e.rn11.com

Discussion in 'Malware Help (A Specialist Will Reply)' started by NotoriousSPB, May 7, 2005.

  1. NotoriousSPB

    NotoriousSPB Private E-2

    Hey everyone, this is my first post. I've got ad-aware and spybot on this computer, which i run periodically, but for some reason they are incapable of eliminating very frequent and very annoying pop-ups from ads1.revenue.net and e.rn11.com. I have no idea why these are coming up, as I have not visited any sites or done anything that would have allowed this to happen. I have downloaded Hijack This but haven't used it before. Any help on eliminating these pop-ups would be GREATLY appreciated, and the simpler the better, as I am competant with computers but not proficient by a long shot. This is really annoying.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus RemovalMake sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you do not know how to extract a file from a ZIP file and you have Win XP, the below should help you.

    To get hijackthis.exe extracted from the ZIP File into the location we requested do the following.
    The below will work for WinXP based system since it can deal with ZIP files.
    You need to create the C:\Program Files\HJT folder. Do the following:
    - Click START and select Explore.
    - Select the drive where Windows is installed (normally C:)
    - Navigate to the C:\Program Files folder and select it.
    - Now click the on the top menu where it says File and then select New.
    - Then select Folder
    - A new folder is created and highlighted.
    - Just type HJT to overwrite the default name (New Folder)

    To extract hijackthis.exe:
    - locate the HijackThis.zip file you downloaded and right click on it
    - Select Extract All and click Next
    - Browse your way to the C:\Program Files\HJT folder created above
    - Select the folder and click Next
     
  4. NotoriousSPB

    NotoriousSPB Private E-2

    I have been in the process of doing all of the steps mentioned in the sticky. Also, is this e.rn11.com and the ads thing common?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have not seen it before. But there are thousands of bad sites. More turn up every day.
     
  6. NotoriousSPB

    NotoriousSPB Private E-2

    Why is this happening though? I do not understand why the spyware programs are ineffective and why the pop-ups are occuring in the first place.
     
  7. NotoriousSPB

    NotoriousSPB Private E-2

    This is the Hijackthis logfile:

    Edit by chaslang: Inline log attached
     

    Attached Files:

    Last edited by a moderator: May 8, 2005
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There a milions of forms of malware and they grow at a dramatic rate. Many also mutate on the fly too. This makes it difficult if not impossible to keep up. The popups are occurring because that is a symptom of what this particular item must be doing to you. I have no idea to what level your PC is protected or what OS you even have so just work thru the steps I gave you so we can try to figure out what is going on. While I have not seen this particular rn11.com problem myself, I have seen it mentioned before on the internet.

    You did not follow directions:
    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  9. NotoriousSPB

    NotoriousSPB Private E-2

    I have WinXP and I have all the updates are current.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Another item you did not follow directions on: C:\Program Files\Internet Explorer\IEXPLORE.EXE
    .


    Is that your complete log? You do not even have an antivirus program or a proper firewall installed. That's a big contributor to why you have a problem.
     
    Last edited: May 7, 2005
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [etbrun] C:\windows\system32\elitexxp32.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:

    C:\windows\system32\elitexxp32.exe <--- also delete any other files that begin with elite and end with .exe. There could be a bunch of them.

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  12. NotoriousSPB

    NotoriousSPB Private E-2

    Alright, I did all of that stuff and thus far have not received a pop-up (around 2 mins). Here is the logfile:


    Edit by chaslang: Inline log attached
     

    Attached Files:

    Last edited by a moderator: May 8, 2005
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Still having a problem with those directions:
    Please do not post logs inline!

    Your last log is clean. You really have to follow all the steps in the below thread as you need to get many of the tools installed:
    How to Protect yourself from malware!
     
  14. NotoriousSPB

    NotoriousSPB Private E-2

    Alright, I will do so in the future. Thanks for the assistance, as it seems to have done the trick!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Make sure you run the steps in that link ASAP!!
     
  16. Dory

    Dory Private E-2

    Hi there.. I have been having the same issue. Would you mind taking a look at my file and telling me what I should fix here?

    O4 - HKLM\..\Run: [checkrun] C:\windows\system32\eliteozi32.exe

    This looks similar to the one that you were telling him to get rid of.. Elite bar is the pest that I had a hell of a time cleaning. When I do my virus scan, this is the only one that I can't locate :
    Any help would be greatly appreciated.

    OH! And what happens if you do this hijack scan with windows open.. or if you do if from a file that is not the C drive? :eek:
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please start your own thread for your problems. Before doing so, run the READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal sticky thread steps.

    Also, just do a search in this forum for elite. We have clean hundreds of these. They are rather simple to clean.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds