Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Lavasoft Rapid Response to SpyAxe
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
HJT Log - homepage redirect and popup »
« How do I get infected?  

MrBradTX

join:2001-05-23
Carrollton, TX

Re: Lavasoft Rapid Response to SpyAxe

One anti-spyware program targeting another as hostile. This should be entertaining to watch.

FWIW I agree with the stand Lavasoft has taken. Software that installs itself by stealth is hostile by definition, regardless of its intent.

trparky
Bite My Shiny Metal Ass
Premium,MVM
join:2000-05-24
Cleveland, OH
clubs:
·AT&T U-Verse

Re: Lavasoft Rapid Response to SpyAxe

Interesting, I had to remove this from someone's machine before. Nice to see someone else seeing this, Google searching didn't result in much when I had to remove this.

Nothing in the Add/Remove Programs like a normal program should have an entry in, so I got to the point where I just told AdAware to remove all junk, it was gone when the removal was complete.
--
WedgeAntilles250

Tom's Rant
Fat City
Premium
join:2003-03-10
Freedonia

Re: Lavasoft Rapid Response to SpyAxe

said by trparky See Profile :

...Nothing in the Add/Remove Programs like a normal program should have an entry in, so I got to the point where I just told AdAware to remove all junk, it was gone when the removal was complete.
Are you sure it's all gone? Do the following files still remain:
mssearchnet.exe
nvctrl.exe

Reason I ask is because I've been hit with SpyAxe several times and I just can't ever seem to get rid of it all. I end up having to restore a known good partition image with Image for Windows.

If SpyAxe installs itself again on my machine I'll try Ad-Aware for removal, and I'll check to see that those two files disappear. If they don't, then I'll restore C:\ once again.
--
Men willingly believe what they wish. - Gaius Julius Caesar

trparky
Bite My Shiny Metal Ass
Premium,MVM
join:2000-05-24
Cleveland, OH
clubs:
·AT&T U-Verse

Re: Lavasoft Rapid Response to SpyAxe

said by Fat City See Profile :

said by trparky See Profile :

...Nothing in the Add/Remove Programs like a normal program should have an entry in, so I got to the point where I just told AdAware to remove all junk, it was gone when the removal was complete.
Are you sure it's all gone? Do the following files still remain:
mssearchnet.exe
nvctrl.exe

Reason I ask is because I've been hit with SpyAxe several times and I just can't ever seem to get rid of it all. I end up having to restore a known good partition image with Image for Windows.

If SpyAxe installs itself again on my machine I'll try Ad-Aware for removal, and I'll check to see that those two files disappear. If they don't, then I'll restore C:\ once again.
I don't know, like I said, when I was removing it, there wasn't much information out there on it. And the little there was was buried.
--
WedgeAntilles250

Tom's Rant
Fat City
Premium
join:2003-03-10
Freedonia

Got hit with SpyAxe again this evening so I tried Spybot - S&D (with latest updates) for removal. Nothing doing---pieces of SpyAxe remained, including the annoying little icon in systray with its constant click, click, click.

So I tried Ad-Aware (again, latest updates) and that didn't remove it either. Pieces of SpyAxe were all over the place including the icon from hell.

Popped in the Terabyte Image for Windows Boot CD and restored to a known good configuration. SpyAxe is gone.

Why aren't Spybot and Ad-Aware successful in removing SpyAxe?
--
Men willingly believe what they wish. - Gaius Julius Caesar

Anonymous
Premium
join:2004-06-01
IA

Re: Lavasoft Rapid Response to SpyAxe

It seems to me you need to get some protection. Re-imaging is no fun if you have to do it on a daily basis.

TheJoker
Premium,VIP,MVM
join:2001-04-26
Alexandria, VA

said by trparky See Profile :

Nice to see someone else seeing this, Google searching didn't result in much when I had to remove this.
I'm surprised you didn't find much on Google. You should go to »www.forums.spywareinfo.com and do a search for spyaxe. You'd be surprised at the number of people there are that have been infected by this hijack. It was supposedly released by one of SpyAxe's affiliates that was supposedly dropped after releasing the hijack that said you were infected and prompted people to download and install SpyAxe. SpyAxe released a supposed fix to remove the hijack, and even the fix is detected by Ewido as malware.
--
Proud ASAP member since 2005

Corrine
Premium
join:2004-08-27

Re: Lavasoft Rapid Response to SpyAxe

We've been buried at Freedomlist with this infection for some time. If it wasn't for noahdfear's smitRem© fix, there would be a lot of unsolved logs there & elsewhere.
--
Corrine, Administrator Freedomlist; Proud Charter Member ASAP Since 2004 (Alliance of Security Analysis Professionals)
Forums » Up and Running » Security » SecurityHJT Log - homepage redirect and popup »
« How do I get infected?  


Thursday, 10-Dec 00:03:18 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [200] Sprint Sued For Distracted Driving Death
· [109] AT&T Launching New 24 Mbps U-Verse Tier
· [82] 3G Network Test Says AT&T Is Tops
· [72] Mediacom Unveils 105 Mbps Pricing
· [66] Sprint Poised For A Turnaround?
· [65] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [60] AT&T Hints At Usage-Based iPhone Data Pricing
· [51] The Future Of Wi-Fi Is Bright
· [47] Site Leaks Yahoo, Verizon Fed Data Share Pricing
· [44] Microwaving Your Innards Is Not 'Extreme'
Most people now reading
· Adobe Flash Player version 10.0.42.34 [Security]
· ICC strats [World of Warcraft]
· Need some electrical advice - one circuit on two fuses? [Home Repair & Improvement]
· Hot Girl falls face first down stairs [56k Lookout (Broadband Heavy)]
· Windows 7 boot manager editing questions [Microsoft Help]
· Cross Server Dungeon Experience [World of Warcraft]
· Official "Invite" thread Part 3 - ALL INVITES GO HERE ! [Filesharing Software]
· Forwarding previous owner's mail [Home Repair & Improvement]
· Comcast refused to install 400' feet. [Comcast HSI]
· RG Firmware update to VDSL2 this morning [AT&T U-verse]