New threat: Spyaxe

Discussion in 'other security issues & news' started by uclajd, Nov 9, 2005.

Thread Status:
Not open for further replies.
  1. illukka

    illukka Spyware Fighter

    Joined:
    Jun 23, 2003
    Posts:
    633
    Location:
    S.A.V.O
    can you check winlogon.exe properties, post them here, thank you
    also i'd like you to scan that file with jottis malware scan, http://virusscan.jotti.org

    see above, if there is something odd at your winlogon.exe, could you upload it to http://www.thespykiller.co.uk/forum/index.php?board=1.0

    see instructions for uploading here:
    http://www.thespykiller.co.uk/forum/index.php?topic=5.0

    thank you in advance

    edit: Jim, i would like to see your hijackthis log, see this page for info:
    http://www.tomcoyote.org/hjt/

    other victims see here:
    https://www.wilderssecurity.com/showthread.php?t=42148
     
  2. garney

    garney Guest

    spyaxe removal explanation and instructions here:
    spyaxe
     
  3. How I dealed with Spyaxe

    I dealed with spyaxe simply by downloading a free trial of Spy Sweeper. I ran a sweep, it caught SpyAxe, then told me to reboot. I rebooted a minute ago, and lo and behold, I have no annoying little popup at the corner of my screen, and my homepage is back to normal.

    Why waste time with dangerous file deletion when Spy Sweeper can do it for you?
     
  4. ugnius

    ugnius Registered Member

    Joined:
    Aug 20, 2004
    Posts:
    2
  5. Iluvporn

    Iluvporn Guest

    Huzzah SPYAXE axed!
     
  6. NewbyName

    NewbyName Guest

    Re: New threat: Spyaxe (.bat->.cmd)

    This advice worked for me ...

    >Spyware Expert Noahdfear has made a tool to remove this infection:
    >download smitRem.exe from
    >http://noahdfear.geekstogo.com/click...click.php?id=1

    ... BUT the RunThis.bat file wouldn't run on my XP Pro system, until
    I renamed it to RunThis.cmd (inspired by a French version of this file
    I found elsewhere).

    Hope this helps anyone else out there with the same problem.

    Cheers
     
  7. Zhen-Xjell

    Zhen-Xjell Security Expert

    Joined:
    Feb 8, 2002
    Posts:
    1,397
    Location:
    Ohio
  8. 71euy

    71euy Guest

    SPYAXE SUCKS!

    Dont go anywhere near this product that purports to be a free malware scanner. I did and even taking advised steps to clear it, it kept re spawning, coming up with multiple pop ups and incescent warning that my PC was infected. Yes it was Spyaxe! Going to their site for the removal tool did not allow me to download it - a pure scam. This is a gotU product in an effort to make you buy their product. After 2 or 3 hours trying to remove it from various program files and many registry entries I was still getting problems.

    I tried Norton, Spybot and Adaware all to no avail although they did remove some files. Finally I dowloaded PC Tools Spyware Doctor - a first class product that finally deleted all the malware etc that had been installed from SpyAxe.

    This was money well spent on Spyware Doctor as it clered up some other issues but most importantly includes "On Guard" to protect from other companies and downloads similar to SpyAXE.

    Wll Spaxe refund the cost of Spyware Doctor? I think not as they are abunch of crooks.
     
  9. sienaworld

    sienaworld Guest

    Hi,

    Tried all the various solutions to the SpyAxe problem, nothing worked, including all the older downloadable fixes and uninstallers -- this must be one of the new ones -- managed to find my way through MSInfo to a solution which seems to have worked for me.

    I found that the file "wbeconm.dll" located in the folder c:\windows\system32 was creating the annoying pop-up taskbar message. This can actually be located and renamed without any recourse on your computer and seems to solve the problem. However, we found that the SpyAxe initial installation, even if not completed, leaves a trojan called Trojan.Zlob.D which creates fake entries in the registry at:

    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

    Delete the file located in the string 'Kernel32.dll - [file name]' then delete the entry in the registry, check any others here as well (I found the others were problems too).

    Cheers.
     
  10. peeved

    peeved Guest

    Has anybody come up with a solution to this latest version of Spyaxe? Because it is really messing up my week.
     
  11. Blackspear

    Blackspear Global Moderator

    Joined:
    Dec 2, 2002
    Posts:
    15,115
    Location:
    Gold Coast, Queensland, Australia
    Have you tried the link in this post?
    It takes you through to this link of which I have used the enclosed tool successfully to remove spyaxe/smitfraud.

    Let us know how you go...

    Cheers :D
     
  12. Stoffel

    Stoffel Guest

    Hello,

    I've been attacked with this stupid thingy as well since yesterday afternoon.

    I've litterally tried everything proposed here, but nothing worked... it keeps coming back!
    I assume it must be a new version which smitRem doesn't remove?
    (BTW, the links to smitRem are dead this morning...?)

    Here's my HT-log, I hope someone can help me!
    THX

    ~snip~ removed HJT Log
     
    Last edited by a moderator: Dec 28, 2005
  13. Blackspear

    Blackspear Global Moderator

    Joined:
    Dec 2, 2002
    Posts:
    15,115
    Location:
    Gold Coast, Queensland, Australia
    Hi Stoffel, have you followed the instructions in my post above yours?

    Cheers :D
     
  14. Stoffel

    Stoffel Guest

    That's what I tried, yes... didn't work though.

    When I try to run the smitRem-tool, I see lots of "not found"-thingies appearing and stuff... but it doesn't remove SpyAxe :(
     
  15. Blackspear

    Blackspear Global Moderator

    Joined:
    Dec 2, 2002
    Posts:
    15,115
    Location:
    Gold Coast, Queensland, Australia
    And this was done in Safe Mode? The instructions have to be followed precisely or they will not work.

    Cheers :D
     
  16. Stoffel

    Stoffel Guest

    Hi :)

    Yes, I did it in Safe Mode ;)


    But I've found another solution now!
    sienaworld wrote about it a bit earlier as well... I had to remove the wbeconm.dll first!

    When I did that, the smitRem-tool and Ewido solved the problem.
    (It wouldn't work without removing that dll though)

    Afterwards, I also removed all values containing the name "SpyAxe" in the register.
    And I removed all folders and files on my computer also containing that name.

    And now it doesn't seem to come back... so: yippee :D


    THX! :)
     
  17. neophyte

    neophyte Guest

    Thanks to all for your postings and help - I just got stung by this piece of turd software. I did the system restore and that seems to have worked. For those like me who are relative novices at pcs here is what to do in Windows XP:
    - click on the start menu
    - select "help and support"
    - at the top left of this screen, there is a "search" box. In it type "system restore wizard"
    - you will get two options - pick the one that says "Run the System Restore Wizard"
    - choose "restore my computer to an earlier time" and click next
    - you will see a calendar with some dates that are in bold type face. These are the days that you can restore your system to. Pick a date that is before the infection by spyaxe and hit "next" and then follow instructions.
     
  18. i was trying to get rid of the alert for 3 days, after i downloaded the spy sweper, then it is gone. and funny thing is that spy sweeper is free for 14 days. you can download it from their official website. but still my homepage is coverded by their page( securitywarning.net). do u know how i can remove this page fom my cover. one more thing i have scanned my computer with spyware doctor, it says i have still registriesd files left from the spyaxe, but spy sweeper doesnt, how come?
     
  19. In case any of you haven't mentioned it yet, there is a SpyAxe removal tool that can be found at this link:

    http://bleepingcomputer.com/forums/topic/36868.html

    Look for a program called smitRem (Do a search on the web site if needed), and download the file. It removed SpyAxe AND the Trojan that downloaded it.

    Killerbfb12345
     
  20. JonPaulOnLine

    JonPaulOnLine Registered Member

    Joined:
    Aug 10, 2005
    Posts:
    96
    Location:
    Philadelphia PA USA
    Or
    Start
    Programs
    Accessories
    System Restore
    "- choose "restore my computer to an earlier time" and click next"
     
  21. db1234

    db1234 Guest

    system restore worked fine for me, piece o' cake. I run XP Pro...
     
  22. Michigan

    Michigan Guest

    Hi

    It seems that I have got the same kind of new Spy Axe since yesterday morning, struggling to get rid of the sucking spyware. Now that merely using smitRem and ewido under safe mode did not improve the situation, I am trying the way posted above.
    I do find the wbeconm.dll, but unable to remove it. Please help me to show the way to remove it!!
     
  23. LadyDev

    LadyDev Guest

    STOPzilla (www.stopzillia.com) or Spyware Doctor really work. Tried Xoftsoft, spybot, (the trio of Smitfraud, Ewido and Adware SE), McCafee virus plus sypware, Etrust Pest Control, the microsoft spyware to no evail. I am not a spokesperson for Stopzilla, but it worked. Will have to pay a few dollars though when the trial period expires, $19.95.
     
  24. Andrew!

    Andrew! Guest

    " do find the wbeconm.dll, but unable to remove it. Please help me to show the way to remove it!!"

    Im having the same problem, I had it before... had to format my comp... i'm thinking im going to have to do this again!

    Yes im in safe mode... spywear doctor removed everything but the taskbar window.... then it redownloaded itself later
     
  25. sullive

    sullive Guest

    Hi, there!

    You have an enterprising friend, or an anti-enterprising friend. I just need help! This annoying fake has prevented me from getting my usual educational homepage, I have to set up my web page for the spring semester, and Iwant out!

    I can't get in touch with my smart people at my job until after New Year -- you're right -- there should be a lawsuit!!!

    xxx,

    Prof. Sullivan

     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.