Fighting Spyware, Malware and Adware one File at a Time.
Navigation Links

Database of Spyware Home

About the Project

View the Database

Forums

Database of Spyware Site Map

Terms of Use

VX2

Overview

Summary

 VX2 is an IE Browser Helper Object. It monitors web pages requested and data entered into forms, sends this information to its home server, and opens pop-up advertisement windows. It also has the capability to update itself and install other software. There are two variants of this parasite with different file and internal names, but both work identically.

Alias

 Adware/MSView [Panda], Application/HideWindow.A [Panda], Application/Psexec.A [Panda], Application/ToolWget.A [Panda], Backdoor Program [Panda], Backdoor.Bionet.405 [Kaspersky], Backdoor.IRC.Zapchast [Kaspersky], Backdoor.IRC.Zcrew [Kaspersky], Backdoor/Bionet.405!Server [Computer Associates], Backdoor/IRC.Zcrew [Computer Associates], Backdoor/ZCrew.B [Computer Associates], Backdoor/ZCrew.B.IRC [Computer Associates], Backdoor/Zcrew.G [Computer Associates], BAT.IRCFlood [Computer Associates], BAT.Noshare.B [Computer Associates], Bat/Flood.C!Trojan [Computer Associates], Bck/IRC.Mirc.Based [Panda], Bck/Multi.I [Panda], Bck/Zcrew.B [Panda], Bck/Zcrew.G [Panda], Blackstone Data Transponder. Was also distributed under the name NetPal by netpalnow.com, but the software now available there is the newer NetPal parasite which isn't the same code., DoS.Win32.Nenet [Kaspersky], Flooder.Win32.WarPing [Kaspersky], Flooder/Nenet. A [Panda], IRC.Flood [Computer Associates], mIRC/Flood.I!Trojan [Computer Associates], mIRC/Flood.RmtCfg!Trojan [Computer Associates], NetPal, RemoteProcessLaunch [McAfee], Sputnik (name used by VX2), Spyware/BetterInet [Panda], Trj/Femad.A [Panda], Trj/Flood.BI [Panda], Trj/Passer.C [Panda], Trojan [Name used by Ad-aware], Trojan Horse [Panda], TrojanDownloader.Win32.Femad.b [Kaspersky], VX2 RespondMiter., VX2.Clean Get-Away, VX2.MSView, VX2.My PanicButton, VX2.Respondmiter, VX2.SiteHelper, VX2.Transponder, Win32.BettInet.C [Computer Associates], Win32.Bionet.405 [Computer Associates], Win32.Femad.A [Computer Associates], Win32.IRCFlood [Computer Associates], Win32.Startpage.KF!downloader [Computer Associates], Win32/Femad.B trojan [Eset], Win32/Rslocal.B!Downloader [Computer Associates], Win32/SillyDL.70656!Trojan [Computer Associates], Win32/Spybot.FR!Worm [Computer Associates], Win32/Startpage.KF!Downloader [Computer Associates],

See Also

  NetPal · TPS108 ·

Category

 Browser Helper Object: (BHO). A component that Internet Explorer will load whenever it starts, shares IE's memory context, can perform any action on the available windows and modules. A BHO can detect events, create windows to display additional information on a viewed page, monitor messages and actions. Microsoft calls it "a spy we send to infiltrate the browser's land." BHOs are not stopped by personal firewalls, because they are seen by the firewall as your browser itself. Some exploits of this technology search all pages you view in IE and replace banner advertisements with other ads. Some monitor and report on your actions. Some change your home page.

Adware:  Software that displays popup/popunder ads when the primary user interface is not visible or which do not appear to be assocaited with the product.

Downloader:  A program designed to retrieve and install additional files, when run. Most will be configured to retrieve from a designated web or FTP site.

Homepage Hijacker:  Any software that changes your browser's home page to some other site. Hijacks may reroute your info and address requests through an unseen site, capturing that info. In such hijacks, your browser may behave normally, but be slower.

Variants

   RespondMiter,Sputnik,AADCOM Extreme Targeting, Netpal, Transponder/Blackstone, Transponder/VX2 and Transponder/TPS108. All work identically; TPS108 was aimed at porn sites. ·
 

Origins

 

Group

 Mindset Interactive

Vendor

 MindsetInteractive is the company behind it all and distributesvarious useless software with the parasite. Aadcomsells advertising for them. ITCowns all these companies. Disk11hosted and tested the pest and may originally have writtenit.

Others By This Group

 FavoriteMan· FavoriteMan.FOne· FavoriteMan.SpyAssault· NetPal· NetPal.PrizePopper·

Date of Origin

 Variants from July, 1999 to May, 2005
 

Detection and Removal

Manual Removal

 

Contrary to VX2's claims there is no entry to removeVX2 in the standard "Add/Remove Programs" Control Panelitem.

VX2 installs itself into your System directory andis called either "IEHelper.DLL" (Transponder variant)or "VX2.dll" (RespondMiter variant). Before you candelete this file you will need to deregister it. Enterthe following command from the command line for Windows95/98/Me:

"%WinDir%\SYSTEM\regsvr32.exe"/u "%WinDir%\VX2.dll"

Or for Windows NT/2000/XP:

regsvr32 /u "%WinDir%\VX2.dll"

That's for the RespondMiter variant - for the Transpondervariant, write 'IEHelper.DLL' instead of 'VX2.dll' above.

After doing this and restarting the computer you candelete the file. There will also be some keys in theregistry under HKLM\Software\Transponder or RespondMiter,which you can clean.


 Stop Running Processes:

Kill these running processes with Task Manager:



Remove Autorun Reference:

Go To the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run


If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\narrator, delete it and reboot the machine immediately.



Unregister DLLs:

Unregister these DLLs with Regsvr32, then reboot:



Clean Registry:

Remove these registry items (if present) with RegEdit:



Remove Files:

Remove these files (if present) with Windows Explorer:



Remove Directories:

Remove these directories (if present) with Windows Explorer:



Restore Settings:

After following the instructions above, you will still need to restore your original settings and prevent this from happening again.
 
VLockerPro  VMBScanner0.5  VNC  VNCServer4.0  VNCViewer4.0  VX2  VX2.Pynix  VXtasy  Vacsina.1082  Vacsina.1206.A  
 
Site Map 2006 © Copyright DatabaseofSpyware.com. All rights reserved. Terms of Use
Another Proud Thor Schrock Development