Unsolved

This post is more than 5 years old

7 Posts

32198

January 2nd, 2006 19:00

Spyaxe will not go away!!!

Ok. So back I come from my brief Christmas vacation. Get home turn on the computer, and whoooosh problems galore. Now I have norton anti-virus, along with the windows beta antispyware program. Norton kept on missing trojan, but it was able to be quarintined eventually. Anyway somehow I seem to have gotten spyaxe on my comp. i have removed it countless times, either through the windows anti-spyware, or by manually going into the control panel and removing it from the add/remove programs part. And what do you know the "darn thing" keeps returning (i don't see why bass-tard is a prohibited word)?!? In addition One of those nice little message bubbles keeps popping up in the lower right hand corner of my taskbar, its something whose icon flashes between the windows icon and a red circle with a white x. I tried contacting windows, but i do not get free support from them due to the fact that I bought my computer with xp already on it....joy. So i did the online chat with dell support but it seems that that is for hardware issues only. My last option, aside from this, is to call the support number. But i seem to have temper problems when being put on hold. So if anyone can help me it would be appreciated.
When i say the message bubble keeps popping up I mean it, I can click on the x to close it but give it a few seconds and it will reappear. Also it makes the "pop" noise about every 10 sec. It's driving me crazzzzzy. If I right click on the icon no menu appears it just launches spy axe.
And advice? And help? Anything?
Mags

2 Intern

 • 

7.9K Posts

January 2nd, 2006 20:00

it took me a few days to get rid of it on mine ... you can scroll down and look at the thread.  more to the point, it's going to keep getting installed via the WMF exploit.

7 Posts

January 2nd, 2006 21:00

WMF exploit??? Did I mention that I am blonde? Whats the WMF exploit?

7 Posts

January 2nd, 2006 21:00

Where is the thread? All the connection took me to was info. on how to ask a question....Wait.....are you trying to send me a not so subtle message?!?!? Actually I couldn't find the thread re:spyaxe or something similar....am I blind???

1.2K Posts

January 2nd, 2006 21:00

Where is the thread?

Here's the thread: Spyaxe

7 Posts

January 2nd, 2006 21:00

just out of curiousity will something remind me to reinstall, or re-register shimngvw.dll. I am a wee bit on the absentminded side here.

2 Intern

 • 

2K Posts

January 2nd, 2006 21:00

http://www.updatexp.com/wmf-exploit.html

2 Intern

 • 

7.9K Posts

January 2nd, 2006 22:00

edit: part of the below solution uses Avast antivirus software.  I am unsure how this will interact with Norton.  You can either turn norton off while using Avast, or uninstall Norton for a time (make sure you can reinstall it later), or use them both and hope things work, or use Norton instead of Avast.  I'm unsure which solution is best for you.

the microsoft KB article is part of my signature and appear in all my messages -- it's somewhat of a generic joke and was not in reference to your post.

my thread on spyaxe is here:  http://forums.us.dell.com/supportforums/board/message?board.id=si_virus&message.id=47267 .

the infection (typically) happens like this.  you visit a webpage which is using the WMF exploit described in the previous posts.  this exploit only requires that your browser load an 'infected' image file.  at that point, a trojan (read virus) is typically installed on your machine.  a lot of these will popup an insanely annoying message about your computer being infected with spyware.  if you click the box it will take you to spy-axe's website.  it will also attempt to install and run spyaxe without your knowledge.  spyaxe will usually find the trojan in question but will not remove it unless you buy the spyaxe software (a nice little shakedown actually).

this problem annoyed me to no end when it hit a computer on my network.  i was finally able to remove it (although new varients of the attack may be harder to kill).  I got a lot of my information from this webpage:  I will reference and you should feel free to follow it exactly if my suggestions don't work. I'm assuming you have XP http://www.bleepingcomputer.com/forums/How_to_remove_the_Smitfraud_Quicknavigate_VirtualMaid-t17258.html

1) download the following programs:

 

highjack this: http://www.merijn.org/files/hijackthis.zip and unzip to c:\HJT

smitrem.exe: http://noahdfear.geekstogo.com/click%20counter/click.php?id=1 (extract it to a folder of your choice)

hoster: http://www.funkytoad.com/download/hoster.zip (extract to a folder of your choice)

DelDomains: http://www.mvps.org/winhelp2002/DelDomains.inf (save in a place you can find it)

The trial version of Ewido: http://www.ewido.net/en/download/ (install and update the definitions but do not run a scan yet)

Cleanup: http://www.stevengould.org/downloads/cleanup/CleanUp40.exe (install but do not run yet)

adaware SE: http://www.download.com/Ad-Aware-SE-Personal-Edition/3000-8022_4-10045910.html?part=dl-ad-aware&subj=dl&tag=top5 (scroll down) (install and update definitions but do not scan yet)

spybot SD: http://www.spybot.info/en/mirrors/index.html (do not install yet -- spyaxe and many of the trojabs will delete important Spybot files if the program is installed -- I found this out the hard way)

MS spyware beta.  Install this and turn realtime protection on.  Update the definitions.  Do not run a scan yet!  If prompted to restart, do so.  http://www.microsoft.com/athome/security/spyware/software/default.mspx .

Avast: http://www.avast.com/eng/download-avast-home.html (the free home edition).  Install and update definitions.  Decline starting a scan.  It's worth noting that the directions above recommend panda activescan instead -- this did not work for me.  neither did AVG free.  it's probably varient specific though and you may need to try multiple AV software packages.

Once you've got all the files, disconnect from the internet and do not reconnect till we're through.  Pull the cable out if possible.

Open Avast and start a scan.  It should detect the trojan in memory (if all goes to plan).  Whether to delete, attempt repair, or move to chest is your call.  I usually deleted because I knew the files were trojans and not critical, but moving to chest or attempting repair might be a more conservative action.  When it finds the trojan in memory it will prompt you to perform a boot time scan.  Agree to this and reboot as prompted.  Let the boot time scan complete -- you will need to specificy an action for every infected file found.  After this windows will load.  At the first opertunity, click the shutdown button and turn your computer off.

Turn the computer back on and begin pressing F8 as soon as the dell screen goes away.  Select safe mode.

Run Highjackthis and select do a system scan only.  Compare the list to entries found to this list (taken from above website).  If the same entry is found.  Put a check mark by it.  Once done, click Fix.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http:://www.quicknavigate.com/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http:://www.quicknavigate.com/bar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http:://www.quicknavigate.com/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http:://www.quicknavigate.com/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http:://www.quicknavigate.com/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http:://www.quicknavigate.com/search.php?qq=%1
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =http:://www.quicknavigate.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http:://www.startsearches.net/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http:://www.startsearches.net/bar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http:://www.startsearches.net/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http:://www.startsearches.net/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http:://www.startsearches.net/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http:://www.startsearches.net/search.php?qq=%1
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http:://www.startsearches.net/
O2 - BHO: VMHomepage Class - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF} - C:\WINDOWS\System32\hp6DD8.tmp
O4 - HKCU\..\Run: [WindowsFY] c:\wp.exe
O4 - HKCU\..\Run: [WindowsFY] c:\bsw.exe
O4 - HKLM\..\Run: [WindowsFZ] C:\WINDOWS\ZLOADER3.EXE
O4 - HKLM\..\Run: [Security iGuard] C:\Program Files\Security iGuard\Security iGuard.exe
O4 - HKCU\..\Run: [SpySheriff] C:\Program Files\SpySheriff\SpySheriff.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKLM\..\Run: [AntivirusGold] C:\Program Files\AntivirusGold\AntivirusGold.exe /h
O4 - HKCU\..\Run: [Intel system tool] C:\WINDOWS\System32\winnook.exe
O4 - HKCU\..\Run: [Intel system tool] C:\WINDOWS\System32\hookdump.exe
O4 - HKLM\..\Run: [AdwareDelete] C:\Program Files\AdwareDelete\adwaredelete.exe /h
O4 - HKLM\..\Run: [Daily Weather Forecast] C:\Program Files\Daily Weather Forecast\weather.exe
O9 - Extra button: Microsoft AntiSpyware helper - {D5BC2651-6A61-4542-BF7D-84D42228772C} - C:\WINDOWS\System32\wldr.dll
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {D5BC2651-6A61-4542-BF7D-84D42228772C} - C:\WINDOWS\System32\wldr.dll
O9 - Extra button: Microsoft AntiSpyware helper - {D5BC2651-6A61-4542-BF7D-84D42228772C} - C:\WINDOWS\System32\wldr.dll (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {D5BC2651-6A61-4542-BF7D-84D42228772C} - C:\WINDOWS\System32\wldr.dll (HKCU)

