Solved

Trying to remove Spyware/Adware coming from www.ad-a-w-a-r-e.com.

Posted on 2004-09-20
5
284 Views
Last Modified: 2010-04-11
Hello,

I have a user in our organization that it consistenly getting windows that are popping up that have the above website address in them.  As of right now, I have added the following information to the hosts file that is on the user's XP Pro machine:

127.0.0.1   www.ad-a-w-a-r-e.com

However, several of these pop-up duing the day on the user's machine.  The user gets the page cannot be displayed message, but that is still somewhat annoying.

I've ran Ad-Aware SE, SpyBot S&D and HijackThis! all the latest editions with the latest definition files, but they do not find anything that seems out of the ordinary.

Can anyone help me figure out where these www.ad-a-w-a-r-e.com messages are coming from?

Thank you,
theposse
0
Comment
Question by:theposse
5 Comments
 
LVL 4

Expert Comment

by:beem4n
ID: 12109347
Hi,
try installing panda antivirus - it works good with spybots.

Also you can run "msconfig" -> and check what files are loading at startup.
Locate by the name your spyware - remove it from startup, reboot, then delete manually from hdd.
0
 
LVL 21

Expert Comment

by:jvuz
ID: 12111088
Check with stinger:

http://vil.nai.com/vil/stinger/
0
 
LVL 21

Expert Comment

by:jvuz
ID: 12111090
0
 
LVL 1

Assisted Solution

by:sevie
sevie earned 100 total points
ID: 12114543
Xp AntiSpy - http://www.xp-antispy.org/  for turning off unneeded Win XP services that only can generat u trafic and can be used as back door

Those programs are very useful for cleaning spywares:
SpySweeper - http://www.spychecker.com/program/spysweeper.html
SpywareBlaster - http://www.spychecker.com/program/spywareblaster.html
CoolWebShredder - http://www.spychecker.com/program/coolwebshredder.html
Stinger - http://vil.nai.com/vil/stinger
Anti-Trojan 5.5.421 -
a2free  - http://www.emsisoft.com/en/
bazookasetup - http://www.kephyr.com/spywarescanner/
BHODemon 2.0
LSPFix  - http://cexx.org/lspfix.htm
Spyware Doctor
Spy-Ad Exterminator  - http://www.oreware.com
ect

and use a firewall to stop the unwanted trafic


0
 
LVL 3

Accepted Solution

by:
browolf earned 25 total points
ID: 12505803
one of  the problems with that url is you cant look for it in google cos it ignores the '-' ,  which means you need to use a different search engine. I found this page
http://computing.net/security/wwwboard/forum/13928.html
which contains the following helpful advice:

For those who are suffering like I did with constant pop-up ads from ad-w-a-r-e.com the situation's been resolved.

It turns out I'd been infected by 'Look2Me', the common name for the 'VX2.BetterInternet' trojan. Here are the steps I took (BREAK@MMX YOU ROCK HARDCORE!):

1. Internet Explorer > "Tools" Pulldown > "Internet Options..." > "Advanced" tab > Turn off all the 'Install On Demand' as well as 'Enable third party browser extensions'. That'll keep it from being downloaded in the first place.

2. http://downloads.subratam.org/VX2Finder9x(126).exe > Run From Current Location. This will wipe it out if you do have it.
0

Featured Post

Complete Microsoft Windows PC® & Mac Backup

Backup and recovery solutions to protect all your PCs & Mac– on-premises or in remote locations. Acronis backs up entire PC or Mac with patented reliable disk imaging technology and you will be able to restore workstations to a new, dissimilar hardware in minutes.

Join & Write a Comment

This paper addresses the security of Sennheiser DECT Contact Center and Office (CC&O) headsets. It describes the DECT security chain comprised of “Pairing”, “Per Call Authentication” and “Encryption”, which are all part of the standard DECT protocol.
It’s a strangely common occurrence that when you send someone their login details for a system, they can’t get in. This article will help you understand why it happens, and what you can do about it.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now