Yes I do, and it is updated. So I did a scan [and kept a logfile] and followed the Ad-aware removal instructions. But when I rebooted the spyaxe had returned. Here is the logfile before attempted removal [the summary is 23 registry keys, 6 registry values, 20 files, and 4 folders]:
Ad-Aware SE Build 1.06r1
Logfile Created on:13 December 2005 20:48:23
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R79 09.12.2005
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Malware.SpyAxe(TAC index:4):44 total references
MRU List(TAC index:0):8 total references
Other(TAC index:5):1 total references
Possible Browser Hijack attempt(TAC index:3):7 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Search for low-risk threats
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
13-12-2005 20:48:23 - Scan started. (Full System Scan)
MRU List Object Recognized!
Location: : C:\Documents and Settings\MLC\Application Data\microsoft\office\recent
Description : list of recently opened documents using microsoft office
MRU List Object Recognized!
Location: : C:\Documents and Settings\MLC\recent
Description : list of recently opened documents
MRU List Object Recognized!
Location: : software\microsoft\directdraw\mostrecentapplication
Description : most recent application to use microsoft directdraw
MRU List Object Recognized!
Location: : S-1-5-21-220523388-152049171-682003330-1003\software\microsoft\search assistant\acmru
Description : list of recent search terms used with the search assistant
MRU List Object Recognized!
Location: : S-1-5-21-220523388-152049171-682003330-1003\software\microsoft\windows\currentversion\applets\wordpad\recent file list
Description : list of recent files opened using wordpad
MRU List Object Recognized!
Location: : S-1-5-21-220523388-152049171-682003330-1003\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
Description : list of recent programs opened
MRU List Object Recognized!
Location: : S-1-5-21-220523388-152049171-682003330-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
Description : list of recently saved files, stored according to file extension
MRU List Object Recognized!
Location: : S-1-5-21-220523388-152049171-682003330-1003\software\microsoft\windows\currentversion\explorer\recentdocs
Description : list of recent documents opened
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 504
ThreadCreationTime : 13-12-2005 20:43:50
BasePriority : Normal
#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 632
ThreadCreationTime : 13-12-2005 20:43:52
BasePriority : Normal
#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 660
ThreadCreationTime : 13-12-2005 20:43:53
BasePriority : High
#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 980
ThreadCreationTime : 13-12-2005 20:43:53
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : services.exe
#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 992
ThreadCreationTime : 13-12-2005 20:43:53
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe
#:6 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1168
ThreadCreationTime : 13-12-2005 20:43:53
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:7 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1228
ThreadCreationTime : 13-12-2005 20:43:53
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:8 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1348
ThreadCreationTime : 13-12-2005 20:43:53
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:9 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1396
ThreadCreationTime : 13-12-2005 20:43:53
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:10 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1448
ThreadCreationTime : 13-12-2005 20:43:54
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:11 [ccproxy.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ProcessID : 1700
ThreadCreationTime : 13-12-2005 20:43:54
BasePriority : Normal
FileVersion : 103.0.4.3
ProductVersion : 103.0.4.3
ProductName : Client and Host Security Platform
CompanyName : Symantec Corporation
FileDescription : Symantec Network Proxy Service
InternalName : ccProxy
LegalCopyright : Copyright (c) 2000-2004 Symantec Corporation. All rights reserved.
OriginalFilename : ccProxy.exe
#:12 [ccsetmgr.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ProcessID : 1780
ThreadCreationTime : 13-12-2005 20:43:55
BasePriority : Normal
FileVersion : 103.0.5.2
ProductVersion : 103.0.5.2
ProductName : Client and Host Security Platform
CompanyName : Symantec Corporation
FileDescription : Symantec Settings Manager Service
InternalName : ccSetMgr
LegalCopyright : Copyright (c) 2000-2004 Symantec Corporation. All rights reserved.
OriginalFilename : ccSetMgr.exe
#:13 [issvc.exe]
FilePath : C:\Program Files\Norton Internet Security\
ProcessID : 1800
ThreadCreationTime : 13-12-2005 20:43:55
BasePriority : Normal
FileVersion : 8.0.5.14
ProductVersion : 8.0
ProductName : Norton Internet Security
CompanyName : Symantec Corporation
FileDescription : IS Service
InternalName : ISSVC.exe
LegalCopyright : Copyright (c) 2004 Symantec Corporation
OriginalFilename : ISSVC.exe
#:14 [sndsrvc.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ProcessID : 1824
ThreadCreationTime : 13-12-2005 20:43:55
BasePriority : Normal
FileVersion : 5.5.1.6
ProductVersion : 5.5
ProductName : Symantec Security Drivers
CompanyName : Symantec Corporation
FileDescription : Network Driver Service
InternalName : SndSrvc
LegalCopyright : Copyright 2002, 2003, 2004 Symantec Corporation
OriginalFilename : SndSrvc.exe
#:15 [spbbcsvc.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\SPBBC\
ProcessID : 1864
ThreadCreationTime : 13-12-2005 20:43:55
BasePriority : Normal
FileVersion : 1,0,1,47
ProductVersion : 1,0,1,47
ProductName : SPBBC
CompanyName : Symantec Corporation
FileDescription : SPBBC Service
InternalName : SPBBCSvc
LegalCopyright : Copyright (c) 2004 Symantec Corporation. All rights reserved.
OriginalFilename : SPBBCSvc.exe
#:16 [ccevtmgr.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ProcessID : 1964
ThreadCreationTime : 13-12-2005 20:43:55
BasePriority : Normal
FileVersion : 103.0.5.2
ProductVersion : 103.0.5.2
ProductName : Client and Host Security Platform
CompanyName : Symantec Corporation
FileDescription : Symantec Event Manager Service
InternalName : ccEvtMgr
LegalCopyright : Copyright (c) 2000-2004 Symantec Corporation. All rights reserved.
OriginalFilename : ccEvtMgr.exe
#:17 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 464
ThreadCreationTime : 13-12-2005 20:43:56
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE
#:18 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 828
ThreadCreationTime : 13-12-2005 20:43:58
BasePriority : Normal
FileVersion : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)
ProductVersion : 5.1.2600.2696
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe
#:19 [cvpnd.exe]
FilePath : C:\Program Files\Cisco Systems\VPN Client\
ProcessID : 936
ThreadCreationTime : 13-12-2005 20:43:58
BasePriority : Normal
FileVersion : 4.6.03.0021
ProductVersion : 4.6.03.0021
ProductName : Cisco Systems VPN Client
CompanyName : Cisco Systems, Inc.
FileDescription : Cisco Systems VPN Client
InternalName : cvpnd
LegalCopyright : Copyright © 1998-2005 Cisco Systems, Inc.
OriginalFilename : CVPND.EXE
#:20 [ewidoctrl.exe]
FilePath : C:\Program Files\ewido\security suite\
ProcessID : 1200
ThreadCreationTime : 13-12-2005 20:43:58
BasePriority : Normal
FileVersion : 3, 0, 0, 1
ProductVersion : 3, 0, 0, 1
ProductName : ewido control
CompanyName : ewido networks
FileDescription : ewido control
InternalName : ewido control
LegalCopyright : Copyright © 2004
OriginalFilename : ewidoctrl.exe
#:21 [activitydisk.exe]
FilePath : C:\PROGRA~1\Iomega\System32\
ProcessID : 1312
ThreadCreationTime : 13-12-2005 20:43:58
BasePriority : Normal
FileVersion : 1, 7, 2, 0
ProductVersion : 1, 7, 2, 0
ProductName : SmartSoft ActivityDisk
CompanyName : Iomega Corporation
FileDescription : ActivityDisk
InternalName : ActivityDisk
LegalCopyright : Copyright © 2000
OriginalFilename : ActivityDisk.exe
Comments : Iomega Activity Disk Service Component For Windows 2000/NT
#:22 [mdm.exe]
FilePath : C:\Program Files\Common Files\Microsoft Shared\VS7Debug\
ProcessID : 1404
ThreadCreationTime : 13-12-2005 20:43:58
BasePriority : Normal
FileVersion : 7.00.9064.9150
ProductVersion : 7.00.9064.9150
ProductName : Microsoft Development Environment
CompanyName : Microsoft Corporation
FileDescription : Machine Debug Manager
InternalName : mdm.exe
LegalCopyright : Copyright (C) Microsoft Corp. 1997-2000
OriginalFilename : mdm.exe
#:23 [navapsvc.exe]
FilePath : C:\Program Files\Norton Internet Security\Norton AntiVirus\
ProcessID : 1436
ThreadCreationTime : 13-12-2005 20:43:58
BasePriority : Normal
FileVersion : 11.0.16.2
ProductVersion : 11.0.16
ProductName : Norton AntiVirus
CompanyName : Symantec Corporation
FileDescription : Norton AntiVirus Auto-Protect Service
InternalName : NAVAPSVC
LegalCopyright : Norton AntiVirus 2005 for Windows 98/ME/2000/XP Copyright © 2004 Symantec Corporation. All rights reserved.
OriginalFilename : NAVAPSVC.EXE
#:24 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1676
ThreadCreationTime : 13-12-2005 20:43:58
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:25 [symlcsvc.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\CCPD-LC\
ProcessID : 1912
ThreadCreationTime : 13-12-2005 20:43:58
BasePriority : Normal
FileVersion : 1.8.54.841
ProductVersion : 1.8.54.841
ProductName : Symantec Core Component
CompanyName : Symantec Corporation
FileDescription : Symantec Core Component
InternalName : symlcsvc
LegalCopyright : Copyright (C) 2003
OriginalFilename : symlcsvc.exe
#:26 [alg.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2224
ThreadCreationTime : 13-12-2005 20:44:02
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Application Layer Gateway Service
InternalName : ALG.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ALG.exe
#:27 [igfxtray.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2304
ThreadCreationTime : 13-12-2005 20:44:04
BasePriority : Normal
FileVersion : 3,0,0,1773
ProductVersion : 7,0,0,1773
ProductName : Intel(R) Common User Interface
CompanyName : Intel Corporation
FileDescription : igfxTray Module
InternalName : IGFXTRAY
LegalCopyright : Copyright 1999-2002, Intel Corporation
OriginalFilename : IGFXTRAY.EXE
#:28 [hkcmd.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2328
ThreadCreationTime : 13-12-2005 20:44:05
BasePriority : Normal
FileVersion : 3,0,0,1773
ProductVersion : 7,0,0,1773
ProductName : Intel(R) Common User Interface
CompanyName : Intel Corporation
FileDescription : hkcmd Module
InternalName : HKCMD
LegalCopyright : Copyright 1999-2002, Intel Corporation
OriginalFilename : HKCMD.EXE
#:29 [soundman.exe]
FilePath : C:\WINDOWS\
ProcessID : 2336
ThreadCreationTime : 13-12-2005 20:44:05
BasePriority : Normal
FileVersion : 5.0.03
ProductVersion : 5.0.03
ProductName : Avance Sound Manager
CompanyName : Avance Logic, Inc.
FileDescription : Avance Sound Manager
InternalName : ALSMTray
LegalCopyright : Copyright (c) 2001-2002 Avance Logic, Inc.
OriginalFilename : ALSMTray.exe
Comments : Avance AC97 Audio Sound Manager
#:30 [imgicon.exe]
FilePath : C:\Program Files\Iomega\DriveIcons\
ProcessID : 2352
ThreadCreationTime : 13-12-2005 20:44:05
BasePriority : Normal
#:31 [type32.exe]
FilePath : C:\Program Files\Microsoft Hardware\Keyboard\
ProcessID : 2376
ThreadCreationTime : 13-12-2005 20:44:05
BasePriority : Normal
#:32 [point32.exe]
FilePath : C:\Program Files\Microsoft Hardware\Mouse\
ProcessID : 2428
ThreadCreationTime : 13-12-2005 20:44:05
BasePriority : Normal
#:33 [drives~1.exe]
FilePath : C:\PROGRA~1\Ahead\NEROTO~1\
ProcessID : 2488
ThreadCreationTime : 13-12-2005 20:44:07
BasePriority : Normal
FileVersion : 1, 6, 1, 0
ProductVersion : 1, 6, 1, 0
ProductName : DriveSpeed
CompanyName : Erik Deppe
FileDescription : Nero DriveSpeed
InternalName : DriveSpeed
LegalCopyright : Copyright (C) 1999-2002
OriginalFilename : DriveSpeed.EXE
#:34 [plguni.exe]
FilePath : C:\Program Files\McAfee\QuickClean\
ProcessID : 2616
ThreadCreationTime : 13-12-2005 20:44:08
BasePriority : Normal
FileVersion : 3.02.6000.0
ProductVersion : 3.02.6000.0
ProductName : QuickClean
CompanyName : Network Associates, Inc.
FileDescription : QuickClean Plug-In For McAfee Agent
InternalName : PlgUni.exe
LegalCopyright : Copyright © 2003 Networks Associates Technology, Inc. All Rights Reserved.
LegalTrademarks : QuickClean is a registered trademark of Network Associates, Inc and/or its affilates in the US or other countries.
OriginalFilename : PlgUni.exe
#:35 [ccapp.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ProcessID : 2668
ThreadCreationTime : 13-12-2005 20:44:08
BasePriority : Normal
FileVersion : 103.0.5.2
ProductVersion : 103.0.5.2
ProductName : Client and Host Security Platform
CompanyName : Symantec Corporation
FileDescription : Symantec User Session
InternalName : ccApp
LegalCopyright : Copyright (c) 2000-2004 Symantec Corporation. All rights reserved.
OriginalFilename : ccApp.exe
#:36 [ituneshelper.exe]
FilePath : C:\Program Files\iTunes\
ProcessID : 2884
ThreadCreationTime : 13-12-2005 20:44:09
BasePriority : Normal
FileVersion : 6.0.1.3
ProductVersion : 6.0.1.3
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iTunesHelper Module
InternalName : iTunesHelper
LegalCopyright : © 2003-2005 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iTunesHelper.exe
#:37 [qttask.exe]
FilePath : C:\Program Files\QuickTime\
ProcessID : 3068
ThreadCreationTime : 13-12-2005 20:44:10
BasePriority : Normal
FileVersion : 7.0.3
ProductVersion : QuickTime 7.0.3
ProductName : QuickTime
CompanyName : Apple Computer, Inc.
FileDescription : QuickTime Task
InternalName : QuickTime Task
LegalCopyright : Copyright Apple Computer, Inc. 1989-2005
OriginalFilename : QTTask.exe
#:38 [spyaxe.exe]
FilePath : C:\Program Files\SpyAxe\
ProcessID : 3640
ThreadCreationTime : 13-12-2005 20:44:13
BasePriority : Normal
FileVersion : 3.0.0.0
ProductVersion : 3.0.0.0
ProductName : SpyAxe
CompanyName : SpyAxe.com
FileDescription : Anti-spyware software
InternalName : spyaxe
LegalCopyright : (c) SpyAxe.com. All rights reserved.
OriginalFilename : spyaxe.exe
#:39 [spyaxe.exe]
FilePath : C:\Program Files\SpyAxe\
ProcessID : 3684
ThreadCreationTime : 13-12-2005 20:44:14
BasePriority : Normal
FileVersion : 3.0.0.0
ProductVersion : 3.0.0.0
ProductName : SpyAxe
CompanyName : SpyAxe.com
FileDescription : Anti-spyware software
InternalName : spyaxe
LegalCopyright : (c) SpyAxe.com. All rights reserved.
OriginalFilename : spyaxe.exe
#:40 [ipodservice.exe]
FilePath : C:\Program Files\iPod\bin\
ProcessID : 3692
ThreadCreationTime : 13-12-2005 20:44:14
BasePriority : Normal
FileVersion : 6.0.1.3
ProductVersion : 6.0.1.3
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iPodService Module
InternalName : iPodService
LegalCopyright : © 2003-2005 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iPodService.exe
#:41 [rulaunch.exe]
FilePath : C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\
ProcessID : 3700
ThreadCreationTime : 13-12-2005 20:44:14
BasePriority : Normal
FileVersion : 2.03.1016.0
ProductVersion : 2.03.1016.0
ProductName : McAfee Instant Updater
CompanyName : Network Associates, Inc.
FileDescription : Instant Updater Main Program
InternalName : RuLaunch
LegalCopyright : Copyright © 1998-2003 Networks Associates Technology, Inc. All rights reserved.
OriginalFilename : RuLaunch.exe
#:42 [offman.exe]
FilePath : C:\Program Files\Intense Language Office\COMMON\
ProcessID : 3756
ThreadCreationTime : 13-12-2005 20:44:16
BasePriority : Normal
#:43 [ctfmon.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 3772
ThreadCreationTime : 13-12-2005 20:44:17
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : CTF Loader
InternalName : CTFMON
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : CTFMON.EXE
#:44 [wzqkpick.exe]
FilePath : C:\Program Files\WinZip\
ProcessID : 4076
ThreadCreationTime : 13-12-2005 20:44:30
BasePriority : Normal
FileVersion : 1.0 (32-bit)
ProductVersion : 8.1 (4319)
ProductName : WinZip
CompanyName : WinZip Computing, Inc.
FileDescription : WinZip Executable
InternalName : WZQKPICK.EXE
LegalCopyright : Copyright (c) WinZip Computing, Inc. 1991-2001 - All Rights Reserved
LegalTrademarks : WinZip is a registered trademark of WinZip Computing, Inc
OriginalFilename : WZQKPICK.EXE
Comments : StringFileInfo: U.S. English
#:45 [fcpms.exe]
FilePath : C:\Program Files\Freecom Personal Media Suite\
ProcessID : 4084
ThreadCreationTime : 13-12-2005 20:44:30
BasePriority : Normal
FileVersion : 2.03
ProductVersion : 2.03
ProductName : Freecom Personal Media Suite
CompanyName : Freecom
FileDescription : Personal Media Suite
InternalName : Zion
LegalCopyright : Copyright © 2003-2004
OriginalFilename : FCPMS.exe
#:46 [sgmain.exe]
FilePath : C:\Program Files\SpywareGuard\
ProcessID : 1428
ThreadCreationTime : 13-12-2005 20:44:32
BasePriority : Normal
FileVersion : 2.02.0001
ProductVersion : 2.02.0001
ProductName : SpywareGuard
FileDescription : SpywareGuard
InternalName : sgmain
LegalCopyright : Copyright (C) 2002-2003 Javacool Software LLC
OriginalFilename : sgmain.exe
Comments : SpywareGuard
#:47 [wuauclt.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 2296
ThreadCreationTime : 13-12-2005 20:44:49
BasePriority : Normal
FileVersion : 5.8.0.2469 built by: lab01_n(wmbla)
ProductVersion : 5.8.0.2469
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Automatic Updates
InternalName : wuauclt.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : wuauclt.exe
#:48 [msiexec.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 3032
ThreadCreationTime : 13-12-2005 20:45:02
BasePriority : Normal
#:49 [msmsgs.exe]
FilePath : C:\Program Files\Messenger\
ProcessID : 124
ThreadCreationTime : 13-12-2005 20:47:27
BasePriority : Normal
FileVersion : 4.7.3001
ProductVersion : Version 4.7.3001
ProductName : Messenger
CompanyName : Microsoft Corporation
FileDescription : Windows Messenger
InternalName : msmsgs
LegalCopyright : Copyright (c) Microsoft Corporation 2004
LegalTrademarks : Microsoft(R) is a registered trademark of Microsoft Corporation in the U.S. and/or other countries.
OriginalFilename : msmsgs.exe
#:50 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
ProcessID : 3780
ThreadCreationTime : 13-12-2005 20:48:01
BasePriority : Normal
FileVersion : 6.2.0.236
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 8
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Malware.SpyAxe Object Recognized!
Type : Regkey
Data :
TAC Rating : 4
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : appid\{70f17c8c-1744-41b6-9d07-575db448dcc5}
Malware.SpyAxe Object Recognized!
Type : Regkey
Data :
TAC Rating : 4
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{957bab51-81ff-8195-f273-d7e286ea702f}
Malware.SpyAxe Object Recognized!
Type : Regkey
Data :
TAC Rating : 4
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{2bb3bcbf-411a-4c67-8e69-f4bb301dc333}
Malware.SpyAxe Object Recognized!
Type : Regkey
Data :
TAC Rating : 4
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{0f68a8aa-a9a8-4711-be36-ae363efa6443}
Malware.SpyAxe Object Recognized!
Type : Regkey
Data :
TAC Rating : 4
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{28420952-c82b-47d9-a042-fa2217d8a082}
Malware.SpyAxe Object Recognized!
Type : Regkey
Data :
TAC Rating : 4
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{3c099c83-8587-4b35-8af0-fc3a169ce14f}
Malware.SpyAxe Object Recognized!
Type : Regkey
Data :
TAC Rating : 4
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{3fe13f31-e890-4c37-8213-4b5f9a511c26}
Malware.SpyAxe Object Recognized!
Type : Regkey
Data :
TAC Rating : 4
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{4cad27dc-1b60-42f4-820e-316fe0a13512}
Malware.SpyAxe Object Recognized!
Type : Regkey
Data :
TAC Rating : 4
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{54874d12-c0c6-44cc-83fb-2c35202f881b}
Malware.SpyAxe Object Recognized!
Type : Regkey
Data :
TAC Rating : 4
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{54a3200b-d76e-48d1-b35c-d87eaf6d90bd}
Malware.SpyAxe Object Recognized!
Type : Regkey
Data :
TAC Rating : 4
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{663dfe59-032c-46fb-a09a-ffc2dc074f54}
Malware.SpyAxe Object Recognized!
Type : Regkey
Data :
TAC Rating : 4
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{69ce4fbc-4861-4206-8211-dd5a9ee79ad3}
Malware.SpyAxe Object Recognized!
Type : Regkey
Data :
TAC Rating : 4
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{afa9056f-aa11-4771-ae01-04ecfde18206}
Malware.SpyAxe Object Recognized!
Type : Regkey
Data :
TAC Rating : 4
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{b8f2487f-aa6a-4914-9a3f-db84e6868d66}
Malware.SpyAxe Object Recognized!
Type : Regkey
Data :
TAC Rating : 4
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{e4645720-e02f-4bb2-8e6d-be7653dd1bf2}
Malware.SpyAxe Object Recognized!
Type : Regkey
Data :
TAC Rating : 4
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{fa46b160-c9dd-4040-b9d9-ccf5d3db5438}
Malware.SpyAxe Object Recognized!
Type : Regkey
Data :
TAC Rating : 4
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{fc1f0c2c-8117-427d-816c-215b68524f74}
Malware.SpyAxe Object Recognized!
Type : Regkey
Data :
TAC Rating : 4
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{fd1eee96-8dc7-478d-be3b-7d06ac67fb66}
Malware.SpyAxe Object Recognized!
Type : Regkey
Data :
TAC Rating : 4
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{fd8e5ed7-0091-416f-a55b-1d072d58a24f}
Malware.SpyAxe Object Recognized!
Type : Regkey
Data :
TAC Rating : 4
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\spyaxe
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 20
Objects found so far: 28
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Possible Browser Hijack attempt Object Recognized!
Type : Regkey
Data : Software\Microsoft\Windows\CurrentVersion\Uninstall\SpyAxe "http://www.spyaxe.com"
TAC Rating : 4
Category : Malware
Comment : (
http://www.spyaxe.com)
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Windows\CurrentVersion\Uninstall\SpyAxe
Possible Browser Hijack attempt Object Recognized!
Type : RegValue
Data : Software\Microsoft\Windows\CurrentVersion\Uninstall\SpyAxe "http://www.spyaxe.com"
TAC Rating : 4
Category : Malware
Comment : (
http://www.spyaxe.com)
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Windows\CurrentVersion\Uninstall\SpyAxe
Value : UninstallString
Possible Browser Hijack attempt Object Recognized!
Type : RegValue
Data : Software\Microsoft\Windows\CurrentVersion\Uninstall\SpyAxe "http://www.spyaxe.com"
TAC Rating : 4
Category : Malware
Comment : (
http://www.spyaxe.com)
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Windows\CurrentVersion\Uninstall\SpyAxe
Value : DisplayIcon
Possible Browser Hijack attempt Object Recognized!
Type : RegValue
Data : Software\Microsoft\Windows\CurrentVersion\Uninstall\SpyAxe "http://www.spyaxe.com"
TAC Rating : 4
Category : Malware
Comment : (
http://www.spyaxe.com)
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Windows\CurrentVersion\Uninstall\SpyAxe
Value : DisplayVersion
Possible Browser Hijack attempt Object Recognized!
Type : RegValue
Data : Software\Microsoft\Windows\CurrentVersion\Uninstall\SpyAxe "http://www.spyaxe.com"
TAC Rating : 4
Category : Malware
Comment : (
http://www.spyaxe.com)
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Windows\CurrentVersion\Uninstall\SpyAxe
Value : NSIS:StartMenuDir
Possible Browser Hijack attempt Object Recognized!
Type : RegValue
Data : Software\Microsoft\Windows\CurrentVersion\Uninstall\SpyAxe "http://www.spyaxe.com"
TAC Rating : 4
Category : Malware
Comment : (
http://www.spyaxe.com)
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Windows\CurrentVersion\Uninstall\SpyAxe
Value : URLInfoAbout
Possible Browser Hijack attempt Object Recognized!
Type : RegValue
Data : Software\Microsoft\Windows\CurrentVersion\Uninstall\SpyAxe "http://www.spyaxe.com"
TAC Rating : 4
Category : Malware
Comment : (
http://www.spyaxe.com)
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Windows\CurrentVersion\Uninstall\SpyAxe
Value : Publisher
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 7
Objects found so far: 35
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 35
Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 35
Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Malware.SpyAxe Object Recognized!
Type : Regkey
Data :
TAC Rating : 4
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : appid\spyaxe.exe
Malware.SpyAxe Object Recognized!
Type : Regkey
Data :
TAC Rating : 4
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\windows\currentversion\app paths\spyaxe.exe
Malware.SpyAxe Object Recognized!
Type : Folder
TAC Rating : 4
Category : Malware
Comment : Malware.SpyAxe
Object : C:\Documents and Settings\MLC\Start Menu\Programs\SpyAxe
Malware.SpyAxe Object Recognized!
Type : Folder
TAC Rating : 4
Category : Malware
Comment : Malware.SpyAxe
Object : C:\Program Files\SpyAxe
Malware.SpyAxe Object Recognized!
Type : Folder
TAC Rating : 4
Category : Malware
Comment : Malware.SpyAxe
Object : C:\Program Files\spyaxe\Lang
Malware.SpyAxe Object Recognized!
Type : Folder
TAC Rating : 4
Category : Malware
Comment : Malware.SpyAxe
Object : C:\Program Files\spyaxe\Quarantine
Malware.SpyAxe Object Recognized!
Type : File
Data : SpyAxe 3.0.lnk
TAC Rating : 4
Category : Malware
Comment :
Object : C:\Documents and Settings\MLC\Start Menu\
Malware.SpyAxe Object Recognized!
Type : File
Data : SpyAxe 3.0.lnk
TAC Rating : 4
Category : Malware
Comment :
Object : C:\Documents and Settings\MLC\Application Data\microsoft\internet explorer\quick launch\
Malware.SpyAxe Object Recognized!
Type : File
Data : SpyAxe.lnk
TAC Rating : 4
Category : Malware
Comment :
Object : C:\Documents and Settings\MLC\Desktop\
Malware.SpyAxe Object Recognized!
Type : File
Data : SpyAxe 3.0 Website.lnk
TAC Rating : 4
Category : Malware
Comment :
Object : C:\Documents and Settings\MLC\Start Menu\Programs\spyaxe\
Malware.SpyAxe Object Recognized!
Type : File
Data : SpyAxe 3.0.lnk
TAC Rating : 4
Category : Malware
Comment :
Object : C:\Documents and Settings\MLC\Start Menu\Programs\spyaxe\
Malware.SpyAxe Object Recognized!
Type : File
Data : Uninstall SpyAxe 3.0.lnk
TAC Rating : 4
Category : Malware
Comment :
Object : C:\Documents and Settings\MLC\Start Menu\Programs\spyaxe\
Malware.SpyAxe Object Recognized!
Type : File
Data : English.ini
TAC Rating : 4
Category : Malware
Comment :
Object : C:\Program Files\spyaxe\lang\
Malware.SpyAxe Object Recognized!
Type : File
Data : msvcp71.dll
TAC Rating : 4
Category : Malware
Comment :
Object : C:\Program Files\spyaxe\
FileVersion : 7.10.3077.0
ProductVersion : 7.10.3077.0
ProductName : Microsoft® Visual Studio .NET
CompanyName : Microsoft Corporation
FileDescription : Microsoft® C++ Runtime Library
InternalName : MSVCP71.DLL
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : MSVCP71.DLL
Malware.SpyAxe Object Recognized!
Type : File
Data : msvcr71.dll
TAC Rating : 4
Category : Malware
Comment :
Object : C:\Program Files\spyaxe\
FileVersion : 7.10.3052.4
ProductVersion : 7.10.3052.4
ProductName : Microsoft® Visual Studio .NET
CompanyName : Microsoft Corporation
FileDescription : Microsoft® C Runtime Library
InternalName : MSVCR71.DLL
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : MSVCR71.DLL
Malware.SpyAxe Object Recognized!
Type : File
Data : signatures.ref
TAC Rating : 4
Category : Malware
Comment :
Object : C:\Program Files\spyaxe\
Malware.SpyAxe Object Recognized!
Type : File
Data : SpyAxe.exe
TAC Rating : 4
Category : Malware
Comment :
Object : C:\Program Files\spyaxe\
FileVersion : 3.0.0.0
ProductVersion : 3.0.0.0
ProductName : SpyAxe
CompanyName : SpyAxe.com
FileDescription : Anti-spyware software
InternalName : spyaxe
LegalCopyright : (c) SpyAxe.com. All rights reserved.
OriginalFilename : spyaxe.exe
Malware.SpyAxe Object Recognized!
Type : File
Data : SpyAxe.url
TAC Rating : 4
Category : Malware
Comment :
Object : C:\Program Files\spyaxe\
Malware.SpyAxe Object Recognized!
Type : File
Data : uninst.exe
TAC Rating : 4
Category : Malware
Comment :
Object : C:\Program Files\spyaxe\
FileVersion : 3.0.0.0
ProductName : SpyAxe 3.0
CompanyName : SpyAxe
FileDescription : SpyAxe Software Installer
LegalCopyright : 2004, All rights reserverd (c) SpyAxe.
OriginalFilename : SpyAxe_Setup.exe
Comments : Anti-Spyware Software
Malware.SpyAxe Object Recognized!
Type : File
Data : SpyAxe.lnk
TAC Rating : 4
Category : Malware
Comment : Shortcut to bad file : C:\Documents and Settings\MLC\Desktop\SpyAxe.lnk
Object : C:\Documents and Settings\MLC\Desktop\
Malware.SpyAxe Object Recognized!
Type : File
Data : SpyAxe 3.0.lnk
TAC Rating : 4
Category : Malware
Comment : Shortcut to bad file : C:\Documents and Settings\MLC\Start Menu\Programs\SpyAxe\SpyAxe 3.0.lnk
Object : C:\Documents and Settings\MLC\Start Menu\Programs\SpyAxe\
Malware.SpyAxe Object Recognized!
Type : File
Data : SpyAxe 3.0.lnk
TAC Rating : 4
Category : Malware
Comment : Shortcut to bad file : C:\Documents and Settings\MLC\Start Menu\SpyAxe 3.0.lnk
Object : C:\Documents and Settings\MLC\Start Menu\
Malware.SpyAxe Object Recognized!
Type : File
Data : SpyAxe 3.0 Website.lnk
TAC Rating : 4
Category : Malware
Comment : Shortcut to bad file : C:\Documents and Settings\MLC\Start Menu\Programs\SpyAxe\SpyAxe 3.0 Website.lnk
Object : C:\Documents and Settings\MLC\Start Menu\Programs\SpyAxe\
Malware.SpyAxe Object Recognized!
Type : File
Data : Uninstall SpyAxe 3.0.lnk
TAC Rating : 4
Category : Malware
Comment : Shortcut to bad file : C:\Documents and Settings\MLC\Start Menu\Programs\SpyAxe\Uninstall SpyAxe 3.0.lnk
Object : C:\Documents and Settings\MLC\Start Menu\Programs\SpyAxe\
Other Object Recognized!
Type : File
Data : SPYAXE.EXE-1E39CDF6.pf
TAC Rating : 7
Category : Malware
Comment :
Object : C:\WINDOWS\prefetch\
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 25
Objects found so far: 60
20:59:03 Scan Complete
Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:10:39.875
Objects scanned:143715
Objects identified:53
Objects ignored:0
New critical objects:53
Thank you - hope this helps. Mojo.