SPYAXE-----popup on icon (toolbar)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by gthomas, Dec 13, 2005.

  1. gthomas

    gthomas Private E-2

    I ran the sticky. I also ran Spy Sweeper.

    I am a computer novice.

    I did the HiJack This thread, and fixed a few things (2 09's that were recommended in other spyaxe thrread).

    I think R1, both 020's,

    I won't be back until tomorrow nite.

    In the right of the bar for windows, the icon tabs for quick launch, a tab/icon is of a windows with the world that flashes to a red circle with a white x. It pops up saying you have malware, click here for the latest....blah blah blah. If you right click icon to get properties, it is as if you click in the box and takes you to spyaxe DOT net.

    Thanks.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How are things currently working
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should have posted the log from SmitRem!
     
  4. gthomas

    gthomas Private E-2

    Sorry about that.

    The computer is running fine (that I know of), except the popup.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is not a full SpySweeper log! What version are you running? And why didn't it fix anything?
     
  6. gthomas

    gthomas Private E-2

    It's the one I got from this site in the thread for Smitfraud, SpySheriff, SpyAxe & PSGuard Removal

    It did find something and delete them. SpyAxe and Antivrus Gold. Ohhh, I couldn't figure out how to save the scan results, and C&P'ed that section.

    I am currently doing a PandaScan.

    SpyAxe has loaded onto my computer twice while scanning without any clicks from me. I lost my first scan.

    On the attachment (kaspesky.txt), I could not find these files under a windows search or looking in the folder.

    I'm attaching the Panda scan also. When I clicked on the link, I hit scan, but it did not have a 'fix' it button.
     

    Attached Files:

  7. gthomas

    gthomas Private E-2


    I fiddled with Spy Sweeper and got this attachment.

    Also, notice today, that I got these two files, that I allowed. (Allowed Startup entry: MicrosoftAntiSpywareCleaner
    9:42 PM: Allowed Startup entry: GIANTAntiSpywareCleaner)
    Should I have?
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We do not have a link to Spy Sweeper in the above mentioned procedure. We do have it elsewhere though!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is you computer date set wrong or is the log from Spy Sweeper really from a day ago?

    Do you have any software from AverMedia installed?
     
  10. gthomas

    gthomas Private E-2


    My bad, it was on another thread. I am very upset now, SpyAxe downloaded onto my computer again.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Make sure you have viewng of hidden files enabled per the READ & RUN ME
    • Boot into safe mode and unplug your cable to the internet
    • Run the SmitRem procedure again and saved the log
    • While still in safe mode look for the below files with Windows Explorer and delete them:
    C:\WINDOWS\system32\ioctrl.dll
    C:\WINDOWS\system32\hpB0D1.tmp
    C:\WINDOWS\system32\msvol.tlb
    C:\WINDOWS\system32\nvctrl.exe



    Now reboot in normal mode and attach the smitfiles.txt log, PandaScan log, and a new HJT log. (you will need two messages to do this.)
     
  12. gthomas

    gthomas Private E-2


    My dates are set correct. I downloaded it yesterday and scanned. Up until 10:08PM is yesterday.

    Then the 9:38 and 9:42 are also today, along with the next session.

    I am unfamiliar with AverMedia. I will search, though.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See and run message # 11. Please do not do anything else!
     
  14. gthomas

    gthomas Private E-2

    When I went to SafeMode, I noticed the popup was not popping up. I ran the scans (attached), and tried searching for the 4 files. I cannot find them. I went and scanned the folder itself and all the files in it, not just in the alphabetical place, and I searched by hitting the START button the search, and typing the name of the folder in the search bar. I cannot find those four files.

    I am doing the PandaScan now.

    When I logged on NormalMode, I do not have the icon, nor popup. Will post PandaScan upon completion.

    Thank you.
     

    Attached Files:

  15. gthomas

    gthomas Private E-2

    Well, I am confused. I didn't do anything, really, and the ioctrl.dll is gone.

    After the PandaScan, I went ahead and ran Adaware.

    It is almost 1:00 A.M. here, thank you very very much.

    Is there anything else I need to do?
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds