Solved: Need Help Removing VX2/Abetterinternet

I'll be glad to help if you still need us. have hijack this fix these entries. I ran adaware AGAIN and the results were exactly the same. A Notepad log shows up Save/name the log: Option 3, and post it in your next reply. Check This Out

I should also note that, obviously, every version of the "look2me" trojan/spyware/adware remover i have downloaded has either A. All tools can be downloaded at the link below and found on that page! . Register a free account to unlock additional features at Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Stinger found 12 infections and claimed to have removed all of them.

VX2. If not, get it. The manual process is also dangerous as the removal process requires you to access and edit sensitive files in the registry of your machine and run the risk of totally destroying The person helping me then suggested I try

Bottom line: three logs in your next reply. Now put a tick by Standard File Kill.

You can switch between the programs by using Alt-Tab. You won't get any more malware, or get redirected to restricted sites again. I have never had to use it... read review HJT Logfile of HijackThis v1.99.1 Scan saved at 3:25:50 AM, on 7/22/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe

Also, each time I delete it windows closes a file about 10 minutes after starting called "Run DLL as executable" and gives me notice of its choice to close that file ANyways, here goes: Following the steps, everything was going smoothly until I had to create that .reg file. How to boot to safe mode * Now copy these instructions to notepad and save them to your desktop. If I feel it would benifit the person to look at the information contained on the site, I send them there.

If you are unable to delete a known spyware\adware\malware program because the file is locked(in use) then you right click on that file, click Who Lock Me and then kill the It's a neat, and free, program that adds a Who Lock Me option to the right click. I downloaded the VX2Finder9x and clicked "click to find VX2BetterInternet" I don't know how long it takes to scan, but clicking MAKE LOG does not do anything.... Or contact the program's manufacturer for an updated version.

the pop ups have also stopped and my computer has returned back to its normal speed.

There may be some variants of this. If you have any p2p file sharing programs you should uninstall those before uninstalling Gator. Is there anyway I can remove these from my computer. C:\Windows\System32\i4jq0e15eh.dll Do you want to let Ad-Aware remove them after the next reboot?" Whenever I receive this message, explorer encounters restarts.

I think if I could get rid of the look2me it might solve the VX.BetterInternet problem. Do you know how your hard drive is formatted: FAT32 or NTFS? I would suggest you join this forum and let the Ad-aware experts help you out.

I was amazed just how straight forward firefox was to install, even offering to transfer favourites from ie, great stuff.

Back to top #3 Scottmotiger Scottmotiger Member Members 27 posts Posted 07 July 2006 - 11:49 AM I have an update on my problem from Hijackthis. If your Spyware detection program still detects ABetterInternet after stepping through the removal instructions, please double-check by stepping through them again. Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLL (file missing) O9 - Extra button: AOL Instant Messenger - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM95\AIM.EXE (file missing) O12 - Plugin for .pps: C:\Program Files\Netscape\Communicator\Program\PLUGINS\NPDOC.DLL O12 I however do not expect anything.

I tried to use Cntrl+alt+del to close all iexplorer processes and turn off the computer, but cntrl+alt+del would not work. TTFN. After updating spybot hit the immunize button. navigate here Ironically, I had just downloaded Google Chrome about two weeks ago in preparation of a work at home job, but I had not used it.

The programs I have downloaded are as follows: Adaware, Spybot, stopzilla popup blocker and google toolbar. Using the site is easy and fun. New log: Logfile of HijackThis v1.99.1 Scan saved at 15:59:10, on 28/07/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\SYSTEM32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe Delete the following file: %WinDir%\bi.dll Note: %WinDir% is a variable (?).

I will sometimes add the brackets for people to click on the links, depends on how busy I am. I may have to save what i can and do a complete reformat of my hard drive if it comes to it. any attempt at manually removes it results in a typical "bla bla bla being used by another person or program." The next time blacklist is run, the registry values have returned From what I have seen though, this does not always work as well.

i have run cwshredder with no help from it. What happens is that this variant wraps itself around the Windows Shell (Explorer) and can not be deleted directly with these tools. I asked how to go about g ... ... Visit our tools page for some very good programs to remove VX2 or any other spyware that your machine may have simply picked up.

I also had Ad Alert 6.0 which pointed out that the hoink.dll file in the windows system file is infected, but recommended manual delete.