Page 1 of 1

VX2 / Transponder - What Flavour Would You Like ?

Posted: Sun Jan 02, 2005 11:38 am
by quicksilver
This particular spy/adware nasty really lives up to its name.
The symptoms are a failure of browser (all varieties), instead will be seen the classic "unable to show this page " screen
The actual DLL hides in the windows System32 folder pretending to be a system process , which means you are unable to manually delete it , even in safe mode :evil:
I made a search of the net for information and also gained a lot of links from the cricket room

http://www.doxdesk.com/parasite/Transponder.html

http://www.cexx.org/vx2.htm

http://www.spywareguide.com/product_show.php?id=25

http://www.scanspyware.net/info/VX2.htm

Ok enough of the reading ..lol
As you can see VX2/transponder comes in many varieties , it will change filename following a reboot and try to contact its "home" about once every minute if you block it, changing ports also (a way to restore your browser in an emergency is to go into task manager and stop the process called RUNDLL32, this will allow you to get on the net for about 2 minutes before the nasty gets back to work and may allow you to get help

Those who have Adaware may not know that a plugin is available for this parasite from lavasoft including instructions for its use

http://www.lavasoftusa.com/software/add ... aner.shtml

Most anti spy programs will detect this under a few different names , but the most successful way of removing it is to clear out your temporary internet files and save any cookies you might need out of the cookies folder , then flush both of these and this is the important part for all users of the machine not just the logged on one , then reboot into safe mode and run your spyware scan, and I suggest doing this more than once before returning to normal mode , as I found different items on 3 seperate scans , it was like peeling an onion.

Of course I seemed to have got the worst variant and used my favourite trick of booting into my small partition (in safe mode also) and using Adaware from there to kill it (and zipping a few files I knew to be "wrong uns", this is in case they turned out to be something useful ).
I pity anyone who gets this as I was rather busy and not having any internet explorer to help folks with is rather annoying

Posted: Wed Jan 05, 2005 2:50 pm
by quicksilver
Another way to lose this nasty is to go here and follow the easy steps

http://forums.cricketmx.com/viewtopic.php?t=1492

Posted: Thu Jan 06, 2005 2:00 am
by Red XIII
Was that the one you were dealing with that one day? :lol:

Posted: Thu Jan 06, 2005 2:42 am
by quicksilver
Yes Red it,s a very nasty little beastie , and should be avoided at all costs :evil:

Posted: Thu Jan 06, 2005 3:40 am
by Red XIII
Were you able to follow it back to the original site you acquired it from?

Cause I followed one spyware back to the original site once and emailed the site host and he finally eliminated it..