Author Topic: SPYAXE !!!!  (Read 3752 times)

0 Members and 1 Guest are viewing this topic.

sonicmax

  • Guest
SPYAXE !!!!
« on: December 30, 2005, 12:36:36 AM »
I some how got spy axe onto my pc. and i have try various methods of removing it. It looks like its gone, but i am not quite sure that it is.

When i want to change my home page internet explorer it goes to a spyware site and its diasbled or deleted explorers pop up blocker. 

How can it correct this?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89129
  • No support PMs thanks
Re: SPYAXE !!!!
« Reply #1 on: December 30, 2005, 01:26:14 AM »
Sounds like some form of browser hijack, a useful diagnostic tool - Download HiJackThis.zip - HJT Information HiJackThis Tutorial 1 or HiJackThis Tutorial 2
For an on-line analysis - HiJackThis Log file - On-line Analysis
Ignore any 023 reference to avast processes, this is a hiccup in the HJT 1.99.1 (especially missing file entry for avast), if you need any help with any of the analysis let us know.
OR HiJackThis Log file - On-line Analysis 2

If you haven't already got this software (freeware), download, install, update and run it.
1. Ad-Aware
2. Spybot Search and Destroy
3. Spywareblaster Don't install this until you are clean.
4. Ewido Security Suite If using winXP. or a-Squared free if using win98/ME.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33916
  • malware fighter
Re: SPYAXE !!!!
« Reply #2 on: December 30, 2005, 01:30:59 AM »
Hi sonicmax,

Here you have an example of how to remove Spy Axe:
http://www.geekstogo.com/forum/index.php?showtopic=84433&mode=threaded&pid=481200

greets,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33916
  • malware fighter
Re: SPYAXE !!!!
« Reply #3 on: January 13, 2006, 11:35:40 AM »
Hi forum members,

Who are those behind infections like Spy Axe and other rogue anti-spyware vendors, infecting machines to sell their scumware?
Read here for some answers:
http://www.sysinternals.com/Blog/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Spiritsongs

  • Guest
Re: SPYAXE !!!!
« Reply #4 on: January 13, 2006, 06:53:25 PM »
 :) These are the "standard" instructions on an antispyware
     forum concerning SpyAxe :
 "INSTRUCTIONS:

A. Download and/or update the following programs. Install them but do NOT run them yet.


Please download HijackThis© Merijn from: http://www.thespykiller.co.uk/files/HJTsetup.exe .

Note: This is a complete installer that installs HijackThis to your computer at C:\Program Files\HijackThis, making an entry in the start menu and also providing a desktop shortcut. If HijackThis is used from a temp folder, it is in danger of being accidentally deleted by clean up tools.

At the download prompt, choose "Save". After the download is complete, navigate to the C:\Program Files\HijackThis folder and double-click it to complete the installation.


Please download smitRem.exe ©noahdfear. Save it to your desktop, then double-click the file and click Start to extract the files to their own folder.

Alternate download site for smitRem© fix: smitRem.exe


Place a shortcut to Panda ActiveScan on your desktop.


Please download Ewido security suite it is a free version of the program.



Install Ewido security suite

When installing, under "Additional Options" uncheck..


Install background guard

Install scan via context menu



Launch Ewido, there should be an icon on your desktop, double-click it.

The program will now open to the main screen.

When you run Ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.


You will need to update Ewido to the latest definition files.


On the left hand side of the main screen click update.

Then click on Start Update.



The update will start and a progress bar will show the updates being installed.
(the status bar at the bottom will display "Update successful")

If you are having problems with the updater, you can use this link to manually update Ewido.
Ewido manual updates


If you have not already installed Ad-Aware SE 1.06, please download it from target="_blank" class="postlink">here or one of the mirror sites on the right-hand side of this page. Follow the instructions here. Don't run it yet!


B. Double-click the HijackThis icon on your desktop. Choose "Do a system scan and save logfile". Select a name for this first logfile.

C. Next, please reboot your computer in SafeMode by doing the following:



Restart your computer

After hearing your computer beep once during startup, but before the Windows icon appears, begin tapping F8.

Instead of Windows loading as normal, a menu should appear

Select the first option, to run Windows in Safe Mode.



D. Run smitRem


Open the smitRem folder

Double-click the RunThis.bat file to start the tool

Follow the prompts on screen.

Wait for the tool to complete and disk cleanup to finish.

The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your post.


E. Launch Ad-Aware SE and do a full scan. Remove all it finds.

F. Shutdown/Restart in SafeMode as instructed above. Run Ewido:


Open Ewido and click on scanner

Click on Complete System Scan and the scan will begin.

While the scan is in progress you will be prompted to clean files, click OK

When it asks if you want to clean the first file, put a check in the lower left corner of the box that says "Perform action on all infections" then choose clean and click OK.

Once the scan has completed, there will be a button located on the bottom of the screen named Save report

Click Save report.

Save the report .txt file to your desktop, or any other easily accessible location.

Now close Ewido security suite.

G. Next go to Control Panel click Display > Desktop > Customize Desktop > Web > Uncheck "Security Info" or anything similar if present.

H. Reboot back into Windows and click the Panda ActiveScan shortcut, then do a full system scan. Make sure the autoclean box is checked!  "