Stubborn ads234, wildmedia, eZula, Peper Trojan...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by catalpa, Aug 19, 2004.

  1. catalpa

    catalpa Private E-2

    Hello all,

    This is my first time asking for help. In the past I've always been able to fix stuff that incrusted itself in my PC, but this time I've got a slew of them and they keep coming back. I've followed all of the instructions I could find on this site: updating Windows, disabling system restore, enabled viewing of hidden files, folders and extensions, scanning with Trend Micro, running CCleaner, scanning with Ad-Aware, CWShredder, SpySweeper and Spybot S&D in safe mode, searching in registry editor, following advice for MidADdle and Hijack This... and so on. As per the warnings found on this site, I have been wary about doing very much in Hijack This. So, here's what I've got:

    On my Dell Dimension 4600 running Win XP Pro version 2002 with Intel Pentium 4, 2.66 GHz and 512MB of RAM, yesterday I noticed something was downloading onto my computer without my consent. A scan with Ad-Aware and Spybot S&D revealed eZula, iLookup, WildMedia, Peper Trojan, among others. Subsequent surfing on the web to try to find a solution revealed that I also had ads234, or MidADdle, as I understand it. I have spent the past 24 hours following every bit of advice I can find on this and other similar sites (much from Major Attitude), but certain thinks keep coming back. I can never be sure I've completely eradicated something. Two suspicious files I found and deleted were ezPopStub.exe and woinstall.exe. Two more suspicious files found by Hijack This (but which I am unable to find in my computer) are 7NbqJa.exe and cdfjmon.exe, but since these are in Hijack This I'm too afraid to mess with it until someone more experienced has a look at the log file. I'm probably leaving out some details, since I've been at this for 24 hours and am sick and tired.

    Can anyone help?

    A million thanks if you can,
    Catalpa
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Attached Files:

    Last edited: Aug 19, 2004
  3. catalpa

    catalpa Private E-2

    Thanks for the suggestions. I got this readout when I ran the trojan scan:

    Memory not infected
    Scan folder: 'A:\', recursive
    Unable to scan A:\ - The device is not ready.
    Scan folder: 'C:\', recursive
    Scan folder: 'D:\', recursive
    Unable to scan D:\ - The device is not ready.
    Scan folder: 'C:\Documents and Settings\All Users\Documents', recursive
    Scan folder: 'C:\Documents and Settings\Mason\My Documents', recursive
    Finished scan at 18:21:51:937
    Total number of files is 36234, number of infected files is 0
    Average files per second is 29, average file size is 7926705

    I had already seen the MidADdle file suggested on this site and followed its advice as best I could. I found it very helpful and easy to understand, but I'm not sure if I found exactly the files it said to look for.

    I've attached the Hijack This log and crossed my fingers. Thanks for your help. I look forward to hearing back from you.

    catalpa
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you tell me what these are?

    C:\Program Files\Le Robert\Le Petit Robert\prhyper.exe
    C:\Program Files\Le Robert\Le Robert & Collins\rcwinHyper.exe
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and put checks on the following 10 lines BUT DO NOT CLICK FIX until you have exited ALL browser sessions first (or it may not work):
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [7NbqJa] C:\documents and settings\mason\local settings\temp\7NbqJa.exe
    O4 - HKLM\..\Run: [gfI] C:\documents and settings\mason\local settings\temp\gfI.exe
    O4 - HKLM\..\Run: [276U3pP] cdfjmon.exe
    O4 - HKLM\..\Run: [7NbqJa.exe] C:\documents and settings\mason\local settings\temp\7NbqJa.exe
    O4 - HKLM\..\Run: [gfI.exe] C:\documents and settings\mason\local settings\temp\gfI.exe
    O4 - HKCU\..\Run: [Jwp8Rfj9R] cerxress.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)



    Now reboot in safe mode: http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406
    Enable viewing of hidden files and folders: http://forums.majorgeeks.com/showthread.php?t=37650
    Delete the following:
    C:\documents and settings\mason\local settings\temp\7NbqJa.exe
    C:\documents and settings\mason\local settings\temp\gfI.exe

    Not sure where cdfjmon.exe and cerxress.exe are located so I will list several directories to look in for each of these files. Let me know where you find them. My best guess is c:\windows.
    c:\
    c:\windows
    c:\windows\system
    c:\windows\system32
    C:\documents and settings\mason\local settings\temp\

    When you find, them delete them. Be sure to look in each directory to make sure they do not appear in multiple places.

    After deleting the 4 files, empty your Recycle Bin and go to c:\windows\Prefetch and delete any occurrences of those files that you see there.

    Boot normal and tell me how things are working.
     
    Last edited: Aug 19, 2004
  6. catalpa

    catalpa Private E-2

    'Le Robert' is a French dictionary. I'll get on your suggestions and get back to you.

    Many thanks!
    catalpa
     
  7. catalpa

    catalpa Private E-2

    Hello again,

    I used the fix in Hijack This, but 7NbqJa.exe and gfl.exe were not in the temp folder, and I was unable to find cdfjmon.exe and cerxress.exe in any of the folders you listed. I found two similar sounding file names: CSRSS.EXE and CTFMON.EXE.

    What do you think?

    catalpa
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No leave those two alone. They are system files do not delete anything that is not an exact match.

    When you ran HijackThis to do the fix, did all lines I gave to fix still exist?

    If you have rebooted your PC since giving me a HijackThis log we may have to start again. You can check for yourself by running a new HijackThis scan. See if the filenames that I gave you from your last log still appear. If not and you see new random character filenames, we need to analayze the new HijackThis log. This time do not shut your PC down or reboot for any reason in between posting your log and me giving you a procedure. Sometimes these programs can change their names on the fly especially if they detect you trying to delete them.

    Also double check these settings are made:
    Click Start.
    Open My Computer.
    Select the Tools menu and click Folder Options.
    Select the View Tab.
    Under the Hidden files and folders heading select Show hidden files and folders.
    Uncheck the Hide extensions for known file types option.
    Uncheck the Hide protected operating system files (recommended) option.
    Click Apply.
    Click OK.
     
  9. catalpa

    catalpa Private E-2

    Sorry if I made things unnecessarily difficult by rebooting. I'll make sure to keep the computer on this time. I verified the settings you listed and re-ran Hijack This. Here is the log.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks to me like your problem is gone. All those lines are no longer in your log. I do see some additional stuff from McAfee I did not see last time. Did you add some feature?

    Are your problems all gone? If not, what problems do you still have?
     
  11. catalpa

    catalpa Private E-2

    That's great news. Everything's running much better. :) And yes, I added McAfee Privacy Service (my ISP was offering 12 months free). Thank you SO much for your help. Is there any other software or configurations you can recommend to help guard against these nasties in the future? And which features should I change back on my PC (system restore, show hidden files, etc.) ?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your welcome!

    Here is a list of things I always send (you may have some of these or a similar program like a virus scanner, so just ignore):

    How to protect yourself and things to have

    Anti Virus
    http://majorgeeks.com/download1968.html Avast
    http://majorgeeks.com/download886.html AVG
    The top two hands down. Beat the heck out of Norton or McAfee (big resource hogs)
    Only run ONE AV!!!!!

    Firewall
    Don't care if your on dial up or High Speed....you must have a firewall
    http://www.majorgeeks.com/download388.html ZoneAlarm Free
    http://majorgeeks.com/download3356.html SygatePersonal Firewall Free
    http://majorgeeks.com/download738.html Kerio Personal Firewall (not free)


    Temp File/Cookies/index.dat cleaner
    http://majorgeeks.com/download4191.html Ccleaner


    SpyWare Prevention Notice I did not say scanner...yet
    http://majorgeeks.com/download2859.html SpyWare Blaster
    http://majorgeeks.com/download3045.html SpyWare Guard

    SpyWare Scanners/Removers
    http://majorgeeks.com/download2471.html SpyBot ( I don't activate the TeaTimer)
    http://majorgeeks.com/download506.html AdAware SE Personal


    Make sure you use SpyBot's Immunize feature.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds