregister windows..no biggie)...anyways..just reboot computer..
9th: Log in under your own log in...
10th: I used in conjunction with the spydoctor program....Spybot ....
11th: It found the Spywware Strike program which wasnt operating on my system now (maybe deleting one of those dll files earlier).....
12th: have spybot delete it...
13th: Reboot once more to make sure everything is ok..
14th: should be able to log on internet without any pop ups or such...CONGRATS!!
15th: PS..u might want to run spybot once more to see if any thing is detected again...
btw... i did not see replmap.dll on any of my files.....maybe its not used on the newer Spyware strike program?
We will see if I am lucky in the next couple of days ; ;
arg, im still not getting it! im kinda computer savvy, but this stuff is way over my head. anyone found an easy answer yet?
thanks
Baron
Thanks so much as usual 2-spyware. Your legends as ever.
muchos gracias.
windows xp
start, run, "msconfig", boot.ini, check "/safeboot", click ok
once in safe mode click yes to proceed in safe mode.
in safe mode:
start, Program Files, Accessories, Command Prompt,
Prompt commands and order
1 - "cd C:WINDOWSsystem32"
2 - "del mssearchnet.exe"
3 - "del nvctrl.exe"
4 - "dir hp*.tmp"
if and hp[four digit].tmp comes up, do
5 - "del hp[four digit].tmp"
6 - "cd C:Program Files"
7 - "del spywarestrike"
8 - "y"
now go
start, run, msconfig, boot.ini, uncheck "/safemode", click ok.
now you should boot up in normal mode (if a windows disk checker comes up, just skip it)
go through your destop, program files and start bar and manually delete all of the spywarestrike
garbage
empty recycle bin and you are good.
hopes this helps - Joseph
Goos luck to anyone who has this pain in the ass bug.
ghcles
Here are the DOS commands for all of you that dont remb
one it came up with a command promp type
C:
cd windows
cd system32
dir (make sure that replmap.dll listed scroll up to see and if so move on to next step)
dir repl*.dll (once again it should be listed there)
del replmap.dll
dir replmap.dll ( you now should get an error that no file was found)
exit
Reboot your comp and cross your fingers
Hope this helps if that doesnt work try going through all these comments and try something else... as you can see different things work for some and other things for others
Paul
They always come back.
Thanks for the help, Bullit.