Can't remove spyware (SpyAxe)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Copasta, Nov 19, 2005.

  1. Copasta

    Copasta Private First Class

    Hello,
    My computer was recently infected with the SpyAxe program, and I can't seem to get anything to get rid of this annoying thing! I have run through the first 6 steps of your READ AND RUN ME FIRST pages, and it cleaned up alot of junk that I didn't even know was in my computer. However, it would not delete or clean up the smitfraud and minibug files. Everytime I restart my computer, this SpyAxe program kicks in and I get virus alert in my taskbar at the icons (looks like windows update icon...blinking, and flashing a red "x"). If I click on it, it immediately opens IE and goes to the SpyAxe page and starts running a scan!
    I won't post a HJThis file until you tell me to! Please help! Thank you!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In step 6 of the READ ME, did you click on the link to:

    Special Removal Procedures to see if your problem is covered there (for example: about:blank or HSA hijacker problems, SpySheriff, Smitfraud, Virtumundo aka WinFixer)

    If you have Smitfraud problems, run that procedure. If still having problems afterwards, continue with below.

    Make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis
     
  3. Copasta

    Copasta Private First Class

    Already went through the Special Removal Procedures. Here is the HJThis log...
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow directions so that we can help you. You do not even have the correct version of HijackThis which means you did not follow the steps in my previous message.

    Please make sure you answer the below questions too:
    1) Did you run the Smitfraud removal procedure?
    2) Did you save the SmitRem log?
    3) Do you still have Smitfraud problems?
    4) Did you first look in Add/Remove programs for SpyAxe and try to uninstall it? If it is not there, we can still remove it with another method.
    5) Do you use eBay Toolbar? It looks broken.

     
  5. Copasta

    Copasta Private First Class

    Ok, here we go......

    1. I ran the SmitFraud removal procedure like it said.

    2. This is the log it produced:

    3. I don't think I do, unless SpyAxe is part of that!

    4. I've tried NUMEROUS times to remove the program via the ADD/REMOVE. As soon as I reboot the computer, the program is back again.

    5. Uninstalled Ebay toolbar, downloaded and re-installed. Works fine now.

    6. Downloaded the NEW version of HJThis. Here is the log file:

    Hope this will help out. Sorry for any confusion or delay that I caused through my inept computer skills!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your OS & IE versions are way out of date and represent a major security risk. After we fix your current problems, you must address this. We will talk about that later.

    Also you are running without any antivirus protection. This is a very bad idea.

    Is there something you are using Microsoft Scheduling Agent for? It is running:
    O4 - HKLM\..\Run: [SchedulingAgent] mstinit.exe /firstlogon

    mstinit.exe is a process belinging to the Microsoft Scheduling Agent which deals with the automation of tasks such as anti-virus and defragmentation. This program is non-essential process to the running of the system, but should not be terminated unless suspected to be causing problems.


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
    O3 - Toolbar: SecurityToolbar - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} - C:\Program Files\Security Toolbar\Security Toolbar.dll (file missing)
    O4 - HKLM\..\Run: [SpyAxe] C:\Program Files\SpyAxe\spyaxe.exe /h
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing


    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\Security Toolbar <--- the whole folder
    C:\Program Files\SpyAxe <--- the whole folder


    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  7. Copasta

    Copasta Private First Class

    Did all that....here is the new log. I think I forgot to disable System Restore before I went into safe mode and deleted the stuff you said to....hope that doesn't cause any problems! I still have the windows icon in the taskbar flashing "virus alert", but the SpyAxe seems to be gone for now! Please let me know about the other things that need attention! Thanks!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    System Restore should still be disabled. You were supposed to disable it in step 1 of the READ & RUN ME and leave it disable until all malware has been fixed.

    You did not answer my question:

    You need to enable PM's (Private Messages) in your user profile. There is something I need to send to you to do via PM to help fix the problem with the Taskbar.
     
