Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Spy Axe 3.0
My PC ^ | 12/6/05 | Me

Posted on 12/06/2005 8:16:34 PM PST by Carling

I hate vanity posts, but I am wondering if anyone in FR land knows anything about the Spy Axe 3.0 virus. It has set up shop in my toolbar and has hijacked my home page.

eTrust isn't touching it. Help?!?!


TOPICS: Miscellaneous
KEYWORDS: exploit; getamac; lowqualitycrap; malware; microsoft; securityflaw; spyware; tech; trojan; virus; virusbait; windows
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-8081-88 next last
To: Skooz

I'll ditto that bookmark.


61 posted on 12/06/2005 9:22:28 PM PST by Danette ("If we ever forget that we're one nation under God, then we will be a nation gone under.")
[ Post Reply | Private Reply | To 20 | View Replies]

To: Riley

I love ewido.


62 posted on 12/06/2005 9:24:11 PM PST by Knitting A Conundrum (Act Justly, Love Mercy, and Walk Humbly With God Micah 6:8)
[ Post Reply | Private Reply | To 58 | View Replies]

To: js1138

My Problem is long gone, thanks anyway.

PS: SpyAxe rat survived that scenario also.


63 posted on 12/06/2005 9:25:01 PM PST by JoeSixPack1
[ Post Reply | Private Reply | To 60 | View Replies]

To: JoeSixPack1
Spyaxe is a "RAT", not adware so to speak and not a virus.

Spyware and viruses are two different animals. Generally- viruses are about control and destruction, and spyware is about money; E.G getting ads in your face and tracking your browsing to see what ads are most likely to get you to spend money- and then it puts them in your face.

I haven't fought Spyaxe in particular, but now that it is becoming more widespread- I will 'contaminate' a test unit and play with it.

64 posted on 12/06/2005 9:27:16 PM PST by Riley ("Bother" said Pooh, as he fired the Claymores.)
[ Post Reply | Private Reply | To 59 | View Replies]

To: HairOfTheDog

If you'd care to read my post again you'll see I said ANTI-Spyware programs. Programs that BLOCK any 'nasties' installing themselves, plus all my ports are checked on a regular basis to make sure there's none open and 100% stealth, and I don't have Firefox. I've never had a problem with IE/OE. A computers just like a car, if you don't look after it and do maintenance on a regular basis it'll break down.
I like to check out slimy commicrat sights so I have a headsup on what stupid nonesense to expect from them so I need all the protection I can get.


65 posted on 12/06/2005 9:28:21 PM PST by AmeriBrit (HILLARY's1974 Watergate Crimes: http://www.freerepublic.com/focus/f-news/925684/posts)
[ Post Reply | Private Reply | To 49 | View Replies]

To: AmeriBrit

I read it correctly, I just think it's hilarious that you run NINE different antispyware programs. You don't have spyware, but you've got one heck of a scareware infestation LOL :~D


66 posted on 12/06/2005 9:30:22 PM PST by HairOfTheDog (Join the Hobbit Hole Troop Support - http://freeper.the-hobbit-hole.net/ 1,000 knives and counting!)
[ Post Reply | Private Reply | To 65 | View Replies]

To: Carling

My experience has been that while Adaware can identify the trojan, it cannot clean it up if it cannot stop it. If it is able to stop it and clean it up, it may be re-infecting the computer when it boots by running a front end that checks for the files, and installing them if they do not exist.

Two programs that I have loaded and ready are TaskInfo2003 and Autoruns.

Taskinfo is just that, it shows you the processes that are running on your machine. Google anything that looks suspicious, and find your trojan and kill the process, if possible.

Autoruns shows what the registry starts when Windows boots. Use Google to find your trojan in the list and delete it.

That should knock it off its feet, and Adaware can identify the beast and clean it up


67 posted on 12/06/2005 9:33:17 PM PST by Mr. Quarterpanel (I am not an actor, but I play one on TV)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Carling

Go here
After Spy Axe Removal
http://www.bullguard.com/forum/10/After-Spy-Axe-Removal_24439.html


68 posted on 12/06/2005 9:36:20 PM PST by philetus (What goes around comes around)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Riley

There is an embedded file named msearchnet.exe or something real close to that naming that is the root problem. Undeletable through medium powered attack tools as stated throughout these freeper threads and system protected against simple deletion, but not uncurable.

I went after the file through DOS and was rebuffed twice, so being the excitable type and not wanting to play with it I cursed and reloaded.

I first cleared my task mgr of it. Then the embedded program files in sys dirs. Then it regenerated. I isolated the above file, but like I said, by that time I was into it and close to a cure I needed my blood pressure medicine and went a different route.

Weekly norton ghost backups are a wonderful thing. :-)


69 posted on 12/06/2005 9:36:38 PM PST by JoeSixPack1
[ Post Reply | Private Reply | To 64 | View Replies]

To: JoeSixPack1
Indeed. Sometimes I use a live CD to boot from- so there are no restrictions on file deletion on the C:\ drive.

http://www.nu2.nu/pebuilder/

There's an Adaware plugin for it, as well.

With that- I am long overdue for some shuteye. G'night all.

70 posted on 12/06/2005 9:44:46 PM PST by Riley ("Bother" said Pooh, as he fired the Claymores.)
[ Post Reply | Private Reply | To 69 | View Replies]

To: Skooz

These are good tools, you may also want to try CCleaner first and run them in Safe Mode, restart and hit F8 repeatedly until boot menu appears, choose Safe Mode. Or Safe mode with networking that way you can run http
://housecall.antivirus.com with your Antivirus and really scan for Viruses.


71 posted on 12/06/2005 9:49:54 PM PST by justaguywithaspellchecker
[ Post Reply | Private Reply | To 12 | View Replies]

To: Riley
Sometimes I use a live CD to boot from- so there are no restrictions on file deletion on the C:\ drive.

I was also under this impression and did exactly that, but was confounded again.

Sleep well. :-)

72 posted on 12/06/2005 9:53:16 PM PST by JoeSixPack1
[ Post Reply | Private Reply | To 70 | View Replies]

To: Skooz

Sorry I did not include this in my last response to you but I am a "newbie" :). Spy Axe is a very bad egg, as you try to delete it even in Safe mode it will reinstall itself and rename itself. If you don't have much data you could always run the restore CD and if you do you could put the hard drive in another computer, scan it for Viruses and then copy your favorites, My documents, Address book/Inbox etc. then restore the contaminated hard drive. Well it is definitely past my bedtime. Good night.


73 posted on 12/06/2005 9:56:49 PM PST by justaguywithaspellchecker
[ Post Reply | Private Reply | To 12 | View Replies]

To: AmeriBrit; Carling

I'll tell you somebody else you can depend on, and that's AnnMarie:

http://www.cybertechhelp.com/forums/showthread.php?t=97919


74 posted on 12/06/2005 9:57:53 PM PST by JoJo Gunn (Help control the Leftist population. Have them spayed or neutered. ©)
[ Post Reply | Private Reply | To 18 | View Replies]

To: Carling
It seems like entrapment or unlawful entry.

Spyaxe a clear case of criminal extortion.

For most computer users, there is no good reason put up with these problems. Learning how to use dozens of anti-virus/anti-spyware programs is not a productive use of a computer.

If your time is valuable, get rid of Windows.

75 posted on 12/06/2005 10:04:52 PM PST by HAL9000 (Get a Mac - The Ultimate FReeping Machine)
[ Post Reply | Private Reply | To 31 | View Replies]

To: FEARED MUTATION

Does extensive lurking count toward FR seniority?


76 posted on 12/06/2005 10:10:37 PM PST by ntnychik
[ Post Reply | Private Reply | To 17 | View Replies]

To: ntnychik

Only if you've got the cache to prove it.


77 posted on 12/06/2005 10:12:42 PM PST by FEARED MUTATION
[ Post Reply | Private Reply | To 76 | View Replies]

To: JoJo Gunn

Ann-Marie is, or used to be at www.suggestafix.com also. :>)))


78 posted on 12/06/2005 10:24:35 PM PST by AmeriBrit (HILLARY's1974 Watergate Crimes: http://www.freerepublic.com/focus/f-news/925684/posts)
[ Post Reply | Private Reply | To 74 | View Replies]

To: HAL9000

There's nothing wrong with Windows or IE if you know what your doing. It's those that don't know what they're doing that's the trouble.

I tried a mac for a month and hated it. You can keep your Mac.


79 posted on 12/06/2005 10:32:04 PM PST by AmeriBrit (HILLARY's1974 Watergate Crimes: http://www.freerepublic.com/focus/f-news/925684/posts)
[ Post Reply | Private Reply | To 75 | View Replies]

To: Carling
Google 'spyaxe'... DON'T go to the 'spyaxe.com' site, they made the thing so who trusts them to get rid of it... Other places mention that the active part is called "svchosts.dll" (as differing from legitimate windows 'svchost.exe'). The popup seems to come from a file called "hpE951.tmp". Both reside in the windows/system32 folder. You might try to delete them as they sit, but if they are active, you won't be allowed. Try starting in safe mode and then see if they can be removed. Remember, DO NOT delete svchost.EXE or you won't even be able to get back online!

This is one of the sources for this information I found on Google:

Remove Spyaxe

Hope this is of some help...

80 posted on 12/06/2005 10:53:44 PM PST by NoCmpromiz (John 14:6 is a non-pluaralistic statement.)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-8081-88 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson