Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | SpyAxe 3.0 Malware...


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

SpyAxe 3.0 Malware...
Reply
 
Thread Tools
Old 07-12-2005, 17:33   #1
jamesclarke555
Inactive
 
jamesclarke555's Avatar
 
Join Date: Jan 2004
Age: 32
Posts: 685
jamesclarke555 has reached the bronze age
jamesclarke555 has reached the bronze agejamesclarke555 has reached the bronze agejamesclarke555 has reached the bronze agejamesclarke555 has reached the bronze age
SpyAxe 3.0 Malware...

Just a heads up for people. My PC was infected with this joker today and it's rather a pain in the ar$e.

I've also lost faith in MS AntiSpyware, as the program did absolutely nothing to stop it and woudn't even detect its presence when running a full scan! Even manually blocking each process didn't work and it reared its ugly head in the form of browser hijacks, constant pop-ups and generally weird behaviour! The irony is that this malware claims to be an anti-spyware solution

Anyway, a quick Ad-Aware scan later determined the culprit, although the program detects the malware, it has trouble removing it.

So here's how:

1. Search for a file called svchosts.dll (not to be confused with the legitimate process svchosts.exe).

2. Rename this file to something else, like pain.dll (you can't delete svchosts.dll directly, as it's "in use").

3. Reboot the machine and go to Control Panel / Internet Options / Programs / Manage Add - Ons.

4. Disable HomepageBHO.

5. Don't forget to delete the .dll file.
jamesclarke555 is offline   Reply With Quote
Advertisement
Old 07-12-2005, 17:43   #2
Paul
Google it!!
 
Paul's Avatar
 
Join Date: Jun 2003
Location: Essex innit
Age: 39
Services: Sky HD + 16Mb ADSL BT Telephone
Posts: 15,735
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Re: SpyAxe 3.0 Malware...

Sounds nasty but at least Google hit those instructions on it's first link from a search
Google search link
Looks like it's a new kid on the malware block, christmas must be arriving early or something with all the new gifts people are finding on their PCs lately lol.
Paul is offline   Reply With Quote
Old 07-12-2005, 17:49   #3
jamesclarke555
Inactive
 
jamesclarke555's Avatar
 
Join Date: Jan 2004
Age: 32
Posts: 685
jamesclarke555 has reached the bronze age
jamesclarke555 has reached the bronze agejamesclarke555 has reached the bronze agejamesclarke555 has reached the bronze agejamesclarke555 has reached the bronze age
Re: SpyAxe 3.0 Malware...

Seems there's still leftovers

Quote:
SpyAxe is a trojan, which displays one or two icons in the system tray. These icons show a message saying that the compromised system is infected with spyware parasites and asking the user to download and install an anti-spyware program, which actually is the infamous SpyAxe, corrupt illegally distributed spyware remover. Once the user clicks on such message, the trojan opens the anti-spyware's official web site. It may also try to download the application automatically. SpyAxe may also change the desktop background. The trojan automatically runs on every Windows startup.
Gonna try this:
http://forums.majorgeeks.com/showthread.php?t=78572
jamesclarke555 is offline   Reply With Quote
Old 07-12-2005, 19:24   #4
fireman328
cf.mega poster
 
fireman328's Avatar
 
Join Date: Nov 2003
Location: Surrey
Posts: 1,356
fireman328 has reached the bronze age
fireman328 has reached the bronze agefireman328 has reached the bronze age
Re: SpyAxe 3.0 Malware...

There is an update dated 02/12/2005 to MS AntiSpyware if you are using the earlier version.
fireman328 is offline   Reply With Quote
Old 07-12-2005, 23:01   #5
jamesclarke555
Inactive
 
jamesclarke555's Avatar
 
Join Date: Jan 2004
Age: 32
Posts: 685
jamesclarke555 has reached the bronze age
jamesclarke555 has reached the bronze agejamesclarke555 has reached the bronze agejamesclarke555 has reached the bronze agejamesclarke555 has reached the bronze age
Re: SpyAxe 3.0 Malware...

Quote:
Originally Posted by fireman328
There is an update dated 02/12/2005 to MS AntiSpyware if you are using the earlier version.
Got the latest build with the latest definitions.
jamesclarke555 is offline   Reply With Quote
Old 08-12-2005, 01:08   #6
50420
cf.addict
 
Join Date: Jul 2003
Posts: 399
50420 has entered a golden reputation era50420 has entered a golden reputation era50420 has entered a golden reputation era50420 has entered a golden reputation era50420 has entered a golden reputation era50420 has entered a golden reputation era50420 has entered a golden reputation era50420 has entered a golden reputation era50420 has entered a golden reputation era50420 has entered a golden reputation era50420 has entered a golden reputation era
Re: SpyAxe 3.0 Malware...

funny thing...just a few minutes after reading the original post on this thread, a friend called with a problem he's been having with popups. he brought the pc down for me to take alook at it....set it up here and booted it boots into a spy axe scan.. managed to get ms antispyware, adaware,spybot, ewido, avast, zonealarm, CCleaner and hijack this onto the pc...which in the 2yrs he's had it, has not had any AV or firewall !!!! managed to update any that needed updating and rebooted into safe mode. ran all the apps in safe mode...and they all found huge amount of trojans, virus, spyware, adware...and spyaxe, and appeared to succesfully remove anything that needed removal,and i also renamed the svchosts.dll file... checked the homepage setting via ctrl panel and ms antispyware advanced tools, and everything seemed cool rebooted pc... up poped the spyaxe scanner and additional spyaxe popups!!! msconfig shows nothing suspicious? anyways am currently working my way through the info on this site http://forums.spywareinfo.com/index....=&#entry325148

will let u guys know how i get off with it..

---------- Post added at 02:08 ---------- Previous post was at 01:03 ----------

well... looks to have done the trick. went through the step by step info on the link above... took a while, mainly due to the duration of the ewido scan... but so far all seems sweet
__________________
"This product that was on TV was available for four easy payments of $19.95. I would like a product that was available for three easy payments and one complicated payment. We can't tell you which payment it is, but one of these payments is going to be hard."
50420 is offline   Reply With Quote
Old 13-12-2005, 06:21   #7
antispy
Inactive
 
Join Date: Dec 2005
Posts: 1
antispy is an unknown quantity at this point
Re: SpyAxe 3.0 Malware...

here is spyaxe removal guide: manual spyaxe removal
antispy is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Google Search




All times are GMT. The time now is 16:03.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.
Copyright © 2003 - 2012, Cable Forum.
(server9.cableforum.co.uk)

SEO by vBSEO 3.3.2