Home Malware Programs Rogue Anti-Spyware Programs SpywareQuake

SpywareQuake

Posted: May 30, 2006

Threat Metric

Threat Level: 10/10
Infected PCs: 52
First Seen: July 24, 2009
Last Seen: April 18, 2023
OS(es) Affected: Windows

ScreenshotSpywareQuake is a trojan that displays an icon in the system tray. SpywareQuake looks like a legitimate application for removal of spyware, but it installs a trojan in an attempt to trick you into buying the software. The SpywareQuake trojan is able to change the Internet Explorer default home page and redirect the web browser to malicious web sites. SpywareQuake will also pop-up fake alerts that resemble system alerts in another attempt to get you to buy it.

Aliases

VIPRE.Suspicious [Sunbelt]Troj/Nonaco-Gen [Sophos]Suspicious file [Panda]TrojanDownloader:Win32/Nonaco.A [Microsoft]Suspicious Trojan/Worm [eSafe]Trojan.DownLoader.25873 [DrWeb](Suspicious) - DNAScan [CAT-QuickHeal]Generic.Drop.Alpha.3CEE6CC4 [BitDefender]Win32:Alphabet-D [Avast]TR/Dldr.Alphabet.LH1 [AntiVir]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



winB471.tmp.exe File name: winB471.tmp.exe
Size: 20.99 KB (20992 bytes)
MD5: 8bb1f9c3d383834b38468c29dd4c83d4
Detection count: 90
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
win15.tmp.exe File name: win15.tmp.exe
Size: 20.99 KB (20992 bytes)
MD5: 23ef96e4105f541afc25845fd0f62565
Detection count: 86
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
srvqnm[1].exe win8.tmp.exe File name: srvqnm[1].exe win8.tmp.exe
Size: 19.45 KB (19456 bytes)
MD5: 6c32a0f11037fb2d319e3ab58bcac0aa
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
SpywareQuakeInstaller[1].exe File name: SpywareQuakeInstaller[1].exe
Size: 2.86 MB (2862626 bytes)
MD5: 1a356729cf6dcd5617e4062a8e866c3f
Detection count: 64
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
win35.tmp.exe File name: win35.tmp.exe
Size: 20.48 KB (20480 bytes)
MD5: 229a6f5beb54c795d3efb8026ff8a9ab
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
fccbx.dll File name: fccbx.dll
Size: 266.33 KB (266336 bytes)
MD5: 3372c1363d15cd98abe1406783571295
Detection count: 11
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
win9.tmp.exe File name: win9.tmp.exe
Size: 78.33 KB (78336 bytes)
MD5: 4f28741f8562780dd6db2ea6e10c1a68
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 20, 2022

Registry Modifications

The following newly produced Registry Values are:

CLSID{189518DF-7EBA-4D31-A7E1-73B5BB60E8D5}{23D627FE-3F02-44CF-9EE1-7B9E44BD9E13}{43CFEFBE-8AE4-400E-BBE4-A2B61BB140FB}{5790B963-23C5-43C1-BCF5-01C9B5A3E44E}{5D42DDF4-81EB-4668-9951-819A1D5BEFC8}{76D06077-D5D3-40CA-B32D-6A67A7FF3F06}{86C7E6C3-EC47-44E5-AA08-EE0D0A25895F}{9283DAC1-43F5-4580-BF86-841F22AF2335}{AE90CAFC-09D4-47F0-9E11-CE621C424F08}{BA397E39-F67F-423F-BC6E-65939450093A}{BEC8A83D-01D4-4F15-B8A9-4B4AB24253A7}{C4EEDC19-992D-409A-B323-ED57D511AFA5}{DD90F677-D205-4F70-9014-659614AABCB2}{E3DF91F3-F24F-441E-9001-D61F36024322}{F459EADB-5903-48D5-864C-2B7B46AB1424}{FC4EDF66-0547-4F1A-AE96-7CFCAD711C90}

Additional Information

The following cookies were detected:
spywarequake

Related Posts

One Comment

  • Vicki Burdin says:

    Security Shield is a virus and won't let me off without a credit card. It keeps popping up to make me accept their so-called "Protection" for $79.99 or something. IT IS A VIRUS

Loading...