need help with unwanted "Earn" folders

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by diablosflylady, Oct 7, 2004.

  1. diablosflylady

    diablosflylady Private E-2

    :)
    Hello all

    I found majorgeeks by doing a google search for help on a problem I had and found the information here to be helpful, informative, and trustworthy. I decided to post a thread because I searched the forums for specific help on getting rid of the Earn folders but did not find any. I followed all the steps in the spyware removal thread and got rid of a lot of crap that was on this comp but this particular folder is still there. I have not d/l HiJackThis as of yet but I will if instructed to do so. If anyone could help me I would be eternally greatful.

    Thankyou for being here!!
    ;)

    Rose
     
  2. PhilliePhan

    PhilliePhan Guest

    Hi Rose,

    Can you provide more details as to what this Earn is and what sort of problems it is causing? The name doesn't ring a bell for me.

    Also, quickly list the tutorial steps that you were able to complete & give computer specs (OS, etc. . .)

    Hopefully, we'll be able to help :)


    *** Did a quick search and found a reference to it, but not much help. Off to dinner, but will check back.

    Best,
    PP
     
    Last edited by a moderator: Oct 7, 2004
  3. diablosflylady

    diablosflylady Private E-2



    Hello PP

    Thank you for the prompt reply. :)

    I followed each step outlined under the heading DO NOT POST UNTIL YOU HAVE READ THIS: How to: Spyware, Trojan and Virus Removal very carefully except for the HSRemove because the computer I am trying to fix has win98 2nd edition installed. It is a genuineIntel x86 (if that helps).

    After following each step carefully and removing a lot of crap, I found that in my program drop down menu there was a link to EARN. Under the EARN drop down menu was the following: About EARN and EARN website link. I checked the properties for the About EARN option and I found the target to be the following: "c:\program files\weboffer\wo.exe" /About EARN.

    It has not caused a problem that I can see. As of yet but I am unwilling to wait until it does. :)
     
  4. Matacumbie

    Matacumbie Rocky Top

    PP,

    There is an EARN that is a peper trojan. It creates these two processes:

    Spybot gets rid of it until a restart, using the PeperFix.exe tool seems to work.

    If that is it I am sure you guy's will get it, just wanted to give you a heads-up on EARN.

    Steve
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Use Control Panel, Add/Remove Programs to remove any of the following malware if found:

    - WebOffer or EZ WebOffer
    - EliteBar
    - TV Media
    - TV Media Display
    - MS T-Media Display

    Let us know if that helps.
     
  6. PhilliePhan

    PhilliePhan Guest

    Hi Rose,

    I did a little research and came up with the same info as posted by Chaslang and Matacumbie. (Thanks Guys :) ) Up to date Spybot and Ad-Aware both detect it, but cannot remove it permanently.

    If it is indeed a Peper Trojan, then the tool Matacumbie mentioned can be downloaded here: http://downloads.subratam.org/PeperFix.exe

    Try the suggestions Chas posted. See how they work out. If problems remain, let us know and send us a HijackThis log.

    First, read this:
    http://forums.majorgeeks.com/showthread.php?t=38752

    Note that you should save the log as a .txt file and attach it via the "Attachment Manager" tool.

    And . . . We'll go from there :)

    PP
     
  7. diablosflylady

    diablosflylady Private E-2

    Good morning

    Well I tried both suggestions. The peper fix found nothing and there was nothing in my add/remove programs. I d/l HiJackThis and I will attach the log file as per your request PP. I followed the directions on the thread.

    I ran a scan of ad-aware as soon as I booted up this morning and it found a lot of bad objects again. Anyway here is the log.

    Rose

    **I will check back later in the day
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    For the SpyDeleter problem, do the below:

    Click Start, Run, and enter into the box the following without the quotes "Notepad"
    Now copy and paste the contents the next 3 lines (including the blank line) into the notepad window.
    REGEDIT4

    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB74C951-ACA1-4e33-A94C-A9261EB2CCB7}]


    Now save it as file name: "delspy.reg" (without the quotes).
    Use Save as file type: All files (*.*)
    Save it on your Desktop where it is easy to locate.

    Now on your Desktop double-click on delspy.reg.

    At the prompt "Do you wish to merge the information into the registry?"
    Answer 'Yes' and wait for a message to appear similar to "Merged Successfully".


    Please run HijackThis and click on the "Config" button in the bottom-right hand corner. Then click on "Misc tools" on the top, and then "Open process manager" on the left-hand side. Look for the following process. Kill it by selecting it and then click "Kill process". Then click yes.
    C:\PROGRAM FILES\WEB OFFER\WO.EXE

    After killing all the above process, click "Back".

    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [sais] c:\program files\180solutions\sais.exe
    O4 - HKLM\..\Run: [intdctrr] C:\WINDOWS\SYSTEM\idctup20.exe
    O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://anu.popcap.com/games/popcaploader_v5.cab


    Boot in safe mode and use Windows Explorer to delete:
    c:\program files\180solutions <--- the whole directory
    C:\PROGRAM FILES\WEB OFFER <--- the whole directory
    C:\WINDOWS\SYSTEM\idctup20.exe

    Now reboot normal and post a new log and tell me how things are working.
     
  9. diablosflylady

    diablosflylady Private E-2

    Hello Chas

    Okay i did all you said to do but when I booted into safe mode and looked for the files I did not find the 180solutions. I am attaching the new log file as per your request. I did not delete the popcap as I have never found that to be a problem.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You log looks clean other than PopCap. Almost every help forum recommends its removal.

    You never answered how things are working.
     
  11. diablosflylady

    diablosflylady Private E-2

    Sorry Chas

    Things are running wonderfully!!!! :) A huge thank you and kudos to you and PP for helping me. I wish I could convince this person to go with a different OS but unfortunately they like what they know LOL.

    Out of all the forums I have ever looked at or requested info from this one was by far the best I have found.

    Thank you again for being here.


    Rose
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome Rose. Happy we could help!
     
  13. PhilliePhan

    PhilliePhan Guest

    I'll second that! Happy to help (though Chas did all of the heavy lifting :) )

    PP
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds