Tilted Forum Project Discussion Community  

Go Back   Tilted Forum Project Discussion Community > Interests > Tilted Technology


 
 
LinkBack Thread Tools
Old 12-03-2005, 03:57 PM   #1 (permalink)
Lennonite Priest
 
pan6467's Avatar
 
Location: Mansfield, Ohio USA
Spyaxe & Spyware Doctor destroying it.

I was surfing and came across this doozy of a bad bug. It goes nuts with your system. you keep getting a warning from your microsoft bullseye (if you have MS antispyware) telling you that you've been infected. Every time you click it you go to "spyaxe's" website.

From what I have read on sites after being infected and getting rid of it, Spyaxe is a fast growing malware that is truly nasty. I did a search to see if anyone else has posted anything about it, but noone had soooooo....

The infected balloon just keeps coming up.

Norton goes crazy, NOTHING I had seemed to even touch it.

This thing blocks websites (switching browsers tho worked), it truly seemed to take over.

What I did was went in removed it through the start. Did a quick search found http://www.thex.com/rd/2005/11/26/firefox-spyaxe and went there. He tells you how to get rid of it, but Hell I don't even know how to get into safe mode. (His way listed at end of post, for those of you who know what to do and how.)

So I searched again, found Spyware Doctor did the scan, it found 127 nasties including Spyaxe. Now it cost $29.95 but had great reviews from what I could tell. I bought it..... wham bam everything including spyaxe is gone.

Anyone know about either? Is Spyware Doctor as good as it seems or am I a sucker for buying it?

Here's the site's way to get rid of Spyaxe for you tech geeks who can know what you're doing and can just go in and bing bam boom take care of the nasty.

Quote:
FireFox - SpyAxe
I was just browsing happily away, secure in the knowledge that FireFox is a much better browser than any other. It generally blocks pop-ups and so on, is more secure than any other, but ‘lo what happens?

My FireFox browser shuts itself down without any warning. Then I look on my desktop, and I see a program called “SpyAxe” had been installed!! Without my say-so no less! Looking on the toolbar, I see two new icons next to my sound controls, network icon, panda anti-virus. The strange thing is, one is exactly like the Windows Update icon. It’s flashing, telling me spyware has been detected.

So I think to myself, how could this happen? Something fishy here. I run Panda, and its found two virii so far. I’ll run Spybot next. How could this happen when I’m running Firefox? I thought it asks if you download something, and certainly isn’t supposed to install things without asking!

Update: I saw a thread over at Spyware Warrior, talking about SpyAxe. One of the commenters said I didn’t post what I was doing so here is the update. I use FireFox for everything, browing blogs, my own coding (nothing nefarious, mostly blog coding, site coding). At the time I think I had Technorati, some computer security sites open (I was writing articles on Networks & Security), and some blogs that I clicked on from BOTD. Now it could be that one of those was “set up” to give out versions of SpyAxe, not sure. Also, I have no FireFox extensions, no 2nd party additions - I use a naked FireFox.

Anyway, here is the process I took to get rid of the SpyAxe *cursing noises*, so others can do it for themselves.

Download HiJackThis;
Reboot the computer into safe mode;
When in Safe Mode, remove SpyAxe.
Run HiJackThis, my “infection” was HomepageBHO, delete it;
Run regedit and find this key:
HKEY_LOCAL_MACHINE\
SOFTWARE\
Microsoft\
Windows\
CurrentVersion\
policies\
Explorer\
run

You’re looking for the mssearchnet and nvctrl entries - delete them outright (right click, delete).

Reboot


That’s what fixed it for me. If this works for you, add a comment to the thread. If not, say so, we can work on it some more.
I hope this helps all who need it......

But I also hope to see some posts that give honest reviews of Spyware Doctor, also.
__________________
I just love people who use the excuse "I use/do this because I LOVE the feeling/joy/happiness it brings me" and expect you to be ok with that as you watch them destroy their life blindly following. My response is, "I like to put forks in an eletrical socket, just LOVE that feeling, can't ever get enough of it, so will you let me put this copper fork in that electric socket?"

Last edited by pan6467; 12-03-2005 at 04:01 PM..
pan6467 is offline  
Old 12-03-2005, 05:03 PM   #2 (permalink)
Addict
 
For future reference: you press F8 during the bootup sequence to get several options, then from those you can choose to boot into safe mode.
phukraut is offline  
Old 12-03-2005, 05:08 PM   #3 (permalink)
Lennonite Priest
 
pan6467's Avatar
 
Location: Mansfield, Ohio USA
Thank you Phukraut. Hope my info has helped you, I will write yours down so I'll know what to do.
__________________
I just love people who use the excuse "I use/do this because I LOVE the feeling/joy/happiness it brings me" and expect you to be ok with that as you watch them destroy their life blindly following. My response is, "I like to put forks in an eletrical socket, just LOVE that feeling, can't ever get enough of it, so will you let me put this copper fork in that electric socket?"
pan6467 is offline  
Old 12-04-2005, 11:37 AM   #4 (permalink)
Husband of Seamaiden
 
Lucifer's Avatar
 
Location: Nova Scotia
I just had this happen to me too on Friday night. Clicked on a picture, and Blam! two new icons on my desktop, and the browser hijacked over to the spyaxe website. I kept getting a pop-up box on re-boots telling me to uninstall norton antivirus and re-install, and I couldn't get rid of the icons. I used Norton's Go-back to restore my system to an earlier time, and everything seems to be ok now. But I'll follow your tips to make sure everything is gone
__________________
I am a brother to dragons, and a companion to owls.
- Job 30:29

1123, 6536, 5321
Lucifer is offline  
Old 12-04-2005, 03:41 PM   #5 (permalink)
Addict
 
I'd also recommend getting a program called SpywareBlaster. You run it, say once a week, and it gives you kind of flu shot against nasties. It writes dummy entries into your registry so that when a malware wants to do something to it, like install itself as a BHO as the above example, it gets sterilized. The nice thing about it is that you don't run it constantly. You run, innoculate, and shut down the program.
phukraut is offline  
Old 12-04-2005, 04:42 PM   #6 (permalink)
Junkie
 
MontanaXVI's Avatar
 
Location: Go A's!!!!
I would say that the ms antispyware is supposed to block such a thing from happening, kind of like the pay version of ad aware it has the real time protections to prevent things from taking over like this. Are all your definition files up to date and all the protections that you have enabled?
__________________
Spank you very much
MontanaXVI is offline  
Old 12-04-2005, 06:54 PM   #7 (permalink)
Lennonite Priest
 
pan6467's Avatar
 
Location: Mansfield, Ohio USA
Quote:
Originally Posted by MontanaXVI
I would say that the ms antispyware is supposed to block such a thing from happening, kind of like the pay version of ad aware it has the real time protections to prevent things from taking over like this. Are all your definition files up to date and all the protections that you have enabled?
Mine were. I check for updates at least 2-3 times a week on MSN Beta and this thing just took over.

The way it acted (and grant you I am computer illetrate in many ways), it seemed to me that it targeted my MSN AntiSpyware as it changed the little bullseye icon, it changed the desktop icon and when I would hit what was my MSN it would take me to their site.

Perhaps there is a flaw or backdoor in the MSN anti-spyware that Spyaxe focuses on and can attach itself to.

All I know is that Spyware Doctor took care of my problem and whatever else was in there because my computer is faster now that I installed it and had it do its thing.
__________________
I just love people who use the excuse "I use/do this because I LOVE the feeling/joy/happiness it brings me" and expect you to be ok with that as you watch them destroy their life blindly following. My response is, "I like to put forks in an eletrical socket, just LOVE that feeling, can't ever get enough of it, so will you let me put this copper fork in that electric socket?"
pan6467 is offline  
Old 12-04-2005, 10:51 PM   #8 (permalink)
Junkie
 
MontanaXVI's Avatar
 
Location: Go A's!!!!
this is going to sound really bad, but the curious side of me kinda wants to see how badass this Spyaxe is for myself and if my current security checks are enough.
__________________
Spank you very much
MontanaXVI is offline  
Old 12-04-2005, 10:59 PM   #9 (permalink)
Insane
 
Location: Somewhere in East Texas
Do you recall what website you contacted this bug from? I sort of feel like Montana in that I'd like to see if I am well protected. I am currently running MS Anti-Spyware, Spybot S&D, and Pest Patrol...in addiction to my firewall.

...Glad to got rid of your problem though...sounded like a real pain in the ass.
__________________
...A Bad Day of Fishing is Better Than a Great Day at Work!
texxasco is offline  
Old 12-04-2005, 11:48 PM   #10 (permalink)
Junkie
 
MontanaXVI's Avatar
 
Location: Go A's!!!!
I got symantec client security installed here, which includes symantec av (better than norton not the memory hog norton is, even though both made by same company) symantec personal firewall, along with the usual spybot and ad aware.


I personally am not a fan of the MS anti spyware as it kept crashing on me, since it is just a beta give it time or wait on a newer release and I might be happier.
__________________
Spank you very much
MontanaXVI is offline  
Old 12-05-2005, 12:21 AM   #11 (permalink)
seeker
 
Location: home
I use the spyware warrior web site to verify a good anti spyware product.
Spyware Doctor is on their trusted list:
http://www.spywarewarrior.com/rogue_...tm#trustworthy

the rouge anti spyware programs outnumber the good atleast 50 to 1:
http://www.spywarewarrior.com/rogue_...e.htm#products

my personal setup is:
Ad aware SE free version
Zone alarm firewall
Norton anti virus
Proxomitron../proxy/pop up stopper/java filter and more
a good hosts file
frequent updates of all above + windows updates
No problems in several years......Knock on wood
__________________
All ideas in this communication are sole property of the voices in my head. (C) 2005, 2006, 2007, 2008, 2009
"The Voices" (TM). All rights reserved.
alpha phi is offline  
Old 12-05-2005, 04:26 AM   #12 (permalink)
Husband of Seamaiden
 
Lucifer's Avatar
 
Location: Nova Scotia
Quote:
Originally Posted by MontanaXVI
this is going to sound really bad, but the curious side of me kinda wants to see how badass this Spyaxe is for myself and if my current security checks are enough.


okay, don't say we didn't warn you. better have a ghost image of your drive before you go out searching. I don't remember exactly where I was when I got it, but I'd wager that if you cruised around some links from the "Links" Forum, you'd pick it up before long
__________________
I am a brother to dragons, and a companion to owls.
- Job 30:29

1123, 6536, 5321
Lucifer is offline  
Old 12-05-2005, 04:28 AM   #13 (permalink)
Husband of Seamaiden
 
Lucifer's Avatar
 
Location: Nova Scotia
Btw, I use Sunbelt's Counterspy, Spybot S&D, Ad Aware, and I have two hardware firewalls and a software firewall, Norton Systemworks; and this bugger still nailed me before I could blink.
__________________
I am a brother to dragons, and a companion to owls.
- Job 30:29

1123, 6536, 5321
Lucifer is offline  
Old 12-05-2005, 05:51 AM   #14 (permalink)
Master of No Domains
 
portwineboy's Avatar
 
Location: WEEhawken, New Joisey
There is a sticky "tons of popups, homepage changed?" that has the aggregate info on spyware and recommended programs. Check it out.

I would never pay for a spyware removal program because as someone else said, many of them are actually more malware.
__________________
If you can read this, thank a teacher.
If you can read this in English, thank a veteran.
portwineboy is offline  
Old 12-05-2005, 06:11 AM   #15 (permalink)
Husband of Seamaiden
 
Lucifer's Avatar
 
Location: Nova Scotia
I paid for Counterspy, and I'm glad I did, but I would never buy from a site that had hijacked my browser in order to sell it's product.
__________________
I am a brother to dragons, and a companion to owls.
- Job 30:29

1123, 6536, 5321
Lucifer is offline  
Old 12-05-2005, 08:13 AM   #16 (permalink)
Lennonite Priest
 
pan6467's Avatar
 
Location: Mansfield, Ohio USA
Quote:
Originally Posted by portwineboy
There is a sticky "tons of popups, homepage changed?" that has the aggregate info on spyware and recommended programs. Check it out.

I would never pay for a spyware removal program because as someone else said, many of them are actually more malware.
I have Adware, Norton systemworks, MSN AntiSpyware Beta, S&D, Blaster and none of them helped me.

Spyware Doctor takes awhile to go through the system but it has done wonders for me. For peace of mind and to save my computer it is well worth the $29.95, even if my budget is tight, it'll save me from more expensive problems..... well at least I'm hoping it does.
__________________
I just love people who use the excuse "I use/do this because I LOVE the feeling/joy/happiness it brings me" and expect you to be ok with that as you watch them destroy their life blindly following. My response is, "I like to put forks in an eletrical socket, just LOVE that feeling, can't ever get enough of it, so will you let me put this copper fork in that electric socket?"
pan6467 is offline  
Old 12-05-2005, 08:20 AM   #17 (permalink)
Registered User
 
I paid for Spy Sweeper and wouldn't recommend anything else. It's never let me down.

also here's a fix for the spyaxe stuff

http://noahdfear.geekstogo.com/click...click.php?id=8

I haven't used it but it's distributed by the geekstogo guys who seem to do pretty well with this sort of thing

Last edited by Glory's Sun; 12-05-2005 at 08:23 AM..
Glory's Sun is offline  
 

Tags
destroying, doctor, spyaxe, spyware


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -8. The time now is 09:44 PM.

Tilted Forum Project

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0 PL2
© 2002-2012 Tilted Forum Project

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360