Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Spy Axe again
   
BullGuard Antivirus Forum > General Security > Spyware > Spy Axe again  
Forum Quick Jump
 
New Topic Post reply to : Spy Axe again Printable version of : Spy Axe again
[ << Previous Thread | Next Thread >> ]

Geekguy
New Member


Date Joined Dec 2005
Total Posts : 14
 
   Posted 12-30-2005 12:53 (GMT +2)    Quote: Spy Axe againAlert an admin about: Spy Axe again
Hi, as with others I have read I cannot get rid of this thing. Have run Adaware and Spybot and although they have detected the malware and said the problem was fixed, the pop ups near the clock still keep popping up
 
This is my Hijack This log, anyone help?
 
Logfile of HijackThis v1.99.1
Scan saved at 22:47:35, on 29/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Promise\Utility\MsgAgt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\DeskPins\DeskPins.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\Explorer.EXE
C:\DOCUME~1\STEVEF~1\LOCALS~1\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/weather/5day.shtml?id=2156
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.wanadoo.co.uk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll (file missing)
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll (file missing)
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Messenger\ycomp.dll (file missing)
O3 - Toolbar: Copernic Desktop Search - {C5F7A735-70F1-477F-8C36-6FF3C736017B} - C:\Program Files\Copernic Desktop Search\CopernicDesktopSearchIntegration740.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - Startup: DeskPins.lnk = C:\Program Files\DeskPins\DeskPins.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk/
O16 - DPF: ChatSpace Full Java Client 3.1.0.246 - http://chat-a3.freeserve.com/Java/cfs31246.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1125085097718
O17 - HKLM\System\CCS\Services\Tcpip\..\{49F3669B-5171-40E2-90AC-7F455B8BD164}: NameServer = 212.50.160.100 213.249.130.100
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Promise RAID message agent (RAIDmAgt) - Unknown owner - C:\Program Files\Promise\Utility\MsgAgt.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
 
Back to Top
 

­
Trusted Member




Date Joined Dec 2005
Total Posts : 113
 
   Posted 12-30-2005 1:13 (GMT +2)    Quote: Spy Axe againAlert an admin about: Spy Axe again
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
It was a part of Real Player, you can clean this no because file is missing on your hard disk.

O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
This line is good only if your sound card is a creative Labs.

O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
You can send this file "c:\program files\bonjour\mdnsnsp.dll" on http://virusscan.jotti.org
As for my self, i think this is the main problem. If it's detect as a malware, check this item & click on "fix checked" then delete this file.
Back to Top
 

rpggamergirl
Forum Moderator




Date Joined Dec 2005
Total Posts : 1534
 
   Posted 12-30-2005 1:24 (GMT +2)    Quote: Spy Axe againAlert an admin about: Spy Axe again
Hi, this will remove SpyAxe

You may want to print out or make a copy of these instructions before starting, because you will not be able to connect to the internet during most of this fix.

Download http://noahdfear.geekstogo.com/click%20counter/click.php?id=1
and save the file to your desktop.
Double click on the file to extract it to it's own folder on the desktop.

Next, please reboot your computer in Safe Mode:

Open the "smitRem" folder, then double click the "RunThis.bat" file to start the tool. Follow the prompts on screen. Your desktop and icons will disappear and then reappear again --- this is normal.
Wait for the tool to complete and Disk Cleanup to finish --- this may take a while; please be patient.
Back to Top
 

Geekguy
New Member


Date Joined Dec 2005
Total Posts : 14
 
   Posted 12-30-2005 10:39 (GMT +2)    Quote: Spy Axe againAlert an admin about: Spy Axe again
Hi and thanks for your replies.
 
I did what you both asked, and then ran Spybot, Adaware and even downloaded the Microsoft Anti Spyware Beta, they all confirmed that the offending spyware had been fixed/removed ets, but the bubble is still popping up telling me I'm infected. As for Hijack fixing the #10 file in the log, it said it couldn't fix it but Spybot would remove it, so I'm back to square one. Seems like a hard drive format may be the only soloution.
Back to Top
 

­
Trusted Member




Date Joined Dec 2005
Total Posts : 113
 
   Posted 12-31-2005 12:19 (GMT +2)    Quote: Spy Axe againAlert an admin about: Spy Axe again
"but the bubble is still popping up telling me I'm infected" <-- What do you mean ?

A bubble like this one ?


Take a screenshot if possible ... thanks.
Back to Top
 

rondrums
New Member


Date Joined Mar 2006
Total Posts : 1
 
   Posted 3-13-2006 12:28 (GMT +2)    Quote: Spy Axe againAlert an admin about: Spy Axe again
I was infected with BOTH Spy Axe and Spy Falcon simultaneously. Both of these are !!!!!!!s to get rid of!!
Neither my Ewido or my AVG could deal with them.
I'm not a do-it-yourself-er like a lot of you folks, so I did some research and found that SpySweeper will get rid of these nasties. Unfortunately, it cost $30 for a year, but it cleaned everything off nicely--desktop, task bar, popups, and all.


Back to Top
 

Geekguy
New Member


Date Joined Dec 2005
Total Posts : 14
 
   Posted 3-13-2006 1:05 (GMT +2)    Quote: Spy Axe againAlert an admin about: Spy Axe again
­ said...
"but the bubble is still popping up telling me I'm infected" <-- What do you mean ?

A bubble like this one ?


Take a screenshot if possible ... thanks.
I am greatful for the help I received on here, and it seems that the problems I had don't seem to be evident anymore. But I am loathed to think I may have solved the problem of both Spyaxe and Sinnaka virus's. I just think that the code may still be there, lurking, even though I have Norton Anti Virus, Microsofts Beta Malware programme, Spybot and Ad-Aware, all up to date. I run them regualally and nothing of consequence turns up, other than a few tracking cookies and MRU lists, so I should be happy about it. But I just wonder if I can really tell.
Back to Top
 

rpggamergirl
Forum Moderator




Date Joined Dec 2005
Total Posts : 1534
 
   Posted 3-17-2006 5:37 (GMT +2)    Quote: Spy Axe againAlert an admin about: Spy Axe again
Hi Geekguy,
Smitrem deletes the registry entries that were added by Spyaxe and restore their defaults.
SpyAxe and SpywareStrike are also known to add sites in the trusted zones which caused the infection to respawn sometimes. For peace of mind, try clearing the trusted zones.
You don't have the "bubble popup" anymore have you?
 
http://www.mvps.org/winhelp2002/DelDomains.inf
Right-click on the deldomains.inf file and select 'Install'
 
The .inf file will clear your trusted and restricted zones.
So if you have Spybot S&D you need to re-immunize,
If you have SpywareBlaster you need to re-enable all protection, if you have IESpyAd you need to reinstall it.

Post Edited (rpggamergirl) : 3/17/2006 3:39:04 AM GMT

Back to Top
 
New Topic Post reply to : Spy Axe again Printable version of : Spy Axe again
 
Forum Information
Currently it is Friday, July 30, 2010 2:20 PM (GMT +2)
There are a total of 79.134 posts in 17.897 threads.
In the last 3 days there were 8 new threads and 53 reply posts. View Active Threads
Who's Online
This forum has 31950 registered members. Please welcome our newest member, Willow.
18 Guest(s), 1 Registered Member(s) are currently online.  Details
tanisstray
5 Latest Threads
Updates more than 6 days old - BG advised upgrade from v8.7 to v9.0 to solve problem (4)30-07-2010 11:44:42 (Alex S.)
Redirect Virus Mozilla (10)30-07-2010 11:03:56 (tanisstray)
Redirected to different sites from links on Google (3)30-07-2010 09:36:16 (Touch)
Iexplore.exe virus causing problems (18)30-07-2010 09:32:14 (Touch)
9.1 is running! (10)30-07-2010 09:15:55 (katrina0)