Unsolved
This post is more than 5 years old
7 Posts
0
32198
January 2nd, 2006 19:00
Spyaxe will not go away!!!
Ok. So back I come from my brief Christmas vacation. Get home turn on the computer, and whoooosh problems galore. Now I have norton anti-virus, along with the windows beta antispyware program. Norton kept on missing trojan, but it was able to be quarintined eventually. Anyway somehow I seem to have gotten spyaxe on my comp. i have removed it countless times, either through the windows anti-spyware, or by manually going into the control panel and removing it from the add/remove programs part. And what do you know the "darn thing" keeps returning (i don't see why bass-tard is a prohibited word)?!? In addition One of those nice little message bubbles keeps popping up in the lower right hand corner of my taskbar, its something whose icon flashes between the windows icon and a red circle with a white x. I tried contacting windows, but i do not get free support from them due to the fact that I bought my computer with xp already on it....joy. So i did the online chat with dell support but it seems that that is for hardware issues only. My last option, aside from this, is to call the support number. But i seem to have temper problems when being put on hold. So if anyone can help me it would be appreciated.
When i say the message bubble keeps popping up I mean it, I can click on the x to close it but give it a few seconds and it will reappear. Also it makes the "pop" noise about every 10 sec. It's driving me crazzzzzy. If I right click on the icon no menu appears it just launches spy axe.
And advice? And help? Anything?
Mags
When i say the message bubble keeps popping up I mean it, I can click on the x to close it but give it a few seconds and it will reappear. Also it makes the "pop" noise about every 10 sec. It's driving me crazzzzzy. If I right click on the icon no menu appears it just launches spy axe.
And advice? And help? Anything?
Mags
No Events found!


NemesisDB
2 Intern
•
7.9K Posts
0
January 2nd, 2006 20:00
maggiee01
7 Posts
0
January 2nd, 2006 21:00
maggiee01
7 Posts
0
January 2nd, 2006 21:00
RoadiJeff
1.2K Posts
0
January 2nd, 2006 21:00
Where is the thread?
Here's the thread: Spyaxe
maggiee01
7 Posts
0
January 2nd, 2006 21:00
msil217
2 Intern
•
2K Posts
0
January 2nd, 2006 21:00
NemesisDB
2 Intern
•
7.9K Posts
0
January 2nd, 2006 22:00
edit: part of the below solution uses Avast antivirus software. I am unsure how this will interact with Norton. You can either turn norton off while using Avast, or uninstall Norton for a time (make sure you can reinstall it later), or use them both and hope things work, or use Norton instead of Avast. I'm unsure which solution is best for you.
the microsoft KB article is part of my signature and appear in all my messages -- it's somewhat of a generic joke and was not in reference to your post.
my thread on spyaxe is here: http://forums.us.dell.com/supportforums/board/message?board.id=si_virus&message.id=47267 .
the infection (typically) happens like this. you visit a webpage which is using the WMF exploit described in the previous posts. this exploit only requires that your browser load an 'infected' image file. at that point, a trojan (read virus) is typically installed on your machine. a lot of these will popup an insanely annoying message about your computer being infected with spyware. if you click the box it will take you to spy-axe's website. it will also attempt to install and run spyaxe without your knowledge. spyaxe will usually find the trojan in question but will not remove it unless you buy the spyaxe software (a nice little shakedown actually).
this problem annoyed me to no end when it hit a computer on my network. i was finally able to remove it (although new varients of the attack may be harder to kill). I got a lot of my information from this webpage: I will reference and you should feel free to follow it exactly if my suggestions don't work. I'm assuming you have XP http://www.bleepingcomputer.com/forums/How_to_remove_the_Smitfraud_Quicknavigate_VirtualMaid-t17258.html
1) download the following programs:
highjack this: http://www.merijn.org/files/hijackthis.zip and unzip to c:\HJT
smitrem.exe: http://noahdfear.geekstogo.com/click%20counter/click.php?id=1 (extract it to a folder of your choice)
hoster: http://www.funkytoad.com/download/hoster.zip (extract to a folder of your choice)
DelDomains: http://www.mvps.org/winhelp2002/DelDomains.inf (save in a place you can find it)
The trial version of Ewido: http://www.ewido.net/en/download/ (install and update the definitions but do not run a scan yet)
Cleanup: http://www.stevengould.org/downloads/cleanup/CleanUp40.exe (install but do not run yet)
adaware SE: http://www.download.com/Ad-Aware-SE-Personal-Edition/3000-8022_4-10045910.html?part=dl-ad-aware&subj=dl&tag=top5 (scroll down) (install and update definitions but do not scan yet)
spybot SD: http://www.spybot.info/en/mirrors/index.html (do not install yet -- spyaxe and many of the trojabs will delete important Spybot files if the program is installed -- I found this out the hard way)
MS spyware beta. Install this and turn realtime protection on. Update the definitions. Do not run a scan yet! If prompted to restart, do so. http://www.microsoft.com/athome/security/spyware/software/default.mspx .
Avast: http://www.avast.com/eng/download-avast-home.html (the free home edition). Install and update definitions. Decline starting a scan. It's worth noting that the directions above recommend panda activescan instead -- this did not work for me. neither did AVG free. it's probably varient specific though and you may need to try multiple AV software packages.
Once you've got all the files, disconnect from the internet and do not reconnect till we're through. Pull the cable out if possible.
Open Avast and start a scan. It should detect the trojan in memory (if all goes to plan). Whether to delete, attempt repair, or move to chest is your call. I usually deleted because I knew the files were trojans and not critical, but moving to chest or attempting repair might be a more conservative action. When it finds the trojan in memory it will prompt you to perform a boot time scan. Agree to this and reboot as prompted. Let the boot time scan complete -- you will need to specificy an action for every infected file found. After this windows will load. At the first opertunity, click the shutdown button and turn your computer off.
Turn the computer back on and begin pressing F8 as soon as the dell screen goes away. Select safe mode.
Run Highjackthis and select do a system scan only. Compare the list to entries found to this list (taken from above website). If the same entry is found. Put a check mark by it. Once done, click Fix.
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http:://www.quicknavigate.com/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http:://www.quicknavigate.com/bar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http:://www.quicknavigate.com/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http:://www.quicknavigate.com/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http:://www.quicknavigate.com/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http:://www.quicknavigate.com/search.php?qq=%1
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =http:://www.quicknavigate.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http:://www.startsearches.net/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http:://www.startsearches.net/bar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http:://www.startsearches.net/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http:://www.startsearches.net/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http:://www.startsearches.net/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http:://www.startsearches.net/search.php?qq=%1
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http:://www.startsearches.net/
O2 - BHO: VMHomepage Class - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF} - C:\WINDOWS\System32\hp6DD8.tmp
O4 - HKCU\..\Run: [WindowsFY] c:\wp.exe
O4 - HKCU\..\Run: [WindowsFY] c:\bsw.exe
O4 - HKLM\..\Run: [WindowsFZ] C:\WINDOWS\ZLOADER3.EXE
O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKCU\..\Run: [SpySheriff] C:\Program Files\SpySheriff\SpySheriff.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKLM\..\Run: [AntivirusGold] C:\Program Files\AntivirusGold\AntivirusGold.exe /h
O4 - HKCU\..\Run: [Intel system tool] C:\WINDOWS\System32\winnook.exe
O4 - HKCU\..\Run: [Intel system tool] C:\WINDOWS\System32\hookdump.exe
O4 - HKLM\..\Run: [AdwareDelete] C:\Program Files\AdwareDelete\adwaredelete.exe /h
O4 - HKLM\..\Run: [Daily Weather Forecast] C:\Program Files\Daily Weather Forecast\weather.exe
O9 - Extra button: Microsoft AntiSpyware helper - {D5BC2651-6A61-4542-BF7D-84D42228772C} - C:\WINDOWS\System32\wldr.dll
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {D5BC2651-6A61-4542-BF7D-84D42228772C} - C:\WINDOWS\System32\wldr.dll
O9 - Extra button: Microsoft AntiSpyware helper - {D5BC2651-6A61-4542-BF7D-84D42228772C} - C:\WINDOWS\System32\wldr.dll (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {D5BC2651-6A61-4542-BF7D-84D42228772C} - C:\WINDOWS\System32\wldr.dll (HKCU)
Next, find the folder where you extracted smitrem and double click the file called 'runthisbat.' You will need to close all open windows. Follow the prompts the program provides and let it complete!!
Once this is done, launch ad-aware and do a full system scan. Delete and critical objects found. Then run ewido and do the same.
Double click hoster.exe to run the program. Click restore original hosts file and then click make hosts file read only. close the program
Right click deldomains.inf and click install.
Run the cleanup program on the default settings (the highest setting will delete things like bookmarks which are likely important to you).
Optional but recommended. Right click "my computer" and click properties. select the system restore tab and click 'turn off system restore.' This will erase all previous and possibly infected restore points. This is your call as it can delete potentially useful restore points.
Restart the computer and boot windows normally. Upon restarting, run another full virus scan with Avast. Then run a full scan with microsoft's spyware beta. Lastly, install spybot search and destroy and turn resident protection (not teatimer) on. Reconnect to the internet and download updates. Disconnect. Use the immunize function and then do a full scan.
At this point, your system will hopefully be clean. You should unregister the dll as mentioned in the above thread. You should also install this unoffical patch: http://www.hexblog.com/2005/12/wmf_vuln.html . Remember to reregister the dll and uninstall this patch when microsoft releases their official patch.
Hope this helps. I'm be know means an expert in this area or certified to post on the HJT board -- so if anyone wants to correct me or offer other advice, feel free. This process worked for me though
Message Edited by NemesisDB on 01-02-2006 07:23 PM
Message Edited by NemesisDB on 01-02-2006 07:26 PM
dave0102
27 Posts
0
January 3rd, 2006 04:00
jillt3
4 Posts
0
January 3rd, 2006 15:00
so you are saying download all of those things.
I have avast on my computer and i still have the saying in the right lower corner your computer is infected. it will not go away.
NemesisDB
2 Intern
•
7.9K Posts
0
January 3rd, 2006 15:00
jillt3
4 Posts
0
January 3rd, 2006 15:00
Maggiee01,
I am having the same trouble you are and I hate it did you every get it off of your computer if so how did you do it. i downloaded the one from macfae but it messed up my interent. This is really making me mad!!!!!!!!!!!!!!
Jillt3
Jasminesjoy
10 Posts
0
January 3rd, 2006 15:00
jillt3
4 Posts
0
January 3rd, 2006 15:00
device manager
101 Posts
0
January 3rd, 2006 22:00
Jill, reboot to safe mode and disable system restore.
Run Panda http://www.pandasoftware.com/activescan
Download and check the readme: http://www.dcwclan.com/files/SpyAxeRemoval.zip
Message Edited by device manager on 01-03-2006 06:47 PM
NemesisDB
2 Intern
•
7.9K Posts
0
January 4th, 2006 00:00