Next, find the folder where you extracted smitrem and double click the file called 'runthisbat.'  You will need to close all open windows.  Follow the prompts the program provides and let it complete!!

Once this is done, launch ad-aware and do a full system scan.  Delete and critical objects found.  Then run ewido and do the same.

Double click hoster.exe to run the program.  Click restore original hosts file and then click make hosts file read only.  close the program

Right click deldomains.inf and click install.

Run the cleanup program on the default settings (the highest setting will delete things like bookmarks which are likely important to you).

Optional but recommended.  Right click "my computer" and click properties.  select the system restore tab and click 'turn off system restore.'  This will erase all previous and possibly infected restore points.  This is your call as it can delete potentially useful restore points.

Restart the computer and boot windows normally.  Upon restarting, run another full virus scan with Avast.  Then run a full scan with microsoft's spyware beta.  Lastly, install spybot search and destroy and turn resident protection (not teatimer) on.  Reconnect to the internet and download updates.  Disconnect.  Use the immunize function and then do a full scan.

At this point, your system will hopefully be clean.  You should unregister the dll as mentioned in the above thread.  You should also install this unoffical patch:  http://www.hexblog.com/2005/12/wmf_vuln.html .  Remember to reregister the dll and uninstall this patch when microsoft releases their official patch.

Hope this helps.  I'm be know means an expert in this area or certified to post on the HJT board -- so if anyone wants to correct me or offer other advice, feel free.  This process worked for me though

 

 

 

Message Edited by NemesisDB on 01-02-2006 07:23 PM

Message Edited by NemesisDB on 01-02-2006 07:26 PM

27 Posts

January 3rd, 2006 04:00

I have succesfully remove the spyaxe on my computer with the procedures on this site:

4 Posts

January 3rd, 2006 15:00

so you are saying download all of those things.

I have avast on my computer and i still have the saying in the right lower corner your computer is infected. it will not go away.

2 Intern

 • 

7.9K Posts

January 3rd, 2006 15:00

follow my procedure above ... it should work on most varients

4 Posts

January 3rd, 2006 15:00

Maggiee01,

I am having the same trouble you are and I hate it did you every get it off of your computer if so how did you do it. i downloaded the one from macfae but it messed up my interent. This is really making me mad!!!!!!!!!!!!!!

Jillt3

10 Posts

January 3rd, 2006 15:00

I am having the same problem. :smileymad: I really thought that I either find some help here or from Microsoft. This is really frustrating me, if anyone can help us, PLEASE DO.
Jasmine

4 Posts

January 3rd, 2006 15:00

I downloaded one thing and it messed up my dsl. so i had to remove it. it did not remove the spyaxe though it is still here and really making me crazy!!!!!!!!!!!!!!!!

January 3rd, 2006 22:00



@jillt3 wrote:

so you are saying download all of those things.

I have avast on my computer and i still have the saying in the right lower corner your computer is infected. it will not go away.



Jill, reboot to safe mode and disable system restore.

Run Panda http://www.pandasoftware.com/activescan

Download and check the readme: http://www.dcwclan.com/files/SpyAxeRemoval.zip


Message Edited by device manager on 01-03-2006 06:47 PM

2 Intern

 • 

7.9K Posts

January 4th, 2006 00:00

device, panda didn't work for me ...  but as I said above, there are so many varients out now it's somewhat luck of the draw which AV program is going to detect what you have
No Events found!

Top