Spyaxe/Spystrike removal problems...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by STPer, Jan 7, 2006.

  1. STPer

    STPer Private E-2

    I have followed the instructions for removing Spyaxe although I seem to have a variant of sorts called SpywareStrike. They appear to be the same thing... If you got to there web pages, they are the same page with a different name. I have attached a Hijack This Log, Panda activescan log and the SmitRem log. Any help would be great because this one is beating me.

    Thanks,
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You only completed half of step 6 and the BitDefender scan must be run before the PandaActiveScan. BitDefender will fix things whereas Panda will not. Order or steps and running ALL steps is important. Please complete the scan with BitDefender and attach the log.

    Did you know that you still have the below running:

    O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe

    This part of Panda Antivirus and you already have AVG. See step 3 of the READ ME.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Look in Add/Remove porgrams for the below and uninstall if found:
    SaveNow
    SpyFighter

    Now download smitRem.exe and save the file to your Desktop. If you already have this tool, delete the old version and download the new one because it has been updated to include SpywareStrike.
    Double click on the smitRem.exe file to extract it to it's own folder on the desktop. (this should be the default selection)
    Do not run anything from it yet we will do that further down.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
    R3 - Default URLSearchHook is missing

    After clicking Fix, exit HJT.

    Now you will need to print or save these instructions locally (to a text file on you Desktop) for later reference. This is necessary because you must not have any browers open and must not connect to the internet while following the below steps.

    • Once you have booted in Safe Mode and your Desktop appears, make sure you close any other windows and only run what is specified. You can open notepad to view the instructions you saved but do not open anything else accept what is specified.
    • Now open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen. Wait for the tool to complete and disk cleanup to finish.
    • The tool will create a log named smitfiles.txt in the root of the drive that you ran the batch file on, eg; Local Disk C: or partition where your operating system is installed.
    • Now open Control Panel and click Display -> Desktop -> Customize Desktop -> Web -> and uncheck any of the below if present:
      • Security Info
      • Warning Message
      • Security Desktop
      • Warning Homepage
    • Now use Windows Explorer to locate and delete any of the below if found:
      • c:\wp.exe
      • c:\bsw.exe
      • c:\secure32.html
      • C:\WINDOWS\ZLOADER3.EXE
      • C:\Program Files\Security iGuard <--- the whole folder
      • C:\Program Files\SpySheriff <--- the whole folder
      • C:\Program Files\SpyAxe <--- the whole folder
      • C:\Program Files\SpywareStrike <--- the whole folder
      • C:\PROGRAM FILES\Starware <--- the whole folder
      • C:\Documents and Settings\Owner\Application Data\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\SpyAxe 3.0.lnk
      • C:\WINDOWS\system32\netwrap.dll <--- please tell me if you see find this or do not find it. It should be gone after running smitrem.exe
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. Also attach the smitfiles.txt log and tell me if you found that netwrap.dll file.
    And tell us how things are working.

    Reminder Note: Once we have determine you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Jan 7, 2006
  4. STPer

    STPer Private E-2

    Sorry it took me so long to reply but it was eventualy solved by a rebuild... That gets it every dang time!:)

    Very much appreciate this forum in any case... Love what is provided here!
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome but that was totally unnecessary!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds