Advertise here as low as $250/month

Home Message Board SBN Articles User Reviews Bike Specs Register Pictures Classifieds Bike Project How To's
MarketPlace Dealers Chat Top Sites Links SBN Store Forum Rules Contributors Sponsors Contact Us Advertising Information

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Go Back   Sportbikes.net > Topic Discussions > Open Forums
Register Subscribe Casino Garage FAQ Members List Calendar Arcade Search Today's Posts Mark Forums Read

Open Forums The Open forum was created for people to discuss anything else Non-Moto related. Just about anything goes! Please remember this is a loosely moderated area. If you do not have thick skin. We suggest you stay out of here.

» Site Sponsors
OPP RacingAmericanMotorcyclistAssociationKomodoGear.comSoloMotoPartsSpringfield ArmoryCheapCycleParts.comSportbikeTrackGearSportbikeTrackGearSuperbikeToyStore.comChainDrain.comNice CycleBikeBanditSee your ad here!

Reply
 
LinkBack Thread Tools Display Modes
Old 10-03-2004, 07:44 PM   #1 (permalink)
Krazy Hawaiian
Dam Munky!
 
Krazy Hawaiian's Avatar
 
Join Date: Jun 2004
Location: Hawaii
Age: 52
Posts: 13,281
Casino Cash: $250
Sportbike: 92 Suzuki GSXR 711 a 1100 engine in a 750 frame
Krazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond repute
Awards Showcase
Green Token: Green SBN Token - Issue reason:  Yellow Token: Yellow SBN Token - Issue reason:  
Total Awards: 2
Exclamation How to Remove VX2/f Spyware....

There's another pain in the a** spyware out and about called VX2/f there are several variants of it and the latest /f variant cannot be removed with Adaware or SpyBot.

I got the new VX2/f version from h**p://www.rage3d.com/ looking for drivers for my ATI vid card. Before it loaded Rage 3D there was a redirect and I wasn't watching and suddenly I was on a blank page and the status bar said downloading from site then I saw the address had changed and as I closed the window all hell broke loose.

This new version has a hidden .dll file that is seperate from the main program that now not only reinstalls itself after it's deleted but it also downloads tons of other crap the instant it senses a connection to the internet.

In my case I removed it, reboted like Adaware 6 Pro asked so it could run before anything loaded and remove the remaining files and when windows was up and running with in 45 seconds it had killed the Google Popup stopper and opened close to 30 - 50 windows. I couldn't close them as fast as they were opening! Cntrl + Alt + Del and killed explorer in the task manager was only a momentairy stop. They imeaditly began opening like crazy again.

I finally disconnected the ethernet cable from the router, closed the windows ran Adaware and SpyBot and in that wild frenzy it collected 6+Mbs of crap!
It apears to be a group effort from VX2, Powerscan, Ezula (theres no way in hell I'd let that in knowingly) BroadcastPC, Bookspace, SideSearch, BargainBuddy, WebBargains, Downloadware, SideFind, Sahware, 180Solutions, TopMoxie, IPInsite, ISTBar, Virtumundo, NetworkEssentials and about 20 toolbars and other shit...

Check the picture of Adaware after scanning, SpyBot found another 200+ entries after I ran Adaware!

*****************************************************************************

How to Remove this POS Crap.....

This information is from Tom Coyote's Forum on Spyware (one of the best, but little known spyware info sites) right now there the only site with any info on removing this POS.

Both the Adaware and SpyBot Forume were asking for users to send them any info or working methods to remove it!

Follow the instructions below and use the tool in the zip file (HiJackThis Ver 1.98.2) to locate the files listed below.

DO NOT CLICK ANY OF THE LINKS BELOW! Only Click the Link for HiJackThis Ver 1.98.2! It's at the very bottom.

Run Hijack This! and fix these items:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=

R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {0000607D-D204-42C7-8E46-216055BF9918} - C:\WINNT\mxTarget.dll

O2 - BHO: (no name) - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINNT\systb.dll

O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)

O4 - HKLM\..\Run: [aktgiicgnhdkc] C:\WINNT\system32\qphuto.exe

O4 - HKLM\..\Run: [zjhqwiwxncpty] C:\WINNT\system32\qphuto.exe

O4 - HKLM\..\Run: [Win Server Updt] C:\WINNT\wupdt.exe

O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub...sh/swflash.cab


Reboot in "safe" mode. Press F8 during the beggining of the boot sequence to get a menu of options for starting windows. Select safe mode.

Find and delete:

c:\winnt\mxtarget.dll <--- file

c:\winnt\systb.dll <--- file

c:\winnt\system32\qphuto.exe <--- file

c:\winnt\wupdt.exe <--- file


After doing that you should be rid of the POS. ARUGH what a pain in the ass. Not as bad as CoolWebSearch was but still no fun. Good Luck!
Aloha, KH
Attached Images
File Type: jpg holy_shit.jpg (50.7 KB, 0 views)
Attached Files
File Type: zip hijackthis_Ver 1.98.2.zip (178.9 KB, 3 views)
__________________


Open Forum and Motocross Forum MODERATOR


The more I Learn about Women, The More I Love my Motorcycles!

*********

Last edited by Krazy Hawaiian : 10-03-2004 at 07:49 PM.
Krazy Hawaiian is offline   Reply With Quote
Sponsored Links
Advertisement
 

Old 10-03-2004, 08:10 PM   #2 (permalink)
MotoTiller
Club Racer
 
MotoTiller's Avatar
 
Join Date: Jul 2004
Location: home
Age: 40
Posts: 85
Casino Cash: $250
Sportbike: none
MotoTiller is on a distinguished road
Default

Why not just use Mozilla Firefox instead of IE?
MotoTiller is offline   Reply With Quote
Old 10-03-2004, 08:41 PM   #3 (permalink)
xXx
SBN Rookie
 
Join Date: Aug 2004
Location: socaL
Age: 26
Posts: 27
Casino Cash: $250
Sportbike: 2004 Blue Yamaha YZF R6
xXx is on a distinguished road
Default

You know, You can also (if using XP Home, Or Pro) goto: Start, Programs, Accessories, System Tools, *System Restore*. It will then restore back 1 day - a few months in time. I have used this twice after getting attacked with those damn adwares/popups, etc, etc, etc ARGH! So, I restored to the day or two before I got hit with the attack, and it got rid of all of it! I also scanned with other things suchas, Anti virus, and adware removers and cleaned up anything that might have been left behind, but indeedly enough the system restore brought my PC right back to how it was minutes before all hell broke loose. Goodluck to those who have this happen and if your on XP try this method works great!
__________________
-Josh D.
2004 BLUE Yamaha YZF-R6
Greggs Flushmounts
Targa Solo Seat Cowl
Intuitive *Race* Frame Sliders
Dr. X Taillight Conversion/Pivot Kit.
xXx is offline   Reply With Quote
Old 10-03-2004, 09:02 PM   #4 (permalink)
Krazy Hawaiian
Dam Munky!
 
Krazy Hawaiian's Avatar
 
Join Date: Jun 2004
Location: Hawaii
Age: 52
Posts: 13,281
Casino Cash: $250
Sportbike: 92 Suzuki GSXR 711 a 1100 engine in a 750 frame
Krazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond repute
Awards Showcase
Green Token: Green SBN Token - Issue reason:  Yellow Token: Yellow SBN Token - Issue reason:  
Total Awards: 2
Default

I won't use Firefox because you still HAVE to have IE to get winhoes updates..... Microslop won't take anything else kind of a double edged sword thing. With all the holes in windows you'd be alot better off updating it, and IE can be setup to do exactly what FF does, mine uasually is, except I had to turn Active X on to update the XP Corprate Ed. I have and forgot to tuen it off DOH !

I dont bother with sys restore for 2 reasons, 1 it's a resource hog (and my comp is old n slow (Athalon 2000 512 ram with it on the new games play like crap) I got this thing for free except for the drive - $49 comp USA special Plus you learn more fixing it yourself.....

2 Sys Restore eats up a bunch of disk space, I only have a little bit of free space (maybe 5-6 gigs total of 80 gigs total, too many movies and no DVD burner ) System Restore can easily gobble several gigs of space. I'd rather keep Faster, One Man's Island and a bunch other new movies than have winhoes hogging it, especially since I don't have cable tv, just RoadRunner.

It's bad enough as it is the way it keeps copies of every dam thing installed and downloaded in its hidden folders...
__________________


Open Forum and Motocross Forum MODERATOR


The more I Learn about Women, The More I Love my Motorcycles!

*********
Krazy Hawaiian is offline   Reply With Quote
Old 10-03-2004, 09:09 PM   #5 (permalink)
Krazy Hawaiian
Dam Munky!
 
Krazy Hawaiian's Avatar
 
Join Date: Jun 2004
Location: Hawaii
Age: 52
Posts: 13,281
Casino Cash: $250
Sportbike: 92 Suzuki GSXR 711 a 1100 engine in a 750 frame
Krazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond repute
Awards Showcase
Green Token: Green SBN Token - Issue reason:  Yellow Token: Yellow SBN Token - Issue reason:  
Total Awards: 2
Default

Thinking about sys restore I don't know if it would work or not with this thing, remember it has a "hidden" .dll that unless it's wiped off the disk it's going to repeat it's same old thing on it..... you have to get rid ot the .dll or it will just come right back.

At least this one doesn't rename and move itself to a new folder everytime the parent is deleted like CoolWebSearch does.. That is one of the hardest to get rid of things I ever ran across.
__________________


Open Forum and Motocross Forum MODERATOR


The more I Learn about Women, The More I Love my Motorcycles!

*********
Krazy Hawaiian is offline   Reply With Quote
Old 10-03-2004, 09:23 PM   #6 (permalink)
MotoTiller
Club Racer
 
MotoTiller's Avatar
 
Join Date: Jul 2004
Location: home
Age: 40
Posts: 85
Casino Cash: $250
Sportbike: none
MotoTiller is on a distinguished road
Default

Didn't know about still having to use IE for updates, mine just auto updated to service pack 2 today through firefox -I didn't see any sign of IE being used at all
MotoTiller is offline   Reply With Quote
Old 10-04-2004, 12:39 AM   #7 (permalink)
Krazy Hawaiian
Dam Munky!
 
Krazy Hawaiian's Avatar
 
Join Date: Jun 2004
Location: Hawaii
Age: 52
Posts: 13,281
Casino Cash: $250
Sportbike: 92 Suzuki GSXR 711 a 1100 engine in a 750 frame
Krazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond reputeKrazy Hawaiian has a reputation beyond repute
Awards Showcase
Green Token: Green SBN Token - Issue reason:  Yellow Token: Yellow SBN Token - Issue reason:  
Total Awards: 2
Talking

Hmmm, that isn't what is says here.....

http://news.zdnet.com/2100-9588_22-5388755.html

also mentions something about a fix for 10 security flaws.... http://news.zdnet.com/2100-3513_22-5368397.html

More on the flaws from a security site.. http://secunia.com/advisories/12526


and a few more from the US Government computer emergency readiness team at Homeland Security.

US-CERT VU#651928:
http://www.kb.cert.org/vuls/id/651928

US-CERT VU#847200:
http://www.kb.cert.org/vuls/id/847200

US-CERT VU#460528:
http://www.kb.cert.org/vuls/id/460528

US-CERT VU#808216:
http://www.kb.cert.org/vuls/id/808216

US-CERT VU#113192:
http://www.kb.cert.org/vuls/id/113192

US-CERT VU#327560:
http://www.kb.cert.org/vuls/id/327560

US-CERT VU#125776:
http://www.kb.cert.org/vuls/id/125776

US-CERT VU#414240:
http://www.kb.cert.org/vuls/id/414240

US-CERT VU#653160:
http://www.kb.cert.org/vuls/id/653160

IE doesn't look all that bad I guess...


there is no perfect software.
__________________


Open Forum and Motocross Forum MODERATOR


The more I Learn about Women, The More I Love my Motorcycles!

*********

Last edited by Krazy Hawaiian : 10-04-2004 at 12:47 AM.
Krazy Hawaiian is offline   Reply With Quote
Old 10-04-2004, 01:25 PM   #8 (permalink)
no_morelipfrom_you
Superbike Champion
 
Join Date: Jul 2004
Location: CA
Age: 32
Posts: 317
Casino Cash: $250
Sportbike: 2000 Katana 600
no_morelipfrom_you has disabled reputation
Default

I use firefox for everything and only open IE when I need to use technet or download some windows updates. Its worth it.
no_morelipfrom_you is offline   Reply With Quote
Old 10-04-2004, 01:28 PM   #9 (permalink)
firefighter81
#1 Gear Nazi
 
firefighter81's Avatar
 
Join Date: Jun 2004
Location: Okinawa
Age: 29
Posts: 4,734
Casino Cash: $17849
Sportbike: 2001 Yamaha R1
firefighter81 will become famous soon enoughfirefighter81 will become famous soon enough
Default

This is sorta on topic, I finally downloaded Ad-Aware, never really found the use for it, but anyways, it's been searching through all my files and so far it's found "327 New Critical Objects" guess I should have downloaded this a while ago!
__________________
If you want me to "find Jesus" I'm gonna need a shovel and a map - Me
firefighter81 is offline   Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -5. The time now is 06:02 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0
© 1997 - 2007 Sportbikes.net INC. All Rights Reserved.