Options

VX2 Spyware Help Needed - clean_wish

Hello all!! I'm new to this site so forgive me if I do something wrong but from what I've seen, you guys are life savers! :D I'm having a problem with a stubborn bit of spyware and if anyone could help me with it, I'd appreciate it! I've been running Ad-aware all day and I keep getting a message stating that the objects named VX2 cannot be deleted until I restart my computer and at which time Ad-aware will run and then delete them.

Each time I've rebooted, Ad-aware doesn't start on it's own and after running it manually, it gives me the same message .. never removing the VX2 items. I've tried doing a systems restore back to a time before this problem but each time the messages are still received and the VX2's are still there. I followed instructions I read elsewhere where I showed hidden files and folders, showed system operating utilities (I think is the word), and disabled my systems restore. Afterwards, I ran Hijack This and the log I received is as follows

ogfile of HijackThis v1.98.2
Scan saved at 12:55:47 AM, on 11/22/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\PROGRAM FILES\MUSICMATCH\MUSICMATCH JUKEBOX\MM_TRAY.EXE
C:\WINDOWS\SYSTEM\HPSYSDRV.EXE
C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\SYSTEM\LXSUPMON.EXE
C:\PROGRAM FILES\ACNIELSEN\HOMESCAN INTERNET TRANSPORTER\HSTRANS.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\MOZILLA.ORG\MOZILLA\MOZILLA.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\START MENU\PROGRAMS\STARTUP\HTILYY.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\KEYBDMGR.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\LEXPPS.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMUSBKB2.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://games.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R3 - URLSearchHook: (no name) - _{707E6F76-9FFB-4920-A976-EA101271BC25} - (no file)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN1\YCOMP5_5_7_0.DLL
O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN1\YCOMP5_5_7_0.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Keyboard Manager] C:\Program Files\Netropa\One-touch Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [HPScanPatch] C:\WINDOWS\SYSTEM\HPScanFix.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MusicMatch\MusicMatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [Delay] C:\WINDOWS\delayrun.exe
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
O4 - HKLM\..\Run: [OSSProxy] C:\WINDOWS\SYSTEM\OSSPROXY.EXE -boot
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [LexStart] LexStart.EXE
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\SYSTEM\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [Megapanel] C:\Program Files\ACNielsen\Homescan Internet Transporter\HSTrans.exe
O4 - HKLM\..\Run: [kofxah] C:\WINDOWS\SYSTEM\rbjqlsid.exe
O4 - HKLM\..\Run: [Narrator] C:\WINDOWS\wrbkyy.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\Program Files\mozilla.org\Mozilla\Mozilla.exe" -turbo
O4 - Startup: htilyy.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O10 - Broken Internet access because of LSP provider 'osmim.dll' missing
O14 - IERESET.INF: START_PAGE_URL=http://hp.my.yahoo.com
O16 - DPF: {869F3BBC-A812-4D13-A93B-7B3FC816DCD5} (McAfee.com Updater) - http://download.mcafee.com/molbin/clinic/virusscan/mcasupd.cab
O16 - DPF: {4855C21B-E452-4661-A702-ED3493CE74DF} - http://sp.ask.com/docs/toolbar/download/askbar-inst.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.6.cab
O16 - DPF: {20359788-0CE3-4AEC-BA27-2B36B4E2E300} (nsBrowserConfig Class 2) - https://www.opinionsquare.com/globalconfig/ngc_activex.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/abarth/us/win/QuickTimeInstaller.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://antu.popcap.com/games/popcaploader_v5.cab
O16 - DPF: {4C226336-4032-489F-9674-67E74225979B} (OTXMovie Class) - http://www.otxresearch.com/OTXMedia/OTXMedia.dll
O16 - DPF: {084F552D-19EB-4668-9788-984CBC781A8F} (AsyncDownloader Class) - http://survey.otxresearch.com/Preloader.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab

I don't want to accidentally delete anything useful so if an expert could take a look at it and tell me which to get rid of, I'd really appreciate it :) Thank you so much for taking the time to read all of this .. I have a rotten habit of rambling.

Comments

  • CrunchieCrunchie Mandurah. Western Australia. Member
    edited November 2004
    download the VX cleaner plug in for Adaware. Install it, then open Adaware & go to *add-ons* & run the plug-in. If anything is found, select *clean system* & when done, reboot & run Adaware & let it finish the clean-up. Reboot again.

    http://www.lavasoftusa.com/software/plugins/vx2cleaner.shtml
  • edited November 2004
    Thank you for answering but it didn't work. This thing refuses to be deleted. I did as you said but after running ad-aware the screen freezes during the "delete". It's been frozen for over 40 minutes now and the list is still there. It did this to me twice, the first time I closed the window, rebooted and then ran it again and right now it's still "deleting". Thanks so much for your help though :)
  • CrunchieCrunchie Mandurah. Western Australia. Member
    edited November 2004
    Please download Kill2Me from here & run it to remove Look2Me from your computer.
    This will only work on the older versions.
  • edited November 2004
    Older versions of windows? I'm running on ME. I downloaded and ran Kill2Me .. rebooted and scanned with Ad-aware and the same thing happened .. the screen froze during the delete. Whatever this VX2 thing is getting from my computer it's likin' it and it's not letting go ;) Ah well .. thanks again and Happy Thanksgiving (if you celebrate that is)
  • SpywareShooterSpywareShooter 127.0.0.1
    edited November 2004
    O4 - HKLM\..\Run: [kofxah] C:\WINDOWS\SYSTEM\rbjqlsid.exe
    O4 - HKLM\..\Run: [Narrator] C:\WINDOWS\wrbkyy.exe

    Fix those entries then find and delete the files listed above, reboot and post a new log.
  • CrunchieCrunchie Mandurah. Western Australia. Member
    edited November 2004
    http://www.downloads.subratam.org/VX2Finder9x.exe

    1.) Scan with the finder, select files it finds and delete them.
    2.) During the deletion the utility will end both Rundll32 & explorer.exe processes, so when all files are gone;
    3.) Click the restore desktop button to get the desktop back.
    4.) Click UserAgent$ to delete last registry item.
    5.) Clear the contents of your C:\Windows\Temp folder

    See how it is then.
  • edited November 2004
    My computer is a bigger mess than before. Everything's either locking up, locking me out or just plain crashing. So much so that I'm going to run my systems recovery discs. Honestly, there's nothing on my system worth crying about if I lose and what I will and want to keep, I'll just download again.

    justlooking, thank you so much for all of your help. The time you took to continue trying is appreciated more than you'll know. I did as you last instructed and scan didn't find anything but thank you so much all the same.

    SpywareShooter, thank you also for your help. I did as you instructed but my ad-aware continued to freeze during the delete. Thank you though, I do appreciate your help.

    I'm off to do the recovery .. take care guys and continue the good work .. I'm sure I'll be back for assistance again soon :)
  • CrunchieCrunchie Mandurah. Western Australia. Member
    edited November 2004
    You are welcome :). Sorry it didn't work for you :(.
  • ronboronbo Connecticut
    edited December 2004
    clean wish if you get this problem again, on the reboot, run your computer in safe mode. A lot of these programs will not let you delete or fix the problems when windows is running.
    ps. also try spybot next time, it worked for me...
  • edited December 2004
    ronbo .. thanks for the suggestion .. the way I surf, I'm sure something else will jump on my system. It should be illegal for sites to put spyware on your computer all because you misspelled a word in the address line and was rerouted to these spam sites. Gets me everytime. Anyway, thanks for the suggestion but I have a question .. where is the "safe mode"? I've heard of doing this before but I have no idea how to do it. Thanks again!
  • ronboronbo Connecticut
    edited December 2004
    Hope this helps you out...
    To use the F8 method
    Use this method only if Windows XP is the only operating system installed on your computer.
    Start Windows, or if it is running, shut Windows down, and then turn off the computer.
    Restart the computer. The computer begins processing a set of instructions known as the Basic Input/Output System (BIOS). What is displayed depends on the BIOS manufacturer. Some computers display a progress bar that refers to the word BIOS, while others may not display any indication that this process is happening.
    As soon as the BIOS has finished loading, begin tapping the F8 key on your keyboard. Continue to do so until the Windows Advanced Options menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
    Using the arrow keys on the keyboard, scroll to and select the Safe mode menu item, and then press Enter.
  • edited December 2004
    Thanks for the instructions .. hope I never need them but just in case I do, thank you. And if your calendar's the same as mine, have a Happy New Year! :celebrate
  • edited December 2004
    You're right. it should be illegal. It maybe is. There are laws against breaking through computer security systems and laws against damaging other people's property. File a complaint regarding look2me and vx2 with the FTC at http://www.ftc.gov/ftc/consumer.htm
    and with the Minnesota consumer services office at
    http://www.ag.state.mn.us/consumer/complaint.html
  • edited December 2004
    Thank you SchWartz! I'm bookmarking both of these sites and will file a complaint with the first about the VX2 .. and anything else that latches on my system while innocently surfing. If your New Year is the same as mine :cheers: Feel free to substitute with the beverage of your choice :D
  • Jer
    edited December 2004
    Clean_wish,
    Good luck,I liked your last smilies. I'm enjoying one of them now. Happy New Year.

    Regards Jer
Sign In or Register to comment.