Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Trying to remove Spyware/Adware coming from www.ad-a-w-a-r-e.com.

Posted on 2004-09-20
5
Medium Priority
?
306 Views
Last Modified: 2010-04-11
Hello,

I have a user in our organization that it consistenly getting windows that are popping up that have the above website address in them.  As of right now, I have added the following information to the hosts file that is on the user's XP Pro machine:

127.0.0.1   www.ad-a-w-a-r-e.com

However, several of these pop-up duing the day on the user's machine.  The user gets the page cannot be displayed message, but that is still somewhat annoying.

I've ran Ad-Aware SE, SpyBot S&D and HijackThis! all the latest editions with the latest definition files, but they do not find anything that seems out of the ordinary.

Can anyone help me figure out where these www.ad-a-w-a-r-e.com messages are coming from?

Thank you,
theposse
0
Comment
Question by:theposse
5 Comments
 
LVL 4

Expert Comment

by:beem4n
ID: 12109347
Hi,
try installing panda antivirus - it works good with spybots.

Also you can run "msconfig" -> and check what files are loading at startup.
Locate by the name your spyware - remove it from startup, reboot, then delete manually from hdd.
0
 
LVL 21

Expert Comment

by:jvuz
ID: 12111088
Check with stinger:

http://vil.nai.com/vil/stinger/
0
 
LVL 21

Expert Comment

by:jvuz
ID: 12111090
0
 
LVL 1

Assisted Solution

by:sevie
sevie earned 400 total points
ID: 12114543
Xp AntiSpy - http://www.xp-antispy.org/  for turning off unneeded Win XP services that only can generat u trafic and can be used as back door

Those programs are very useful for cleaning spywares:
SpySweeper - http://www.spychecker.com/program/spysweeper.html
SpywareBlaster - http://www.spychecker.com/program/spywareblaster.html
CoolWebShredder - http://www.spychecker.com/program/coolwebshredder.html
Stinger - http://vil.nai.com/vil/stinger 
Anti-Trojan 5.5.421 -
a2free  - http://www.emsisoft.com/en/ 
bazookasetup - http://www.kephyr.com/spywarescanner/
BHODemon 2.0
LSPFix  - http://cexx.org/lspfix.htm 
Spyware Doctor
Spy-Ad Exterminator  - http://www.oreware.com 
ect

and use a firewall to stop the unwanted trafic


0
 
LVL 3

Accepted Solution

by:
browolf earned 100 total points
ID: 12505803
one of  the problems with that url is you cant look for it in google cos it ignores the '-' ,  which means you need to use a different search engine. I found this page
http://computing.net/security/wwwboard/forum/13928.html
which contains the following helpful advice:

For those who are suffering like I did with constant pop-up ads from ad-w-a-r-e.com the situation's been resolved.

It turns out I'd been infected by 'Look2Me', the common name for the 'VX2.BetterInternet' trojan. Here are the steps I took (BREAK@MMX YOU ROCK HARDCORE!):

1. Internet Explorer > "Tools" Pulldown > "Internet Options..." > "Advanced" tab > Turn off all the 'Install On Demand' as well as 'Enable third party browser extensions'. That'll keep it from being downloaded in the first place.

2. http://downloads.subratam.org/VX2Finder9x(126).exe > Run From Current Location. This will wipe it out if you do have it.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Ransomware - Defeated! Client opened the wrong email and was attacked by Ransomware. I was able to use file recovery utilities to find shadow copies of the encrypted files and make a complete recovery.
The Internet has made sending and receiving information online a breeze. But there is also the threat of unauthorized viewing, data tampering, and phoney messages. Surprisingly, a lot of business owners do not fully understand how to use security t…
Is your data getting by on basic protection measures? In today’s climate of debilitating malware and ransomware—like WannaCry—that may not be enough. You need to establish more than basics, like a recovery plan that protects both data and endpoints.…
In a question here at Experts Exchange (https://www.experts-exchange.com/questions/29062564/Adobe-acrobat-reader-DC.html), a member asked how to create a signature in Adobe Acrobat Reader DC (the free Reader product, not the paid, full Acrobat produ…

876 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question