Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Lavasoft Rapid Response to SpyAxe
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
HJT Log - homepage redirect and popup »
« How do I get infected?  

siggyx
Siggy
Premium
join:2003-12-10
Cambridge

Re: Lavasoft Rapid Response to SpyAxe

I agree with Corrine, If it wasn't for noahdfear's smitRem© fix we would be heavily bogged down at TC with unresolved logs. As it is we are seeing more and more everyday.
--
90% of sports is mental, the other half is physical

Profixer

join:2005-07-01

Re: Lavasoft Rapid Response to SpyAxe

From what we can see... it is a possibility that a huge number of SpyAxe variants were pre-built before the whole mess started, and this has resulted in an huge amount of them out in the wild from day one.... we have received 9 more variants in the past 2 days and are adding these to detection.... it seems there may be on average 5 new variants a week... this IS a serious issue, which we are working hard to get it resolved.

CalamityJane
Premium,VIP,MVM
join:2002-08-27
Eustis, FL

Re: Lavasoft Rapid Response to SpyAxe

Thanks for the feedback LS SteveJ. I'm glad to hear Adaware continues to work on detection and removal for the new variants. We have certainly noticed an increase in cries for help here.

Meanwhile, the SmitRem tool by Noadfear can help and has been updated to include SpyAxe. New FAQ added last night to give some steps on removing SpyAxe and other Smitfraud variants:
»Security »Zlob/Smitfraud Removal
--
It takes a disaster to make a woman out of a female
Microsoft MVP/Windows Security 2003-2006
Proud Member of ASAP (Alliance of Security Analysis Professionals)

Profixer

join:2005-07-01

Re: Lavasoft Rapid Response to SpyAxe

No problem Calamity!... Its peeing us off just as much as our users, and the community, I promise you....

there is a ton of downloaders out there, installing new variants on a daily basis... and we are trying our best to get both the downloaders, and the variants they are spitting out....

I will keep you posted

CalamityJane
Premium,VIP,MVM
join:2002-08-27
Eustis, FL

Re: Lavasoft Rapid Response to SpyAxe

said by Profixer See Profile :

I will keep you posted
Thank you for your efforts! Appreciate it

Was wondering why we're seeing so many new victims of this. Any idea what exploit they are using (or other method of install) so we can warn folks how to prevent it?
--
It takes a disaster to make a woman out of a female
Microsoft MVP/Windows Security 2003-2006
Proud Member of ASAP (Alliance of Security Analysis Professionals)

Profixer

join:2005-07-01

Re: Lavasoft Rapid Response to SpyAxe

There are alot being installed by variants of Trojan.Downloader.Zlob.. people should keep there eye out for svchosts.dll / svchost.dll especially... the method of choice for SpyAxe install is a fraudlent Windows Update icon in the tray, popping a bubble saying "Your computer is infected with spyware, click here to install the latest anti-spyware"... or something of that nature....

CalamityJane
Premium,VIP,MVM
join:2002-08-27
Eustis, FL

Re: Lavasoft Rapid Response to SpyAxe

Thanks again, Steve. Keep us posted on any developments!
Forums » Up and Running » Security » SecurityHJT Log - homepage redirect and popup »
« How do I get infected?  


Sunday, 06-Dec 12:08:49 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [147] Avast Antivirus Has Gone Mad
· [134] The Bandwidth Hog Does Not Exist
· [128] Comcast Makes NBC Universal Acquisition Official
· [105] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [101] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [85] FCC Ponders Moving From PSTN To IP Voice
· [82] Latest Consumer Reports Survey Not Kind To AT&T
· [81] New Bill Aims To Limit ETFs
· [75] Sprint Defuses GPS Privacy Media Bomb
Most people now reading
· Wife might have to work in.... Iowa for a few months!!! [General Questions]
· Problems with rlslog.net? [TekSavvy]
· False positive in Avast! or is it real? [Security]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· Windows 7 boot manager editing questions [Microsoft Help]
· Bulb for garage door opener [Home Repair & Improvement]
· How fast is your upstream internet connection? [General Questions]
· [DNS] Google's public DNS... performance increases? [Comcast HSI]
· Unable to get incoming SIP with Callcentric [VOIP Tech Chat]
· [Newsgroups] Newzleech down? [Filesharing Software]