Hi, My Norton located a nasty spyware, that I have tried for a week to remove. The file name is artiveds.cpy.dll and the threat name is called adware.binet. I have spybot and adware 6. I have tried everything. They locate it but they can't fix it. The file is located at C:\WINDOWS\SYSTEM32\artiveds.cpy.dll. I go there to try to delete it and I get the following message: "Cannot delete artiveds.cpy: Access is denied. Make sure the disk is not full or write-protected and that the file is not currently in use." I have tried removing explorer.exe and that didn't work also. I would appreciate any help.
Important: Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT.
Unzip HijackThis into this folder. When you run HijackThis from this folder and have it "Fixed checked" it will create a backup file of modifications to use if restore is necessary. Then run, scan, save log, then in notepad copy the FULL log by copy and paste as a reply to this post and an expert with HijackThis Knowldge, will have a go at giving advice. Please note the list of experts names below, very few forum regulars here have had this training.
DO NOT FIX ANYTHING WITH HIJACKTHIS WITHOUT EXPERT ADVICE, most of what it finds you need for normal MS Windows tasks.
Known Spyware HijackThis fighters in DellTalk - If you are, and are not on the list please PM Me.
TomCoyote (of
http://tomcoyote.org/forums/index.php fame)
YoKenny (Accredited Expert at TomCoyotes)
baskar1234 (Teaching Assistant at TomCoyotes, Trusted Advisor Spywareinfo)
ChrisRLG (Classroom Coordinator at TomCoyotes, Trusted Advisor Spywareinfo)
Tuxedo Jack (Teaching Assistant at TomCoyotes, Trusted Advisor Spywareinfo)
Yellowhammer (Trusted Advisor at Net-Integration, First Responder at Computer Cops)
tashi (Helper at Spywareinfo, in training at TomCoyotes)
therock247uk (In Training at TomCoyotes and Spywareinfo)
irelynmisses (In Training at TomCoyotes and Spywareinfo)
Texruss (In Training at TomCoyotes and Spywareinfo)
PGPhantom (In Training at Spywareinfo)
I, and the other hijack experts mentioned above, are in all those sites (and more) with the same login names. You might get one of us at those sites also to anwser your log, but other experts will also be available.
Hi, Thanks for replying. Here is my Hijack this log.
Thanks, Tammy
Logfile of HijackThis v1.97.2 Scan saved at 10:18:04 AM, on 4/20/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Don't see anything suspicious in Hijackthis other than this entry:
C:\WINDOWS\System32\wuauclt.exe
It can be a Trojan, but might not be on your system.
To check right button click on that file in that path using Windows Explorer. Do a scan with Norton. Also look at properties...mine shows version 5.4.360.2550. It may also show built by lab04_N which seems suspicious, but apparently isn't as it shows that info on my machine. *;-)
From your first message I don't see any activity of those files or that adware (see Norton database here for binet) You might search for some of those files listed and see if you see them. Then follow Norton for removal.
Please read this topic from Broadband Medic - Expert Option^Explicit - is the main expert trying to solve this problem. He has fixes for most op systems, BUT the winXP home version is still being worked on.
It mentions 'The Killbox' which you should get hold of, and try to use to remove your problem.
Please post back here with how you solve your problem, others will be watching and knowing the answer would be appreciated.
A fix is now available ======================== Option^Explicit has just posted a reply to a topic that you have subscribed to titled "Vx2.betterinternet/look2me".
If anyone is interested, the fix for the VX2.BetterInternet & Look2Me files seems to be working, other than the odd blue screen(which I may have fixed, I uploaded a newer version) as a side affect, the files are deletesd and policies are restored (thanks to research by freeatlast :wavey: )
1.)Close any open browser windows or programs you are using, since we will be shutting down the computer a couple of times.
2.) Start the OE2.BetterInternet.exe and click the Find VX2.BetterInternet button and wait a few seconds, you should see some info appear in the white textbox.
3.)Now Click the Fix button.. and your machine will automatically reboot.(Thats Step 1)
4.)When you restart and get back to your desktop, the OE2.BetterInternet program will start up again on it's own. As before click Find VX2.BetterInternet then click Fix, and the computer should restart again..(Thats Step 2)
5.)When it restarts this time the OE2.BetterInternet.exe will start itself one last time. This time Click Find VX2.BetterInternet button, you should notice that the section Files Found--- will be blank, indicating that they were deleted successfully.
Click the Fix button one more time and the program will cleanup and close.(you are done) ================================ Please post a new hijackthis log when you have done the above.
Thank you so much. I followed the steps that you had given me and it's gone. I have been working on it a month! My updated Hijack log is below.
Thank you so much, Tammy
Logfile of HijackThis v1.97.2 Scan saved at 1:20:17 PM, on 4/29/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
C:\DOCUME~1\TAMMYD~1\LOCALS~1\Temp\MirarSetup.exe Comments: What is this?
I have no idea what this is, but my firewall keeps popping up with it. I have tried to delete it, but it won't let me. I looked at properties and it was just created yesterday.
My updated Hijack log is below.
Thanks so much, Tammy
Logfile of HijackThis v1.97.2 Scan saved at 5:19:42 PM, on 4/29/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Texruss
2 Intern
•
3447 Posts
320
0
Posted April 20th, 2004 01:00
http://securityresponse.symantec.com/avcenter/venc/data/adware.binet.html
Hijackthis should show some of these entries.
Texruss