BetterInternet: hijack!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Ms Peel, Apr 15, 2004.

  1. Ms Peel

    Ms Peel Private E-2

    A slip of the finger this morning landed me in the world of those who shall be first against the wall when the revolution comes, but I digress... I've run Norton System Works, AdAware, Spybot, Hijack This, and lastly RegSupreme. I've made things better, but there are two files firmly planted in system32 that I can't dislodge, even manually: ...system32\aklui.cpy.dll & ...\aklui.dll.

    My boot up and shut down are reeaaallly slow, too. Help! I'm running AdAware every couple of hours and it always picks up something new along with the BetterInternet stuff. I'm cheesed!!!

    win xp pro, service pk 1
    custom build laptop w/ pentium 4
    2/2 GHz cpu
    2/19 GHz
    496 MB ram

    Anybody got a rope to throw me?

    Cheers, Peel
     
  2. Genius Boy

    Genius Boy The Examinator

    My only thought would be booting into Safe Mode and trying to delete the files then, if they are indeed unneeded.

    To boot into Safe Mode, hold F8 when Windows is booting up.
     
  3. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Check your add\remove programs for anything unfamiliar and uninstall it. Also, check for startup programs. Typically an uninstall and reboot removes them. Another possibility would be to disable system restore and try scanning as well if the above fails.

     
  4. Ms Peel

    Ms Peel Private E-2

    Tried the safemode thing: still wouldn't let me pull the files! Checked startup programs, too. AdAware finds the darn files every time, then says it will remove them on the next rebott, but they just show up again.

    Thanks for the suggestions!

    Still cheesed,

    Peel
     
  5. billH

    billH Master Sergeant

    Hi Mrs. Peel :) Have you tried using Spybot in advanced mode? It might be able to get at the boogers. Try advanced mode "tools" section. I thought I had cleaned out my system pretty good but SpyBot in advanced mode found a BHO and a couple of active X no nos. Also CCleaner her on MG does a pretty thorough job with issues and cookies and lots of other stuff.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  7. alanc

    alanc MajorGeek

    DelLater is a nifty little free utility that will delete any recalcitrant file upon rebooting. Sounds like just the ticket for this :)
     
  8. Ms Peel

    Ms Peel Private E-2

    Looks cool. I'm ready to try anything at this point. I've got DelLater on my machine, now...but how do it work? Sorry, it's one of those simple little programs that is going right past me comprehension-wise...

    Thanks,

    Peel
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Here ya go direct from the website:

    To DelLater A File...

    1. Run dellater.exe <filename>
    2. Reboot (whenever you like).
    That's all that's required. After rebooting and logging in you'll be able to see that the file you specified is no longer there.

    If you don't know what this means. They mean click Start then Run and enter in the run window dellater <filename> Filename will have to be the fullpath to the file you want to delete..
     
  10. Ms Peel

    Ms Peel Private E-2

    Got it. Finally got DelLater to target the files...but there they were again after reboot. I am sad.

    Peel
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  12. NonSuch

    NonSuch Private E-2

    Unfortunately, within the past few weeks BetterInternet, Look2Me, and ZestyFind (all in the VX2 Transponder category) have come out with new variants that are morphing their files. This makes it extremely difficult to clean out and keep cleaned out, which sounds like the problem you're having.

    With all due respect to those who so kindly help out with hijack problems on this board, you need expertise that is beyond what is available here. I suggest you go to a site that specializes in the eradication of this problem and post a HijackThis log. SpywareInfo, TomCoyote, Net-Integration, Computer Cops and WildersSecurity are some that immediately come to mind but there are others.
     
  13. billH

    billH Master Sergeant

    Been there . . . not impressed
     
  14. Ms Peel

    Ms Peel Private E-2

    Ya, right now I'm working with the folks at AdAware, and am about to try something involving my Windows disk. At this point my machine will no longer go online or even talk to our home network. I'm on my husband's machine right now. I'm also thinking about hunting down the Betterinternet folks and killing them slowly and painfully...

    Peel
     
  15. billH

    billH Master Sergeant

    Yep, just once I'd like to see those jerks get everything they deserve. I think though if you and AdAware are working together you're in the best hands possible. Good Luck
    Bill
     
  16. Ms Peel

    Ms Peel Private E-2

    I'm sure the AdAware folks are good people, but I think they have their hands full with this thing right now. They are taking their sweet time getting to MY (oh so important) request for help. In the meanwhile, I tried the method for removal using my win xp cd, and I think I got the bugger. Unfortunately, my machine is still jacked up...no internet connection, no network, can't use the taskbar...and now my display is wonky and won't go above min res: what next!!!??

    I tried doing a repair of my installation with my xp disk, but nothing helps. I'm at a total loss. This is a really nice machine and I'm afraid I've totally bolloxed it up!

    Peel
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds