?
Solved

Very Pesky Spyware Problem... VX2.BetterInternet?

Posted on 2004-09-21
8
Medium Priority
?
425 Views
Last Modified: 2010-04-11
Alright... Here's what i've got... Every 5 minutes or so, i get an IE popup.  The sites vary, but the most common ones are:
http://www.xzoomy.com
http://69.20.56.3/yyy10.html
http://69.20.62.53/yyy10.html
http://www.ad-w-a-r-e.com/cgi-bin/PopupV2?ID={BCA284CF-8715-4592-BB7D-456387DAF378}
http://www.888.com  (This one only comes up once, when i first start my computer, as a popup right after I open IE for the first time)

It happens more often when i'm at the computer than when i'm not, or so it seems.  That could be me just noticing it more and getting pissed off.

My full (Yes, full) Hijack this log:

Logfile of HijackThis v1.98.2
Scan saved at 1:17:42 PM, on 9/21/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\MsPMSPSv.exe
D:\D-Tools\daemon.exe
D:\AIM\aim.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
E:\Exe Files\HijackThis.exe

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [DAEMON Tools-1033] "D:\D-Tools\daemon.exe"  -lang 1033
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] D:\AIM\aim.exe -cnetwait.odl
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\AIM\aim.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{463189F6-44A5-442F-86A3-2EDCF7757BA0}: NameServer = 128.115.25.3,130.203.1.4


I looked around and found that some people with the yyy10.html popups had something called VX2.betterinternet.  I downloaded a fix for that (VX2Finder.exe), ran it and it found a key, but no files to delete.  Here's the log from that.

Log for VX2.BetterInternet File Finder

Files Found---


Guardian Key--- is called:

User Agent String---
{BCA284CF-8715-4592-BB7D-456387DAF378}


That user agent string is the same ID that's in the URL for one of the popups, so i know they're linked somehow.  VX2Finder gives me 2 options, Restore Policy and User Agent$, and neither of them do anything.  I've run a virus scan locally, from housecall.trendmicro.com, run the latest Hijackthis, CWShredder, Spybot, and Adaware all in safe mode.  Nothing seems to stick out.  500 points for this, as it's REALLY bothering me.   Please help!


0
Comment
Question by:EvilAardvark
  • 4
  • 3
8 Comments
 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 12114679
Hello EvilAardvark =)

Create a New User Account and check there for these problems..... post back results and we will move further from there !! :)
0
 
LVL 2

Author Comment

by:EvilAardvark
ID: 12114813
I've been logged in on the other user account for about 5-10 minutes with no popups.  It seems to work fine over here.
0
 
LVL 2

Author Comment

by:EvilAardvark
ID: 12114840
scratch that.. Just got a popup to http://69.20.62.53/yyy10.html
0
Firewall Management 201 with Professor Wool

In this whiteboard video, Professor Wool highlights the challenges, benefits and trade-offs of utilizing zero-touch automation for security policy change management. Watch and Learn!

 
LVL 2

Author Comment

by:EvilAardvark
ID: 12114927
I'm definitely getting the same popups regardless of which account i'm on.
0
 
LVL 65

Accepted Solution

by:
SheharyaarSaahil earned 1000 total points
ID: 12115088
ok so when u run the spyware removal tools..... they come as clean,,,,, or picks up, deletes them, and when back in normal mode, they returns back ??
u are running SP2, so u must be having IE built-in popup blocker,,,,, still getting those popups ??
are u sure u have ur System Restore turned off ??
0
 
LVL 2

Author Comment

by:EvilAardvark
ID: 12115424
It picks them up and deletes them, they come back even in safe mode.  
I have the IE popup blocker, and still get the pop ups.
Yes, system restore is off.

I think i fixed the problem on my own... Here's what i did:

I checked the filenames that kept coming back, and found there was a file with the same last modified date/time and same size as those in my windows/system32 directory, hidden, by the name of aeaamon.dll.  I couldn't delete it because it was "in use" (even in safe mode), so i went into my recovery console and found i still couldn't delete it...  SOOOOO I renamed it to "stupidfile.dmb" and restarted.  I deleted stupidfile.dmb in windows (Normal mode) and it deleted fine.  I ran spybot, adaware and all the others again and cleaned all the remnants.  Looks like i beat it!
0
 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 12115640
that's great ^_^

that's the benefit of having ur system infront of u where u can look and search all the inches of system !!  ;-D
Happy Computing and Cheers =)
0
 
LVL 29

Expert Comment

by:blue_zee
ID: 12117418

Try this:

http://www.downloads.subratam.org/VX2Finder.exe
The latest Look2Me Fix for Win2K/XP

Also this:

http://downloads.subratam.org/VX2Finder(126).exe
New Version for L2M

Zee
0

Featured Post

KuppingerCole Reviews AlgoSec in Executive Report

Leading analyst firm, KuppingerCole reviews AlgoSec's Security Policy Management Solution, and the security challenges faced by companies today in their Executive View report.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

It's not just another paperwork submission. Serious planning and rigour to managing the whole thought processes need to be put in place. The intent is not on drilling into the details, but to share tips in getting the first thing right to kick-start…
Although free tools can be helpful to a limited extent, it’s better to stick to paid versions for business use.
We’ve all felt that sense of false security before—locking down external access to a database or component and feeling like we’ve done all we need to do to secure company data. But that feeling is fleeting. Attacks these days can happen in many w…
In a question here at Experts Exchange (https://www.experts-exchange.com/questions/29062564/Adobe-acrobat-reader-DC.html), a member asked how to create a signature in Adobe Acrobat Reader DC (the free Reader product, not the paid, full Acrobat produ…

599 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question