Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Very Pesky Spyware Problem... VX2.BetterInternet?

Posted on 2004-09-21
8
Medium Priority
?
421 Views
Last Modified: 2010-04-11
Alright... Here's what i've got... Every 5 minutes or so, i get an IE popup.  The sites vary, but the most common ones are:
http://www.xzoomy.com
http://69.20.56.3/yyy10.html
http://69.20.62.53/yyy10.html
http://www.ad-w-a-r-e.com/cgi-bin/PopupV2?ID={BCA284CF-8715-4592-BB7D-456387DAF378}
http://www.888.com  (This one only comes up once, when i first start my computer, as a popup right after I open IE for the first time)

It happens more often when i'm at the computer than when i'm not, or so it seems.  That could be me just noticing it more and getting pissed off.

My full (Yes, full) Hijack this log:

Logfile of HijackThis v1.98.2
Scan saved at 1:17:42 PM, on 9/21/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\MsPMSPSv.exe
D:\D-Tools\daemon.exe
D:\AIM\aim.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
E:\Exe Files\HijackThis.exe

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [DAEMON Tools-1033] "D:\D-Tools\daemon.exe"  -lang 1033
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] D:\AIM\aim.exe -cnetwait.odl
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\AIM\aim.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{463189F6-44A5-442F-86A3-2EDCF7757BA0}: NameServer = 128.115.25.3,130.203.1.4


I looked around and found that some people with the yyy10.html popups had something called VX2.betterinternet.  I downloaded a fix for that (VX2Finder.exe), ran it and it found a key, but no files to delete.  Here's the log from that.

Log for VX2.BetterInternet File Finder

Files Found---


Guardian Key--- is called:

User Agent String---
{BCA284CF-8715-4592-BB7D-456387DAF378}


That user agent string is the same ID that's in the URL for one of the popups, so i know they're linked somehow.  VX2Finder gives me 2 options, Restore Policy and User Agent$, and neither of them do anything.  I've run a virus scan locally, from housecall.trendmicro.com, run the latest Hijackthis, CWShredder, Spybot, and Adaware all in safe mode.  Nothing seems to stick out.  500 points for this, as it's REALLY bothering me.   Please help!


0
Comment
Question by:EvilAardvark
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
8 Comments
 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 12114679
Hello EvilAardvark =)

Create a New User Account and check there for these problems..... post back results and we will move further from there !! :)
0
 
LVL 2

Author Comment

by:EvilAardvark
ID: 12114813
I've been logged in on the other user account for about 5-10 minutes with no popups.  It seems to work fine over here.
0
 
LVL 2

Author Comment

by:EvilAardvark
ID: 12114840
scratch that.. Just got a popup to http://69.20.62.53/yyy10.html
0
Use Case: Protecting a Hybrid Cloud Infrastructure

Microsoft Azure is rapidly becoming the norm in dynamic IT environments. This document describes the challenges that organizations face when protecting data in a hybrid cloud IT environment and presents a use case to demonstrate how Acronis Backup protects all data.

 
LVL 2

Author Comment

by:EvilAardvark
ID: 12114927
I'm definitely getting the same popups regardless of which account i'm on.
0
 
LVL 65

Accepted Solution

by:
SheharyaarSaahil earned 1000 total points
ID: 12115088
ok so when u run the spyware removal tools..... they come as clean,,,,, or picks up, deletes them, and when back in normal mode, they returns back ??
u are running SP2, so u must be having IE built-in popup blocker,,,,, still getting those popups ??
are u sure u have ur System Restore turned off ??
0
 
LVL 2

Author Comment

by:EvilAardvark
ID: 12115424
It picks them up and deletes them, they come back even in safe mode.  
I have the IE popup blocker, and still get the pop ups.
Yes, system restore is off.

I think i fixed the problem on my own... Here's what i did:

I checked the filenames that kept coming back, and found there was a file with the same last modified date/time and same size as those in my windows/system32 directory, hidden, by the name of aeaamon.dll.  I couldn't delete it because it was "in use" (even in safe mode), so i went into my recovery console and found i still couldn't delete it...  SOOOOO I renamed it to "stupidfile.dmb" and restarted.  I deleted stupidfile.dmb in windows (Normal mode) and it deleted fine.  I ran spybot, adaware and all the others again and cleaned all the remnants.  Looks like i beat it!
0
 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 12115640
that's great ^_^

that's the benefit of having ur system infront of u where u can look and search all the inches of system !!  ;-D
Happy Computing and Cheers =)
0
 
LVL 29

Expert Comment

by:blue_zee
ID: 12117418

Try this:

http://www.downloads.subratam.org/VX2Finder.exe
The latest Look2Me Fix for Win2K/XP

Also this:

http://downloads.subratam.org/VX2Finder(126).exe
New Version for L2M

Zee
0

Featured Post

Cyber Threats to Small Businesses (Part 2)

The evolving cybersecurity landscape presents SMBs with a host of new threats to their clients, their data, and their bottom line. In part 2 of this blog series, learn three quick processes Webroot’s CISO, Gary Hayslip, recommends to help small businesses beat modern threats.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article is written by John Gates, CISSP. Gates, the SNUG President-Elect, currently holds the position of Manager of Information Systems at Lake Park High School in Roselle, Illinois.
Will you be ready when the clock on GDPR compliance runs out? Is GDPR even something you need to worry about? Find out more about the upcoming regulation changes and download our comprehensive GDPR checklist today !
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question