The creator of the "Internet Optimizer" worm.

I have a fantasy of finding out where the creator of the “Internet Optimizer” worm lives. It’s night, and I’m in a room full of computers and servers and the like; tens of thousands of dollars worth of equipment. I’m not sure how I got there, but I have a five-gallon jug of whole milk with me. I start pouring the stuff into the vents of his machines, and it starts shorting out, with sparks and pops and very loud crackling sounds. Then the guy who designed the worm hears it and bursts into the room. A brief struggle ensues, and I kick his ass.

This probably won’t happen, but it’d be great even if someone else does this and kicks his ass. I’d cheer that person and share the joy vicariously.

So since I probably won’t get to kick the bastard’s deserving ass and cause him property damage, the next best thing would be figuring out how to get this damned worm off my computer. Sometimes it hijacks my browser and sends it to the Internet Optimizer home page, which is a cheesy search page with ads on it. It also brings me popups, most often for porn and gambling sites. And, of course, this worm does anything but optimize the internet, and makes my computer run painfully slow, even when I’m not on line. And I’ve got a six-year-old machine, so it’s pretty slow to begin with.

I’ve removed hijackers before, but I can’t for the life of me figure out how to get rid of this garbage. Does anyone have any ideas about how to kill it? Advice would be most appreciated.

And, of course, if anyone can manage to kick the ass of the creator of this abomination, I’d appreciate that, too.

Try running HiJack this
http://www.majorgeeks.com/download3155.html

I would be careful with it, mostly it is used by advanced computer users.

Hijackthis will not remove anything. Do not delete everything it finds, most of them are files and registry entries that are required to run your computer. Post your log here.

Here are manual removal instructions for Internet Optimizer.

There are links on that page for a commercial product called “Spyware Sweeper.” Just ignore them. The manual removal instructions work fine.

You’re having trouble deleting that sonovabitch because it has roots buried in your registry.

If the instructions are too confusing, or if you have trouble, then I second Fear Itself - run HiJack This! and post the log here so we can look at it.

So, am I to understand this is not actually optimizing the Internet?

Okay, thanks for the advice and the links. I’m not at home right now, so I can’t disinfect yet, but I’ll try it tonight.

Sure it is. More people with broken machines who can’t go online means a smoother surfing experience for everyone! :wink:

Not for the person using a computer it’s on, no. Also beware of “IE Plugin”–the name implies it’s an Internet Explorer plugin from Microsoft but it’s not.

“Internet Optimizer” is especially sneaky, too. It only activates in response to 404 “file not found” error, and then hijacks you over to Internet Optimizer’s “search” page (which then, of course, loads other popups and “helper objects.”)

It’s even worse when VeriSign does this. It wasn’t as bad from a spyware/hijack/worm point of view, but it broke the Web for anyone who wasn’t using it through a web browser. VeriSign eventually stopped, but the fundamental problem of focusing so much power in one company’s hands is still unsolved.

Okay, so I tried Uvula Donor’s instructions first. I’d found similar instructions on the web before, and I had the same problem then: none of the files it told me to remove were in my Windows “Downloaded Files” folder. All information I can find about it says there are four variants to the worm; maybe I’ve got a fifth one? Regardless, thanks.

So I’ve run HiJack This!* and have gotten a scan. I haven’t removed anything, but I’ve got a log. So, with no further ado, here 'tis:

Lemme know what you think, if you don’t mind, and I’ll get back to this hopefully tonight, since I don’t have access to my computer at home during the day. Thanks.

I found another page with more detailed instructions.

http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453076206

From there, I see that you need to remove this line, and reboot the machine immediately:

Check the box in HijackThis! and let it remove the entry.

These lines are also suspect, but from a different browser hijack:

O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...meInstaller.exe
O16 - DPF: {87D1A6EF-8CBC-458A-84B5-0333562418CD} (ctadlctrl Class) - http://www.clicktracking.info/ctadl1.cab
Good luck!

Put a check next to the following items:

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\NEM220.DLL
O3 - Toolbar: YourSiteBar - {86227D9C-0EFE-4f8a-AA55-30386A3F5686} - C:\PROGRAM FILES\YOURSITEBAR\YSB.DLL
O4 - HKLM…\Run: [IST Service] \ISTsvc\istsvc.exe
O4 - HKLM…\Run: [WoF71a] C:\YLJEENKU.EXE
O4 - HKLM…\Run: [Internet Optimizer] “C:\Program Files\Internet Optimizer\optimize.exe”
O4 - HKCU…\Run: [180ClientStubInstall] "C:\WINDOWS\TEMP\SAIS.EXE"

Click on “Fix checked” to remove them.

Do a Windows file search on the following items, and delete them if they are found:

NEM220.DLL
YSB.DLL
istsvc.exe
YLJEENKU.EXE
SAIS.EXE

If you have not done so already, download and install Adaware SE Personal 1.06, Microsoft AntiSpyware, and Spybot Search & Destroy 1.4. After installing, be sure to use the update function of each to check for updates. Restart in Safe Mode, and run each of these programs, and delete everything they find.

You also appear to be using a very old version of McAfee antivirus that may not be updating with current virus definitions. If this is the case, uninstall McAfee, and install a new antivirus, such as AVG Free Edition 7.0. After installing be sure to use the update function to check for the latest virus definitions. Run AVG, and it will automatically remove everything it finds.

When you get done with all of this, reboot and post a new HijackThis log here.

Sorry, find and delete optimize.exe as well.

Also, skip Microsoft AntiSpyware, it won’t install in Win98, it is for WinXP only.

Not true. I’m running it just fine on Win 2k.

I always find Hijack This log files interesting (Og, I am soo sad). It’s amazing the amount of cruft that people collect as continually running services on their computers. Little wonder they find their computer slowing if they allow every bit of nonsense on their computer to install itself as a startup.

I stand corrected. But it won’t run on Win98 or WinMe.

Hey guys, how 'bout me?

You have a lot of spyware installed. Start with this:

Download and install Adaware SE Personal 1.06, Microsoft AntiSpyware, and Spybot Search & Destroy 1.4. After installing, be sure to use the update function of each to check for updates. Restart in Safe Mode, and run each of these programs, and delete everything they find.

Check your Norton Antivirus to see if it is a current subscription with current updates. Ifit is not current, uninstall Norton and install a new antivirus, such as AVG Free Edition 7.0. After installing be sure to use the update function to check for the latest virus definitions. Run AVG, and it will automatically remove everything it finds.

When you get done with all of this, reboot and post a new HijackThis log here.

Fear, I just wanted to say that it’s very decent of you to do this for people. You’re a good guy.