 |
Spyware Warrior Help with Spyware, Hijacking & Other Internet Nuisances
|
| View previous topic :: View next topic |
| Author |
Message |
wawadave Warrior Obsessed

Joined: 25 Jan 2004 Last Visit: 24 Jul 2009 Posts: 3448 Location: Illegitimus non carborundum
|
Posted: Wed Apr 21, 2004 12:06 pm Post subject: Norton 2004, Adaware & Spybot can not remove |
|
|
http://www.driverheaven.net/
Adspy-Virus that Norton 2004, Adaware & Spybot can not remove
Posted on Monday, April 19, 2004
at 6:44 PM by zerodamage - 47 Comments
I've come across the ugliest spyware to date. This thing will just not go away by normal means. Adaware, Spybot, nothing will remove it at this time.
I've been working on removing this spyware infection on a customer's computer for 2 days now. Adaware has an update to find the infection but what happens is that it can not be removed. Spybot doesn't detect it either. What happens is that Adaware finds this and says it will have to reboot, even in safe mode, and when the computer restarts, this spyware kills Adaware from starting up at startup. This spyware also connects to the internet and installs other spyware. Not only that but it digs itself into the Winlogon.exe file. You do NOT want this thing on your computer. The only way to remove this thing right now is by reinstalling windows and possibly by other complicated methods. Norton Antivirus 2004 did not detect it.
Now this thing is called: VX2.BetterInternet
The file is ausmsext.cpy.dll located in your system32 folder. This thing uses different DLL files and makes copies.
There is also a registry entry going into Hkey_Local_Machine/Software/Microsoft/Windows NT/winlogon/notify/guardian
Adaware classifies this thing as a Data Miner. Now there are ways to remove this but none of them are 100% and it finds ways of getting back. So the only sure way of removing this is a format and reinstall of Windows. Adaware finds it but can not fully remove it.
You can see how ugly this thing can be at the Adaware forums Here.
To help you avoid getting this thing, avoid the sites listed at: PCSympathy.com
This seems to be the only working method for removing this thing. It did not work for me but has worked for many others if you have this thing on your computer. Read the instructions Here
There is some good news in all of this. Spyware Blaster blocks this from ever installing on your system. You can download it from Javacoolsoftware. Remember to update after installing it. Also make sure you enable all of the protection.
These types of infections are only going to get worse. Laws need to be put into place to punish companies that do this.
UPDATE: I noticed this and it should tell you a lot about this VX2 stuff. Companies name was VX2 based out of the U.K.
Read about it here: ZDnet http://news.zdnet.co.uk/internet/0,39020369,2103354,00.htm
_________________ RFID tags! SPYWARE
Tired of proprietary Cor-pirationware?
http://www.openoffice.org/
Installing Vista http://tinyurl.com/2l9qyd |
|
| Back to top |
|
 |
Nick Site Admin

Joined: 27 Feb 2004 Last Visit: 28 Aug 2012 Posts: 3913 Location: California
|
Posted: Wed Apr 21, 2004 8:51 pm Post subject: |
|
|
I know, it is nasty and even using Hijackthis won't remove it, as it may not even show in the log. It's also known as Look2me. It hides very well and will change it's filenames when being searched for. It requires several special tools and lots knowlege and time to kill it and then it may still be there... _________________ Nick's Security Ticker
 |
|
| Back to top |
|
 |
CalamityKen Warrior Addict

Joined: 06 Mar 2004 Last Visit: 26 Aug 2004 Posts: 611 Location: Ont. Canada
|
|
| Back to top |
|
 |
Angry Homer Junior Member

Joined: 24 Apr 2004 Last Visit: 17 Jul 2006 Posts: 36
|
Posted: Mon Apr 26, 2004 6:51 am Post subject: |
|
|
man, this thing sound like the flesh eating bacteria, but in computers!! damn them! damn them all to hell!!! _________________ I say kill the bastards first and ask questions later!! |
|
| Back to top |
|
 |
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
smartBlue Style © 2002 Smartor
Powered by phpBB © 2001, 2002 phpBB Group
|