Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

UGLY SPYAXE VIRUS ALERT (VANITY)
12-06-2005 | Cawats

Posted on 12/06/2005 6:38:12 PM PST by CAWats

My computer apparently picked up a virus from spyaxe.net. I have a pop-up window saying I have spyware and "it is recommended to use antispyware tools to prevent data loss." Everytime I close the popup it pops up again. I got tired of closing it and installed it then removed it with "Add/Remove Software" in the control panel. The pop-up is back.



Can anyone help?


TOPICS: Miscellaneous
KEYWORDS: exploit; getamac; lowqualitycrap; malware; microsoft; securityflaw; spyaxevirus; spyware; trojan; virus; virusbait; windows
Navigation: use the links below to view more comments.
first 1-5051-62 next last

1 posted on 12/06/2005 6:38:13 PM PST by CAWats
[ Post Reply | Private Reply | View Replies]

To: CAWats

you must have Firefox.


2 posted on 12/06/2005 6:39:49 PM PST by Perdogg ("Facts are stupid things." - President Ronald Wilson Reagan)
[ Post Reply | Private Reply | To 1 | View Replies]

To: CAWats; backhoe

You might want to install SpyBot and run it. It's free. Pinging Backhoe who might have more ideas.


3 posted on 12/06/2005 6:40:24 PM PST by MizSterious (Anonymous sources often means "the voices in my head told me.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: CAWats

http://www.thex.com/rd/2005/11/26/firefox-spyaxe/


4 posted on 12/06/2005 6:40:35 PM PST by Perdogg ("Facts are stupid things." - President Ronald Wilson Reagan)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Perdogg

YES!!


5 posted on 12/06/2005 6:40:44 PM PST by CAWats (People that are easily angered are easily frightened)
[ Post Reply | Private Reply | To 2 | View Replies]

To: CAWats

Is your computer on?


6 posted on 12/06/2005 6:41:01 PM PST by nevergore (“It could be that the purpose of my life is simply to serve as a warning to others.”)
[ Post Reply | Private Reply | To 1 | View Replies]

To: CAWats

also try adaware by lavasoft also free. do it and spybot both.


7 posted on 12/06/2005 6:41:34 PM PST by fatrat
[ Post Reply | Private Reply | To 1 | View Replies]

To: CAWats

I would think that message itself is a spyware wolf-in-sheeps-clothing. It 'says' it's from Windows, but I don't think so...

I'd recommend you download Microsoft Anti-Spyware Beta and give your pc a good cleaning.

http://www.microsoft.com/athome/security/spyware/spywareremove.mspx


8 posted on 12/06/2005 6:42:43 PM PST by Syberyenta
[ Post Reply | Private Reply | To 1 | View Replies]

To: CAWats

I did a Google search, and found this site with some recommendations:

http://www.spywareguide.com/product_show.php?id=2361

If that doesn't work, then I would recommend going to HiJackThis and getting some expert help. They are pretty good with persistent spyware that refused to let itself be deleted.


9 posted on 12/06/2005 6:44:13 PM PST by Cicero (Marcus Tullius)
[ Post Reply | Private Reply | To 1 | View Replies]

To: CAWats

... FWIW I like Spybot and Ad-Aware too. They're also less intrusive.


10 posted on 12/06/2005 6:44:46 PM PST by Syberyenta
[ Post Reply | Private Reply | To 1 | View Replies]

To: Syberyenta

Get a Mac. You don't have to waste your time with this stuff.


11 posted on 12/06/2005 6:46:01 PM PST by sullivan-fan
[ Post Reply | Private Reply | To 10 | View Replies]

To: sullivan-fan

I agree about the Mac. I've got a PowerBook G4 behind a NAT Router, Intego NetBarrier firewall, Norton Antivirus for a belt & suspenders approach. Never had any spyware, virus or trojans. Not one.


12 posted on 12/06/2005 6:48:30 PM PST by ProtectOurFreedom
[ Post Reply | Private Reply | To 11 | View Replies]

To: CAWats
I would also recommend Ad-Aware.  You can get it here

The personal version is free, I believe.

13 posted on 12/06/2005 6:49:10 PM PST by softwarecreator (Facts are to liberals as holy water is to vampires.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: CAWats

Windows let it install, let windows clean it up!


14 posted on 12/06/2005 6:51:02 PM PST by operation clinton cleanup
[ Post Reply | Private Reply | To 1 | View Replies]

To: CAWats

and stop surfing porn sites.


15 posted on 12/06/2005 6:51:07 PM PST by FEARED MUTATION
[ Post Reply | Private Reply | To 1 | View Replies]

To: All

Thanks for all the help!!


16 posted on 12/06/2005 6:51:12 PM PST by CAWats (People that are easily angered are easily frightened)
[ Post Reply | Private Reply | To 12 | View Replies]

To: sullivan-fan
I have Windows with a firewall.  I also don't have to worry about this stuff.
17 posted on 12/06/2005 6:51:14 PM PST by softwarecreator (Facts are to liberals as holy water is to vampires.)
[ Post Reply | Private Reply | To 11 | View Replies]

To: CAWats
I was just on the phone with my dad for two hours because he got this Spyaxe crap.

Trust me - Adaware, MS Anti-Spyware, Spybot S&D - none of them get rid of it. They look like they might, but don't. Adaware finds it and says it will delete it, but it comes back.

The instructions I found say to start Windows in safe mode (press F8 while booting), then delete the file svchosts.dll (not svchost.exe) from c:\windows\system32, then run Adaware or some other scanner that knows about Spyaxe.

Sometimes you can't delete svchosts.dll and you need a program like killbox.exe (Google it) because the dll is in memory and locked.

There is also a SpyAxeFix.exe out there that will supposedly get rid of it.

I haven't tried any of these things yet - I am heading over to his house tomorrow night to try them. Trying to talk him (actually anyone) through the instructions is painful when you can't see what is going on.

You could give this guy some grief...

Domain name: SPYAXE.COM

Registrant Contact:

U-12
Joshua Veronimo (admin@spyaxe.net) +632.8323123 Fax: +632.8323123 U-12 Gamma Commercial Complex # 47 Rizal Highway cor. Manila
Olongapo City, 1300
PH

Administrative Contact:
U-12
Joshua Veronimo (admin@spyaxe.net)
+632.8323123
Fax: +632.8323123
U-12 Gamma Commercial Complex # 47 Rizal Highway cor. Manila
Olongapo City, 1300
PH

18 posted on 12/06/2005 6:52:19 PM PST by Mannaggia l'America
[ Post Reply | Private Reply | To 1 | View Replies]

To: FEARED MUTATION
and stop surfing porn sites.

..yeah bumps and grins make for nnnnaarrrley waves man

Doogle

19 posted on 12/06/2005 6:55:41 PM PST by Doogle (USAF...7thAF ..4077th TFW...408th MMS..Ubon Thailand.."69",,Night Line Delivery..AMMO)
[ Post Reply | Private Reply | To 15 | View Replies]

To: nevergore

My computer isn't on, but it is running.


Should I try to catch it?


20 posted on 12/06/2005 6:55:47 PM PST by spinestein (All journalists today are paid advocates for someone's agenda.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Mannaggia l'America
haven't tried any of these things yet - I am heading over to his house tomorrow night to try them. Trying to talk him (actually anyone) through the instructions is painful when you can't see what is going on.

Please let me know what happens!

21 posted on 12/06/2005 6:56:09 PM PST by CAWats (People that are easily angered are easily frightened)
[ Post Reply | Private Reply | To 18 | View Replies]

To: softwarecreator
I have Windows with a firewall. I also don't have to worry about this stuff.

Hate to tell you, but generally a firewall only stops incoming connections. It won't stop drive-by-downloads, unless your firewall has content filtering and knows about this particular spyware/malware. Reports are that this comes in as baggage in a codec download. If you choose to download the codec (and I'm not even sure if you are asked, especially if Media Player is configured for automatic codec downloads), it's normal http traffic and a firewall won't stop it.

My dad got this Spyaxe today, and I set up his system and he does have a firewall and anti-virus softare and anti-spyware software - and it got through. I can't say whether or not he did something dumb to let it download or not, but nothing stopped it.

22 posted on 12/06/2005 6:58:29 PM PST by Mannaggia l'America
[ Post Reply | Private Reply | To 17 | View Replies]

Comment #23 Removed by Moderator

To: FEARED MUTATION

and stop surfing porn sites.

I don't goto moveon.org


24 posted on 12/06/2005 6:59:03 PM PST by CAWats (People that are easily angered are easily frightened)
[ Post Reply | Private Reply | To 15 | View Replies]

To: CAWats

Ah! Hahaha! Good attitude! :)


25 posted on 12/06/2005 7:01:15 PM PST by FEARED MUTATION
[ Post Reply | Private Reply | To 24 | View Replies]

To: CAWats

You really need to do some homework.

If you have a firewall you might look to see how to eliminate traffic from that address. I switched to Zone Alarm and it would remove it.


26 posted on 12/06/2005 7:02:24 PM PST by JustAnotherOkie
[ Post Reply | Private Reply | To 1 | View Replies]

To: operation clinton cleanup

Windows let it install, let windows clean it up!

I tried that. It didn't work. (and it installed itself anyway!!)


27 posted on 12/06/2005 7:07:06 PM PST by CAWats (People that are easily angered are easily frightened)
[ Post Reply | Private Reply | To 14 | View Replies]

To: CAWats

If all else fails reboot your machine in safe mode then run your spy ware. This will sometimes get rid of these pesky pop-ups


28 posted on 12/06/2005 7:16:42 PM PST by Crackhead Willie
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

ping


29 posted on 12/06/2005 7:25:09 PM PST by JoJo Gunn (Help control the Leftist population. Have them spayed or neutered. ©)
[ Post Reply | Private Reply | To 1 | View Replies]

To: CAWats

--b--


30 posted on 12/06/2005 7:26:31 PM PST by rellimpank (Don't believe anything about firearms or explosives stated by the mass media---NRABenefactor)
[ Post Reply | Private Reply | To 1 | View Replies]

To: sullivan-fan; ProtectOurFreedom

Come on guys, don't do that. I am a lifelong mac user and advocate, but when people post things like this, they don't want to hear "get a mac".

I agree with you, and don't even use virus protection, but this guy is looking for a solution to the problem he's got.

I hate it when people come into a mac thread and jump on with their usual remarks that have nothing to do with the subject at hand. Let's not do it to them.


31 posted on 12/06/2005 7:29:21 PM PST by rlmorel ("Innocence seldom utters outraged shrieks. Guilt does." Whittaker Chambers)
[ Post Reply | Private Reply | To 11 | View Replies]

To: CAWats

Almost half of all Internet use is directed toward porn sites.

The virus producers know this, and a high percentage of virus, worms and trojans come from porn sites.

Many others come from emails. My anti-virus stopped a virus today. I got an email about "your new user name and password". Since I just had to get a new user name and password for a credit card I lost, I thought this was legit. As soon as I opened the file, my anti-virus program caught it and I was able to delete the file before downloading.

1] I am not saying you visit porn sites, but about half of all time spent on the Internet is at porn sites.

2] Get a AV program and make sure it is up to date.

Even though I have my AV program set for auto-updates, I do Live Update every single time I start my computer.

3] Do not open ANY email that you are not 100% sure is legit.

This all sounds simple, but even the "pros" get caught now and then by letting their guard down.


32 posted on 12/06/2005 7:34:20 PM PST by Dont_Tread_On_Me_888 (Bush's #1 priority Africa. #2 priority appease Fox and Mexico . . . USA priority #64.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: CAWats

I had one of these last year that about drove me crazy....but I prevailed. You might want to post your problem or read one of the many computer forums on the net. That is the approach I took.

Just do a google search for computer forums.


33 posted on 12/06/2005 7:55:16 PM PST by TheLion
[ Post Reply | Private Reply | To 1 | View Replies]

To: CAWats

Yo should try the program called Hijack This. Be careful though. It also displays legitiment registry entries.


34 posted on 12/06/2005 7:56:23 PM PST by Paul_Denton (The U.S. should adopt the policy of Oom Shmoom: Israeli policy where no one gives a sh*t about U.N.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Mannaggia l'America
Hate to tell you but I've not had an "intrusion" in over 3 years.

You make a good point, though, most viruses are let in because users open themselves up to the potential.

Glad to know you got rid of "SpyAxe".  People who create spyware and pop-ups should face the same penalties as those who create viruses.

35 posted on 12/06/2005 7:57:02 PM PST by softwarecreator (Facts are to liberals as holy water is to vampires.)
[ Post Reply | Private Reply | To 22 | View Replies]

To: ProtectOurFreedom
I agree about the Mac. I've got a PowerBook G4 behind a NAT Router

bump that !

Got Unix ?

36 posted on 12/06/2005 8:04:09 PM PST by XeniaSt (Y'shua <==> YHvH is my Salvation (Psalm 118-14))
[ Post Reply | Private Reply | To 12 | View Replies]

To: softwarecreator

True. Most computer viruses are spread by human behavior patterns.


37 posted on 12/06/2005 8:13:22 PM PST by rlmorel ("Innocence seldom utters outraged shrieks. Guilt does." Whittaker Chambers)
[ Post Reply | Private Reply | To 35 | View Replies]

To: CAWats
Get Spybot, Adaware and Spyware Blaster. They are all FREE. Download them, update them then run them. Spyware Blaster runs constantly in background. It needs to be updated about once a week. It blocks spyware from being installed. Spybot, and Adaware have to be run but Windows can schedule the to run. They should be updated weekly. Also there is the beta version of Microsoft's program It used to be called Microsoft Defender. You can download and install that as well. you need more than one program to hunt for spyware. Zone Alarm Pro also has a built in spyware program.
38 posted on 12/06/2005 8:23:05 PM PST by airedale ( XZ)
[ Post Reply | Private Reply | To 1 | View Replies]

To: CAWats
The pop-up is back.

I can tell you how to get rid of the popup...but not the SpyAxe.

39 posted on 12/06/2005 8:55:03 PM PST by Bloody Sam Roberts (This is my tagline. There are many like it but this one is mine.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: CAWats

Check freep mail please. :-)


40 posted on 12/06/2005 9:08:18 PM PST by JoeSixPack1
[ Post Reply | Private Reply | To 1 | View Replies]

To: rlmorel

You are right, of course. But you never know when somebody is thinking about making a change, especially during the Christmas season.

I've used PCs for years at work and always keep up with latest OS and browser patches, keep antispyware tools running, defrag, clean up registry, keep AV running. I've had pretty good luck keeping my machines clean, but I understand how awful it can be when you've something like this. It may be such a deeply buried and hidden rootkit that the only solution is to reinstall Windows.


41 posted on 12/06/2005 9:11:14 PM PST by ProtectOurFreedom
[ Post Reply | Private Reply | To 31 | View Replies]

To: spinestein

Only if you find it running to Windows......


42 posted on 12/06/2005 9:17:43 PM PST by nevergore (“It could be that the purpose of my life is simply to serve as a warning to others.”)
[ Post Reply | Private Reply | To 20 | View Replies]

To: CAWats

bumping in case I catch it.


43 posted on 12/06/2005 9:19:16 PM PST by Danette ("If we ever forget that we're one nation under God, then we will be a nation gone under.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: CAWats
Still have this?

Google 'spyaxe'... DON'T go to the 'spyaxe.com' site, they made the thing so who trusts them to get rid of it... Other places mention that the active part is called "svchosts.dll" (as differing from legitimate windows 'svchost.exe'). The popup seems to come from a file called "hpE951.tmp". Both reside in the windows/system32 folder. You might try to delete them as they sit, but if they are active, you won't be allowed. Try starting in safe mode and then see if they can be removed. Remember, DO NOT delete svchost.EXE or you won't even be able to get back online!

This is one of the sources for this information I found on Google:

Remove Spyaxe

Hope this is of some help...

44 posted on 12/06/2005 9:52:08 PM PST by NoCmpromiz (John 14:6 is a non-pluaralistic statement.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: airedale
Spybot, Adaware and Spyware Blaster

I use both AdAware and Spybot S&D. It seems though that as of right now, neither of these find or remove this.

45 posted on 12/06/2005 9:54:53 PM PST by NoCmpromiz (John 14:6 is a non-pluaralistic statement.)
[ Post Reply | Private Reply | To 38 | View Replies]

To: NoCmpromiz
Download the beta version of Microsoft Defender it's now called: Windows AntiSpyware (Beta)The URL is http://www.microsoft.com/athome/security/spyware/software/default.mspx. You might see if Symantec or McAfee or other firm has a test version of their anti-spyware software. If they do download and install it and see what they find. You can always delete it. If that doesn't work use your news browser (part of Outlook Express or Outlook) and go to grc.com and post your message on their BBS in the spyware section. It's a site for people who are very very interested in security and tech matters. You'll get some good advice. If your not familar with newsgroups just remember they are public and the spambots can find a real e-mail address. When you set up your e-mail address for the newsreader use something phony like nospam@nospam.com That way you won't attract spam. It also means you can only get a reply at the newsgroup.

You might pick up Process Explorer at Systemeinternals.com and see what is running. Second go to grc.com's website and pick up leaktest and see if you have something that's opened a whole in your system which allows stuff in and out around your firewall. Third go to your start menu and then Run Insert MSCONFIG See what's in the Startup section. See what's being started when you boot up. If you uncheck a box it won't start up the next time you boot up. If you recheck the box it will start the next time you boot up.
46 posted on 12/06/2005 10:50:18 PM PST by airedale ( XZ)
[ Post Reply | Private Reply | To 45 | View Replies]

To: airedale
Umm, thanks Airedale... But I don't have the problem, just posted some info I found on the problem and noted that as of yet AdAware and Spybot S&D don't find this thing. Also, Symantec's site says they don't know anything called Spyaxe.. I am assuming that this will change as this thing gets more well known (and it seems to be spreading as there is another thread on this that started up about 3 hours after this one did...)

I have Process Explorer, have Zone Alarm pro and keep my stuff updated, use Norton 2005 which detects 'threats'.. I haven't picked up anything on my machine in 7 years...

Now, my daughter managed to get something on her machine (we suspect it was on an .mp3 she listened to) but Norton grabbed it when it tried to execute when the machine was next restarted. It just took a bit of convincing to get it out of there since it acted like a rootkit.. (Scared her enough to make her quit using IE though!) I'm going to be watching this one, since it seems to be 'off the radar' as far as the spyware/virus/adware people are concerned.

Oh, and as for things Microsoft... I've had very unpleasant experiences with MS betas and I will never use another one no matter how inviting. I follow the rule "don't install any MS software until SP1..."

However, I am sure that your comments will be of help to others... (probably a good thing you didn't mention mucking around in the reg HKLM/software/windows/etc/etc/etc stuff! Imagine the mess they could get themselves in doing that!)

47 posted on 12/06/2005 11:18:25 PM PST by NoCmpromiz (John 14:6 is a non-pluaralistic statement.)
[ Post Reply | Private Reply | To 46 | View Replies]

To: CAWats
I've been doing some more searching since my last reply. Here is what seems to be a more thorough description of what you need:

SpyAxe removal instructions

48 posted on 12/06/2005 11:26:28 PM PST by NoCmpromiz (John 14:6 is a non-pluaralistic statement.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: CAWats; All
 
Things you need--(all FREE)
Anti-Virus
AVG Anti-Virus version 7 (free) release available...
 Avast
Firewall
Kerio(Direct Download) Zone Alarm
 If are using zone alarm it may slow your PC. Try Outpost Firewall http://www.agnitum.com/products/outpost or Sygate Firewall http://www.sygate.com/ both have FREE and Pro versions and are heads above ZA.
Misc.
IE Spyads SpywareBlaster Spyware Guard
Windows Update- you must keep updated, it is the start of a secure system-
get all CRITICAL Updates

Things you want(Still Free)
 
 Get Firefox I use Firefox. Click the link and give it a try.
 
 

Ad-Aware
Spybot S&D
SpywareBlaster
MS MVP Hosts file
Mike Lin's Homepage and get the Startup Control Panel and Startup Monitor tools.
 
The best forum for malware removal:
-SWI Forums-
 
 
http://www.freerepublic.com/focus/f-news/1315720/posts
 Microsoft Releases Anti-Spyware Beta 1 To Public Today.
Microsoft.com ^
 
=================================================
 
 
 
Browser Wars, take two
various FR links | 12-22-04 | The Heavy Equipment Guy
http://www.freerepublic.com/focus/f-news/1306815/posts

...and let your compiler of links drop out of Lurk & Link mode for comment and advice:


Keep your OS updated & patched.

Run a hardware firewall-- with today's LAN's, it's easy. You need a hardware firewall.


49 posted on 12/07/2005 1:28:59 AM PST by backhoe (Just an old Keyboard Cowboy, ridin' the trackball into the Sunset...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: backhoe

Re: Sygate Firewall...

Sygate has been swallowed whole by Symantec, and all consumer firewall software is discontinued.


50 posted on 12/07/2005 1:33:58 AM PST by Keith in Iowa (You know you have bird flu if you have usual flu symptoms + desire to crap on freshly washed cars.)
[ Post Reply | Private Reply | To 49 | View Replies]


Navigation: use the links below to view more comments.
first 1-5051-62 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson