Security Stronghold security made easy

How to remove SpyAxe (ads, banners, deals)



Threat's profile Threat indicator: HIGH

Name of the threat:SpyAxe

Command or file name:wuau32.exe

Threat type:Adware

Affected OS:Win32/Win64 (Windows XP, Vista/7, 8/8.1, Windows 10)

Affected browsers:Google Chrome, Mozilla Firefox, Internet Explorer, Safari

Adware is in general seen by the designer as a way to repair development costs but really it makes everything boring and create a covet to remove adware. Adware is any software package which mechanically plays, depicts or downloads advertisements to a computer after the software is installed creating a requirement to remove adware. is called private information-invasive software. The whole group housing malware, adware, trackware, etc. Adware products present commersializing materials treatment every chance appeared, so it is preferable to have adware removal tool installed to perform adware removal operation. One more reason to remove adware is that it labours advertisement such as notification or hotlinks on websites that are not a share of page's coded character set. Adware is a share of banner depict commersializing on the Internet and most users are unaware that adware is running on their computers as they don't have adware removal tool to detect and remove adware. If adware came from shareware programs it's often endamaged and while operating displays needless, periodic alarms, so, remove adware a.s.a.p.. You will require to install adware removal tool as adware may add dispatchers to your favorites and your desktop. With adware there is no presage that the software is setup and adware don't have de-installation routine, so adware removal is hard without adware removal tool. !!!You're pretty much startled with adware, aren't you? Searching results from adware broken toolbars may be constrained to only sites that pay for position controlling.


SpyAxe intrusion method

SpyAxe installs on your PC along with free software. This method is called "bundled installation". Freeware offers you to install additional module (SpyAxe). Then if you fail to decline the offer it starts hidden installation. SpyAxe copies its file(s) to your hard disk. Its typical file name is wuau32.exe. Then it creates new startup key with name SpyAxe and value wuau32.exe. You can also find it in your processes list with name wuau32.exe or SpyAxe. Also, it can create folder with name SpyAxe under C:\Program Files\ or C:\ProgramData. If you have further questions about SpyAxe, please ask below. You can use programs to remove SpyAxe from your browsers below.


Download Removal Tool

Download this advanced removal tool and solve problems with SpyAxe and wuau32.exe (download of fix will start immediately):

Download WiperSoft Antispyware to remove SpyAxe

* WiperSoft Antispyware was developed to remove threats like SpyAxe in automatic mode. Remover has active module to protect PC from hijackers, trojans, ransomware and other viruses. Trial version of Wipersoft provides detection of computer viruses for FREE. To remove malware, you have to purchase the full version of Wipersoft.


Features of WiperSoft Antispyware Malware Remediation Tool

  • Removes all files created by viruses.
  • Removes all registry entries created by viruses.
  • You can activate System and Network Guards and forget about malware.
  • Can fix browser problems and protect browser settings.
  • Removal is guaranteed - if Removal Tool fails ask for FREE support.
  • 24/7 Spyware Helpdesk Support included into the package.

Download Spyhunter Remediation Tool by Enigma Software

Download antimalware designed specifically to remove threats like SpyAxe and wuau32.exe (download of fix will start immediately):

Download AntiMalware to remove SpyAxe

Features of Spyhunter Remediation Tool

  • Removes all files created by SpyAxe.
  • Removes all registry entries created by SpyAxe.
  • Fixes browser redirection and hijack if needed.
  • "Toolbar Remover" tool will help you get rid of unwanted browser extensions.
  • Removal is guaranteed - if Spyhunter Remediation Tool fails ask for FREE support.
  • 24/7 Helpdesk Support and 5 hours of Remote Support via GoToAssist included into the package.


We noticed that you are on smartphone or tablet now, but you need this solution on your PC. Enter your email below and we’ll automatically send you an email with the downloading link for SpyAxe Removal Tool, so you can use it when you are back to your PC.

Privacy Policy


Let our support team solve your problem with SpyAxe and remove SpyAxe right now!

Submit support ticket below and describe your problem with SpyAxe. Support team will offer you solution in several minutes and give a step-by-step instruction on how to remove SpyAxe. Trouble-free tech support with over 10 years experience removing malware.
Submit support ticket

Software Industry Professionals Member Threat's description and solution are developed by Security Stronghold security team.

Here you can also learn:


How to remove SpyAxe manually

This problem can be solved manually by deleting all registry keys and files connected with SpyAxe, removing it from startup list and unregistering all corresponding DLLs. Additionally missing DLL's should be restored from distribution in case they are corrupted by SpyAxe.

To get rid of SpyAxe, you should:

1. Kill the following processes and delete the appropriate files:

  • spyaxe.exe
  • hpE951.tmp
  • I found the mssearchnet.exe
  • sa1.exe
  • SpywareAxe.exe
  • sa_setup.exe
  • spywareaxe 3.0.lnk
  • spywareaxe.lnk
  • spywareaxe.url
  • spywareaxe 3.0 website.lnk
  • uninstall spywareaxe 3.0.lnk
  • 0fd1a8eb.tmp
  • salanguage.ini
  • dbver[1].dat
  • spyfalcon 3.1.lnk
  • spyfalcon 3.1 website.lnk
  • uninstall spyfalcon 3.1.lnk
  • 507b8750.tmp
  • sflanguage.ini
  • ss_setup.exe
  • 3fca41b8.tmp
  • sslanguage.ini
  • sheriff.exe
  • 08_05_2006_15_59_22_15.log
  • adwaresheriff.exe
  • 10_05_2006_13_58_35_546.log
  • Spy-Quake2.exe
  • hp101.tmp
  • sf.ini
  • spyaxe.ini
  • saignorelist.dat
  • is-1e7bu.tmp
  • is-8ai7d.tmp
  • is-nt2un.tmp
  • is-mcpm0.tmp
  • is-949ho.tmp
  • is-f109p.tmp
  • is-rea5s.tmp
  • is-vhufm.tmp
  • is-8iu6r.tmp
  • is-rlqeb.tmp
  • is-765d6.tmp
  • is-cp8ac.tmp
  • is-6e0nb.tmp
  • is-bncnv.tmp
  • ncompat.tlb
  • wuau32.exe

Warning: you should delete only those files which checksums are listed as malicious. There may be valid files with the same names in your system. We recommend you to use WiperSoft Antispyware Malware Remediation Tool for safe problem solution.

**Trial version of Wipersoft provides detection of computer viruses for FREE. To remove malware, you have to purchase the full version of Wipersoft.

2. Delete the following malicious folders:

  • %programfiles%\SpyAxe\
  • %windows%\system32\
  • %commonprogramfiles%\adwaresheriff\
  • %programfiles%\SpyAxe\
  • %programfiles%\SpyFalcon\
  • %programfiles%\SpyFalcon\Lang\
  • %programfiles%\SpyFalcon\Logs\
  • %programfiles%\SpyFalcon\Quarantine\
  • %programfiles%\SpywareAxe\
  • %programfiles%\SpywareAxe\Lang\
  • %programfiles%\SpywareAxe\Quarantine\
  • %programfiles%\SpywareStrike\
  • %programfiles%\SpywareStrike\Lang\
  • %programfiles%\SpywareStrike\Quarantine\
  • %startmenu%\Programs\SpyFalcon\
  • %startmenu%\Programs\SpywareAxe\
  • %startmenu%\Programs\SpywareStrike\
  • %programfiles%\adwaresheriff\interface\
  • %programfiles%\adwaresheriff\sounds\
  • %autostart% \adwaresheriff\
  • %profile%\local settings\application data\adwaresheriff\quarantine\
  • %profile%\local settings\application data\adwaresheriff\db\run_backup\
  • %autostart% \spywareaxe\
  • %autostart% \spyfalcon\
  • %autostart% \spywarestrike\
  • %profile%\local settings\temporary internet files\content.ie5\21uh2d6z\
  • %programfiles%\spyquake2.com\

3. Delete the following malicious registry entries and\or values:

  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}
  • Key: Software\SpyFalcon
    Value: refid
  • Key: Applications\SpyFalcon.exe
  • Key: software\classes\appid\{C1A8B6A1-2C81-1C3D-A3C6-A1CCDB10B47F}
  • Key: software\classes\appid\spyaxe.exe
  • Key: SOFTWARE\Classes\AppID\SpywareStrike.EXE
  • Key: software\classes\clsid\{06506b3a-857d-431f-be0b-038b1ec386b3}
  • Key: software\classes\clsid\{0bff94f7-9748-43d1-bac4-d963351b63e7}
  • Key: software\classes\clsid\{0c580891-ca9d-4619-bdc9-85378eb65931}
  • Key: software\classes\clsid\{53525a6c-3774-4b47-b317-bc7dfe4fc7ed}
  • Key: software\classes\clsid\{5deb9a24-19e0-49e6-a6b2-110bc3e1062a}
  • Key: software\classes\clsid\{5e1ace2a-8638-4775-8aa9-5c187ad40a82}
  • Key: software\classes\clsid\{629c4fe9-b627-4905-af5b-ad652bb1b5c5}
  • Key: software\classes\clsid\{659f78ea-6ff2-40f8-8ea3-06f7418a209e}
  • Key: software\classes\clsid\{7616a7f7-df99-432f-870d-4afea0d079f4}
  • Key: software\classes\clsid\{7eb22f36-2ccd-4003-89ee-6cf40ebc4282}
  • Key: software\classes\clsid\{a0d06aa3-499b-4156-9ffd-0be236f0d4e5}
  • Key: software\classes\clsid\{b6610f1d-da77-42c4-8300-721d9da9d70b}
  • Key: software\classes\spyaxe.backup
  • Key: software\classes\spyaxe.backup.1
  • Key: software\classes\spyaxe.enginelistener
  • Key: software\classes\spyaxe.enginelistener.1
  • Key: software\classes\spyaxe.log
  • Key: software\classes\spyaxe.log.1
  • Key: software\classes\spyaxe.logrecord
  • Key: software\classes\spyaxe.logrecord.1
  • Key: software\classes\spyaxe.paths
  • Key: software\classes\spyaxe.paths.1
  • Key: software\classes\spyaxe.quarantine
  • Key: software\classes\spyaxe.quarantine.1
  • Key: software\classes\spyaxe.runas
  • Key: software\classes\spyaxe.runas.1
  • Key: software\classes\spyaxe.scanner
  • Key: software\classes\spyaxe.scanner.1
  • Key: software\classes\spyaxe.searchitem
  • Key: software\classes\spyaxe.searchitem.1
  • Key: software\classes\spyaxe.threatcollection
  • Key: software\classes\spyaxe.threatcollection.1
  • Key: SOFTWARE\Classes\TypeLib\{0F7DF776-BBD8-493B-85C7-6A23E2571E38}
  • Key: SOFTWARE\Classes\TypeLib\{244B730E-D899-4E38-9428-03D1143242E0}
  • Key: software\classes\typelib\{2bb3bcbf-411a-4c67-8e69-f4bb301dc333}
  • Key: SOFTWARE\Classes\TypeLib\{6D42E870-6D15-4C82-8C78-ECD53FF5B6F0}
  • Key: Software\Microsoft\Windows\CurrentVersion\App Paths\SpyFalcon.exe
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\spywareaxe.exe
  • Key: SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpywareStrike.exe
  • Key: Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu
    \Programs\SpyFalcon
  • Key: Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu
    \Programs\SpywareStrike
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\SpyFalcon
    Value: DisplayName
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\SpywareAxe
    Value: DisplayName
  • Key: Software\SpywareAxe
    Value: ref
  • Key:
    CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\Implemented Categories\{62C8FE65-4EBB-45E7-B440-6E39B2CDBF29}
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\InprocServer32
    Value: ThreadingModel
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\ProgId
  • Key: TypeLib\{6D42E870-6D15-4C82-8C78-ECD53FF5B6F0}\1.0
  • Key: TypeLib\{6D42E870-6D15-4C82-8C78-ECD53FF5B6F0}\1.0\FLAGS
  • Key: TypeLib\{6D42E870-6D15-4C82-8C78-ECD53FF5B6F0}\1.0\0\win32
  • Key: TypeLib\{6D42E870-6D15-4C82-8C78-ECD53FF5B6F0}\1.0\HELPDIR
  • Key: Interface\{250CB705-B9F5-4C77-A8C0-8D9D436FCFF4}
  • Key: Interface\{250CB705-B9F5-4C77-A8C0-8D9D436FCFF4}\ProxyStubClsid
  • Key: Interface\{250CB705-B9F5-4C77-A8C0-8D9D436FCFF4}\ProxyStubClsid32
  • Key: Interface\{250CB705-B9F5-4C77-A8C0-8D9D436FCFF4}\TypeLib
    Value: Version
  • Key: Interface\{FCF0A3DD-9231-4625-84C6-4810BBE5F54B}
  • Key: Interface\{FCF0A3DD-9231-4625-84C6-4810BBE5F54B}\ProxyStubClsid
  • Key: Interface\{FCF0A3DD-9231-4625-84C6-4810BBE5F54B}\ProxyStubClsid32
  • Key: Interface\{FCF0A3DD-9231-4625-84C6-4810BBE5F54B}\TypeLib
    Value: Version
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\InprocServer32
    Value: ThreadingModel
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\ProgID
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\VersionIndependentProgID
  • Key: SpyFalcon.PopupBlockerConnector.1
  • Key: SpyFalcon.PopupBlockerConnector.1\CLSID
  • Key: SpyFalcon.PopupBlockerConnector
  • Key: SpyFalcon.PopupBlockerConnector\CLSID
  • Key: SpyFalcon.PopupBlockerConnector\CurVer
  • Key: CLSID\{008E3200-28EB-463b-9B58-75C23D80911A}
  • Key: CLSID\{008E3200-28EB-463b-9B58-75C23D80911A}\ProgID
  • Key: CLSID\{008E3200-28EB-463b-9B58-75C23D80911A}\VersionIndependentProgID
  • Key: CLSID\{008E3200-28EB-463b-9B58-75C23D80911A}\LocalServer32
  • Key: CLSID\{008E3200-28EB-463b-9B58-75C23D80911A}\TypeLib
  • Key: Interface\{7CC220DA-D962-4935-AD3A-21F7CA4962E3}
  • Key: Interface\{7CC220DA-D962-4935-AD3A-21F7CA4962E3}\ProxyStubClsid
  • Key: Interface\{7CC220DA-D962-4935-AD3A-21F7CA4962E3}\ProxyStubClsid32
  • Key: Interface\{7CC220DA-D962-4935-AD3A-21F7CA4962E3}\TypeLib
    Value: Version
  • Key: Interface\{E9B91E0C-305A-4DD2-9987-B3B0C254C6DE}
  • Key: Interface\{E9B91E0C-305A-4DD2-9987-B3B0C254C6DE}\ProxyStubClsid
  • Key: Interface\{E9B91E0C-305A-4DD2-9987-B3B0C254C6DE}\ProxyStubClsid32
  • Key: Interface\{E9B91E0C-305A-4DD2-9987-B3B0C254C6DE}\TypeLib
    Value: Version
  • Key: Interface\{5796859D-53C4-46C1-AD6F-2A3C4D4306EB}
  • Key: Interface\{5796859D-53C4-46C1-AD6F-2A3C4D4306EB}\ProxyStubClsid
  • Key: Interface\{5796859D-53C4-46C1-AD6F-2A3C4D4306EB}\ProxyStubClsid32
  • Key: Interface\{5796859D-53C4-46C1-AD6F-2A3C4D4306EB}\TypeLib
    Value: Version
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\jqVtnzai
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\mtQqSm
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\iiHsfOlbnc
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\pVcmdotxyO
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\zmEuynwi
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\lobp
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\wduZdsduaoYij
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\aVeiFek
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\aVwSKDXkwZb
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\qlQom
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\tdcsaWvRz
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\zdluasd
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\xXbntnCcutP
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\nxsuTz
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\gkbiCPhn
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\HhUzbJAcAyrx
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\zWcgZyG
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\ejztqgovGg
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\mfwwf
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\wqbE
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\ujfhuweykic
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\0
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\0
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\HNLHSvffY
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\wjxqdcepM
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\oZrXchjbfZ
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\gVmLd
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\BeWfd
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\JyxZrpkbz
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\xMjhjPUitt
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\UbpqpN
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\YcYztiQgjXr
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\dfne
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\ogfunkz
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\wdodtcu
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\qMdkPWysdwpIx
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\tCRLndmwZyc
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\itxYmi
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\gfpvntdn
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\jRcxpwghnU
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\rFtjgouzP
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\zQgObdrv
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\lvoPru
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\ntuzhvFyDN
  • Key: Interface\{44B2F61F-7081-4B93-AE50-CD568548E4A7}
  • Key: Interface\{44B2F61F-7081-4B93-AE50-CD568548E4A7}\ProxyStubClsid
  • Key: Interface\{44B2F61F-7081-4B93-AE50-CD568548E4A7}\ProxyStubClsid32
  • Key: Interface\{44B2F61F-7081-4B93-AE50-CD568548E4A7}\TypeLib
    Value: Version
  • Key: Interface\{7C987433-CAB4-499A-A0CE-A518F3C54E96}
  • Key: Interface\{7C987433-CAB4-499A-A0CE-A518F3C54E96}\ProxyStubClsid
  • Key: Interface\{7C987433-CAB4-499A-A0CE-A518F3C54E96}\ProxyStubClsid32
  • Key: Interface\{7C987433-CAB4-499A-A0CE-A518F3C54E96}\TypeLib
    Value: Version
  • Key: Interface\{DEA859D7-ABB8-4239-B454-6731F4891560}
  • Key: Interface\{DEA859D7-ABB8-4239-B454-6731F4891560}\ProxyStubClsid
  • Key: Interface\{DEA859D7-ABB8-4239-B454-6731F4891560}\ProxyStubClsid32
  • Key: Interface\{DEA859D7-ABB8-4239-B454-6731F4891560}\TypeLib
    Value: Version
  • Key: Interface\{9AD637EF-97F0-4F13-AA24-E84AA5C0E1CE}
  • Key: Interface\{9AD637EF-97F0-4F13-AA24-E84AA5C0E1CE}\ProxyStubClsid
  • Key: Interface\{9AD637EF-97F0-4F13-AA24-E84AA5C0E1CE}\ProxyStubClsid32
  • Key: Interface\{9AD637EF-97F0-4F13-AA24-E84AA5C0E1CE}\TypeLib
    Value: Version
  • Key: Interface\{C74D1FC2-A047-44FD-B1D1-2E7F193F1762}
  • Key: Interface\{C74D1FC2-A047-44FD-B1D1-2E7F193F1762}\ProxyStubClsid
  • Key: Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
    Value: {A1D9D3F0-8C2A-9A1D-A376-2CACFB10AB72}
  • Key: Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
    Value: {A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F}
  • Key: Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
    Value: {A2D9D3F0-8C2A-2A1D-A376-1BECFB10AB72}
  • Key: Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
    Value: {C1A2FDA2-1A5B-2A8F-F3A2-B22DA1A3C41D}
  • Key: Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
    Value: {C1A2FDA2-2A5B-2C8A-F2A2-BA2DB3A2C31C}
  • Key: Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
    Value: {C1A8B6A1-2C81-1C3D-A3C6-A1CCDB10B47F}
  • Key: Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
    Value: {C9FA1DC9-1FB3-C2A8-2F1A-DC1A33E7AF9D}
  • Key: Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
    Value: {D1A2E7CD-F5C1-21A8-CA2C-13D0AC72D19D}
  • Key: Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
    Value: {D81E2FC4-B0A2-11D3-21AC-07C04C21A18A}
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\InprocServer32
    Value: Class
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\InprocServer32
    Value: Assembly
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\InprocServer32
    Value: RuntimeVersion
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\InprocServer32\1.0.5000.0
    Value: Class
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\InprocServer32\1.0.5000.0
    Value: Assembly
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\InprocServer32\1.0.5000.0
    Value: RuntimeVersion
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\InprocServer32\2.0.0.0
    Value: RuntimeVersion
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\InprocServer32\2.0.0.0
    Value: Assembly
  • Key: CLSID\{957BAB51-81FF-8195-F273-D7E286EA702F}\InprocServer32\2.0.0.0
    Value: Class
  • Key: Software\Licenses
    Value: {I4FBD2E52B24702B5}
  • Key: Software\Licenses
    Value: {04FBD2E52B24702B5}
  • Key: AppID\SpyAxe.EXE
    Value: AppID
  • Key: Software\Licenses
    Value: {I484BBA8980BF0CFD}
  • Key: Software\Licenses
    Value: {0484BBA8980BF0CFD}
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\AdwareSheriff_is1
    Value: Inno Setup: Setup Version
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\AdwareSheriff_is1
    Value: Inno Setup: App Path
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\AdwareSheriff_is1
    Value: InstallLocation
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\AdwareSheriff_is1
    Value: Inno Setup: Icon Group
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\AdwareSheriff_is1
    Value: Inno Setup: User
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\AdwareSheriff_is1
    Value: Inno Setup: Selected Tasks
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\AdwareSheriff_is1
    Value: Inno Setup: Deselected Tasks
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\AdwareSheriff_is1
    Value: DisplayName
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\AdwareSheriff_is1
    Value: DisplayIcon
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\AdwareSheriff_is1
    Value: UninstallString
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\AdwareSheriff_is1
    Value: QuietUninstallString
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\AdwareSheriff_is1
    Value: Publisher
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\AdwareSheriff_is1
    Value: URLInfoAbout
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\AdwareSheriff_is1
    Value: HelpLink
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\AdwareSheriff_is1
    Value: URLUpdateInfo
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\AdwareSheriff_is1
    Value: NoModify
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\AdwareSheriff_is1
    Value: NoRepair
  • Key:
    Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{16e0d49c-e067-11da-ae2b-806d6172696f}

    Value: BaseClass
  • Key: Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
    Value: {64ba30a2-811a-4597-b0af-d551128be340}
  • Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winkxq32
    Value: Asynchronous
  • Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winkxq32
    Value: DllName
  • Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winkxq32
    Value: Impersonate
  • Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winkxq32
    Value: Startup
  • Key: SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winkxq32
    Value: Shutdown
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winkxq32
    Value: Asynchronous
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winkxq32
    Value: DllName
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winkxq32
    Value: Impersonate
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winkxq32
    Value: Startup
  • Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winkxq32
    Value: Shutdown
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\SpyFalcon
    Value: UninstallString
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\SpyFalcon
    Value: DisplayIcon
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\SpyFalcon
    Value: DisplayVersion
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\SpyFalcon
    Value: NSIS:StartMenuDir
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\SpyFalcon
    Value: URLInfoAbout
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\SpyFalcon
    Value: Publisher
  • Key: Software\SpyFalcon
    Value: Language
  • Key: CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}\InprocServer32
    Value: InprocServer32
  • Key: Software\SpywareAxe
    Value: Language
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\SpywareAxe
    Value: UninstallString
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\SpywareAxe
    Value: DisplayIcon
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\SpywareAxe
    Value: DisplayVersion
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\SpywareAxe
    Value: NSIS:StartMenuDir
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\SpywareAxe
    Value: URLInfoAbout
  • Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\SpywareAxe
    Value: Publisher
  • Key: software\microsoft\internet explorerinternet0%\Main
    Value: Default_Page_URL
    Data: ~~~security2k.net
  • Key: software\microsoft\internet explorerinternet0%\Main
    Value: Default_Search_URL
    Data: ~~~security2k.net
  • Key: software\microsoft\internet explorerinternet0%\Main
    Value: First Home Page
    Data: ~~~security2k.net
  • Key: software\microsoft\internet explorerinternet0%\Main
    Value: Local Page
    Data: ~~~security2k.net
  • Key: software\microsoft\internet explorerinternet0%\Main
    Value: Search Bar
    Data: ~~~security2k.net
  • Key: software\microsoft\internet explorerinternet0%\Main
    Value: Search Page
    Data: ~~~security2k.net
  • Key: software\microsoft\internet explorerinternet0%\Main
    Value: Start Page
    Data: ~~~security2k.net
  • Key: software\microsoft\internet explorerinternet0%\Search
    Value: CustomizeSearch
    Data: ~~~security2k.net
  • Key: software\microsoft\internet explorerinternet0%\Search
    Value: Default_Page_URL
    Data: ~~~security2k.net
  • Key: software\microsoft\internet explorerinternet0%\Search
    Value: Default_Search_URL
    Data: ~~~security2k.net
  • Key: software\microsoft\internet explorerinternet0%\Search
    Value: SearchAssistant
    Data: ~~~security2k.net

Warning: if value is listed for some registry entries, you should only clear these values and leave keys with such values untouched. We recommend you to use WiperSoft Antispyware Malware Remediation Tool for safe problem solution.


Uninstall SpyAxe related programs from Control Panel

We recommend you to check list of installed programs and search for SpyAxe entry or other unknown and suspicious programs. Below are instructions for different version if Windows. In some cases adware programs are protected by malicious service or process and it will not allow you to uninstall it. If SpyAxe won't uninstall or gives you error message that you do not have sufficient rights to do this perform below instructions in Safe Mode or Safe Mode with Networking or use WiperSoft Antispyware Malware Remediation Tool.


Windows 10

  • Click on the Start menu and choose Settings
  • Then click on System and choose Apps & Features in the left column
  • Find SpyAxe under in the list and click Uninstall button near it.
  • Confirm by clicking Uninstall button in opened window if necessary.

Windows 8/8.1

  • Right click on the bottom left corner of the screen (while on your desktop)
  • In the menu choose Control Panel
  • Click Uninstall a program under Programs and Features.
  • Locate programs that can be connected with SpyAxe or other related suspicious program.
  • Click Uninstall button.
  • Wait until uninstall process is complete.

Windows 7/Vista

  • Click Start and choose Control Panel.
  • Choose Programs and Features and Uninstall a program.
  • In the list of installed programs find entries related to SpyAxe
  • Click Uninstall button.

Windows XP

  • Click Start
  • In the menu choose Control Panel
  • Choose Add / Remove Programs.
  • Find SpyAxe related entries.
  • Click Remove button.

Remove SpyAxe related extensions from your browsers

SpyAxe in some cases can be accompanied with browsers extension. We recommend you to use free option Toolbar Remover under Tools in Spyhunter Remediation Tool to remove unwanted browser extensions related to SpyAxe. We recommend you to perform scan your PC with Removal Tool or Spyhunter Remediation Tool. To remove extenions from your browsers manually do the following:

Internet Explorer

  • While in Internet Explorer click cogwheel icon in the top right corner
  • In the menu choose the Manage Add-ons
  • Select Toolbar and Extension tab.
  • Choose add-on possibly related to SpyAxe or other related adware BHO.
  • Click Disable button.

Warning: This option will only disable unwanted plugin. For effective SpyAxe removal use WiperSoft Antispyware Malware Remediation Tool.

Google Chrome

  • Start Google Chrome.
  • In the address bar type chrome://extensions/
  • In the list of add-ons find related to SpyAxe and click recycle bin icon.
  • Confirm SpyAxe removal.

Mozilla Firefox

  • Open Firefox
  • In the address bar type about:addons
  • Click Extensions tab.
  • In the list of extension locate ones related to SpyAxe.
  • Click Remove button near it.

Protect computer and browsers from infection

Adware threats like SpyAxe are very widespread and, unfortunately, many anti-virus programs fail to detect it. To protect your computer from future infection we recommend you to use WiperSoft Antispyware Malware Remediation Tool, it has active protection module and browser settings guard. It does not conflict with any anti-virus programs and creates additional shield against threats like SpyAxe.


Popular threat: removing alexa

Home | Partners | Shop | Support | Terms of use | Contact Us | Privacy Policy | Sitemap

Copyright © 2024 Security Stronghold. All Rights Reserved. All content on this website is protected and belongs to Security Stronghold LLC.