Solved

Trying to remove Spyware/Adware coming from www.ad-a-w-a-r-e.com.

Posted on 2004-09-20
5
286 Views
Last Modified: 2010-04-11
Hello,

I have a user in our organization that it consistenly getting windows that are popping up that have the above website address in them.  As of right now, I have added the following information to the hosts file that is on the user's XP Pro machine:

127.0.0.1   www.ad-a-w-a-r-e.com

However, several of these pop-up duing the day on the user's machine.  The user gets the page cannot be displayed message, but that is still somewhat annoying.

I've ran Ad-Aware SE, SpyBot S&D and HijackThis! all the latest editions with the latest definition files, but they do not find anything that seems out of the ordinary.

Can anyone help me figure out where these www.ad-a-w-a-r-e.com messages are coming from?

Thank you,
theposse
0
Comment
Question by:theposse
5 Comments
 
LVL 4

Expert Comment

by:beem4n
ID: 12109347
Hi,
try installing panda antivirus - it works good with spybots.

Also you can run "msconfig" -> and check what files are loading at startup.
Locate by the name your spyware - remove it from startup, reboot, then delete manually from hdd.
0
 
LVL 21

Expert Comment

by:jvuz
ID: 12111088
Check with stinger:

http://vil.nai.com/vil/stinger/
0
 
LVL 21

Expert Comment

by:jvuz
ID: 12111090
0
 
LVL 1

Assisted Solution

by:sevie
sevie earned 100 total points
ID: 12114543
Xp AntiSpy - http://www.xp-antispy.org/  for turning off unneeded Win XP services that only can generat u trafic and can be used as back door

Those programs are very useful for cleaning spywares:
SpySweeper - http://www.spychecker.com/program/spysweeper.html
SpywareBlaster - http://www.spychecker.com/program/spywareblaster.html
CoolWebShredder - http://www.spychecker.com/program/coolwebshredder.html
Stinger - http://vil.nai.com/vil/stinger 
Anti-Trojan 5.5.421 -
a2free  - http://www.emsisoft.com/en/ 
bazookasetup - http://www.kephyr.com/spywarescanner/
BHODemon 2.0
LSPFix  - http://cexx.org/lspfix.htm 
Spyware Doctor
Spy-Ad Exterminator  - http://www.oreware.com 
ect

and use a firewall to stop the unwanted trafic


0
 
LVL 3

Accepted Solution

by:
browolf earned 25 total points
ID: 12505803
one of  the problems with that url is you cant look for it in google cos it ignores the '-' ,  which means you need to use a different search engine. I found this page
http://computing.net/security/wwwboard/forum/13928.html
which contains the following helpful advice:

For those who are suffering like I did with constant pop-up ads from ad-w-a-r-e.com the situation's been resolved.

It turns out I'd been infected by 'Look2Me', the common name for the 'VX2.BetterInternet' trojan. Here are the steps I took (BREAK@MMX YOU ROCK HARDCORE!):

1. Internet Explorer > "Tools" Pulldown > "Internet Options..." > "Advanced" tab > Turn off all the 'Install On Demand' as well as 'Enable third party browser extensions'. That'll keep it from being downloaded in the first place.

2. http://downloads.subratam.org/VX2Finder9x(126).exe > Run From Current Location. This will wipe it out if you do have it.
0

Featured Post

Free camera licenses with purchase of My Cloud NAS

Milestone Arcus software is compatible with thousands of industry-leading cameras for added flexibility. Upon installation on your My Cloud NAS, you will receive two (2) camera licenses already enabled in the software. And for a limited time, get additional camera licenses FREE.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Every computer eventually fails. When that happens, your valuable data is only as safe as your current backup.
These days, all we hear about hacktivists took down so and so websites and retrieved thousands of user’s data. One of the techniques to get unauthorized access to database is by performing SQL injection. This article is quite lengthy which gives bas…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now