  9. Copasta

    Copasta Private First Class

    Ok, I've enabled PM. As far as I know, I'm not using Microsoft Sheduling Agent for anything (but then I don't know a whole lot, either!). Can I fix that in HJThis?Thanks for all your help, and being so patient with me!:)
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    I would look for Microsoft Scheduling Agent in your tray and right click on it and see if you can disable it from running. If we use HJT to fix it, it may delete the file which is not what you want to do for this file. We just want to stop the agent from running.
     
  11. Copasta

    Copasta Private First Class

    Here are the posts you requested from your PM. The "virus alert" message is no longer in the taskbar! Damn, you guys are good! I don't see any type of Microsoft Scheduling Agent in my tray to right click on....wasn't quite sure what to do there! The only other thing is, from earlier, you said that my OS and IE are out of date. What do I have to do to update them? Also, I used to be running Norton Internet Security with Norton Antivirus, but I think when I upgraded to XP, it didn't work anymore. I guess I should have taken care of that sooner, huh!

    Again, thanks for all the help! You guys are light at the end of the tunnel when it comes to times like this!
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's try to fix the scheduling agent manually.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixmsa.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixmsa.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Then you should move on the below link and complete all steps. The first step in the link will discuss Microsoft update. Another step will give you some suggestions for an antivirus application.

    How to Protect yourself from malware!
     
  13. Copasta

    Copasta Private First Class

    Couldn't update windows.....it kept saying it was unable to update Service Pack 2. I installed the antivirus software, but have to go to work now. I'll check back later!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you get any messages about genuine windows validation or similar? Your copy needs to be validated or you will not be able to get the updates. Did you try Express or Custom update?

    Did the registry patch work? Is that scheduling agent line now gone from your HJT log.
     
  15. Copasta

    Copasta Private First Class

    The only notice I received with the update was that I had to accept the license agreement before it would download. Then the download would fail. I used the express method to do this. How do I validate my copy of windows?

    The Microsoft Scheduling Agent line is still in the HJT log!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What download failed? The download of the license agreement? Or did you actually get to the point where downloading of patches/upgrades began. Validation is part of the Windows update process now. It winds up adding something to your PC (an O16 line will show in HJT that indicated Windows is genuine).

    Did the registry patch say it add into the registry okay?
    Do you know how to run and use regedit?
     
  17. Copasta

    Copasta Private First Class

    The license agreement was accepted, and the download of the updates begins, then stops almost immediately and says "download failed". It is the Service Pack 2 patch that says it has to be downloaded before the rest of the updates can be downloaded. I used to have Windows Update do this automatically and there was never a problem, but I guess whatever happened to it is the reason the automatic update doesn't work anymore either.

    As far as I can remember (we've done ALOT over the last few days!) the registry patch did everything that it was supposed to, and added into the registry ok. However, the line is still in HJT. I don't understand. Maybe I should try it again?

    Also, I'm really not sure how to run regedit....I know I can really mess things up if I do something wrong in there!
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I do not believe your problem with MS Update is from malware but I cannot be positive!

    First try this:
    - disable your ZoneAlarm firewall and then try Windows Update

    If that does not work for you, then let's start by getting the WinXP SP1a patch installed. It is a least a start in the right direction. You should be able to get this full SP1a download from

    http://www.softwarepatch.com/windows/winxpsp1.html

    Download the file and then install it. As typical, this is a very large file (over 100Mb). Afterwards reboot and then post a new HJT log.
     
  19. Copasta

    Copasta Private First Class

    Disabling the firewall didn't work either. I downloaded the SP1a patch and tried to install, but it keeps getting stuck on "Finishing Install - Running processes after install". I've tried a few different times using different methods (archive files, do not archive, etc.). This is beginning to get a little discouraging at this point. Any other ideas?

    Anyway, hope you and yours have a wonderful Thanksgiving! Thanks for all the help so far!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what is going on right now with Windows Update. You may have to ask this one in the software forum.

    Thanks! Enjoy the holiday too.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds