Exploit Trojan destroying Content IE5

L

Lori

We have been experiencing popup resident protection
windows for the past week telling us that we have an
exploit trojan in the ContentIE5\******* assorted files,
different ones each day. Our antivirus software doesn't
pick up on it, except the manufacturer's resident
protection popups do. We can do a full scan but it comes
up clean with the software (etrust EZ antivirus from CA).
Now we can no longer access the Internet as of today and
got some LSP error message, and were receiving many popup
ads from IE even when we weren't online. Have tried to
scan for spyware and used the CW Shredder, but no luck.
Also have removed any programs we didn't recognize.
Any idea how to save this computer which seems to be
dying? It is six months old, a Dell, running on XP.
Thanks for any input.
 
L

LuckyStrike

It might be a bit late now Lori, but this is what has been said regarding
the loss of internet connection (after removing certain spyware) by resident
guru Jim Byrd MVP:

<paste>
Before you try to remove spyware using any of the programs below, download a
copy of LSPFIX from any of the following sites:

http://www.cexx.org/lspfix.htm
http://www.spychecker.com/program/winsockxpfix.html (if your OS is Win2k or
XP)

The process of removing certain malware may kill your internet connection.
If this should occur, this program, LSPFIX, will enable you to regain your
connection.

All of the removal tools should be run from Safe mode when
possible.
<paste/>

Thereafter, you can run the gamut of Anti Spyware programs:
Ad-Aware
CWShredder
Spybot S&D
Hijack This

Just for simplicities sake, here is a lengthy C/P from my sent items folder.
Please forgive my lack of personal attention in submitting this to you, but
it applies to most who have these issues. <s>


"Check for Spyware" suggestions:
First, install the respective programs and then update them immediately, so
that they have the current versions, and definitions. Read the Help Files
and
Tutorials. Run them one at a time. With Ad-Aware you may have it generally
clean whatever it finds. The same applies for CWShredder. Spybot S&D
requires special attention (listed below), as does HijackThis (Only more so.
Details listed below) The programs are listed in order of their general
strength, safety, and purpose. It is perhaps best to install and run these
in this order of appearance. All are freeware programs, but if you are
pleased with the results and quality of the utilities, donations to the
respective Authors are cheerfully accepted.

Ad -Aware
http://www.lavasoftusa.com/support/download/
Ad-Aware Tutorial (might help if you look through this)
http://www.bleepingcomputer.com/forums/index.php?showtutorial=48

CWShredder (cleans all Cool Web Search malware)
http://www.majorgeeks.com/download4086.html
CWShredder Tutorial
http://www.bleepingcomputer.com/forums/index.php?showtutorial=47

Spybot S&D
http://www.safer-networking.org/index.php?page=download
Spybot Tutorial (Must Read)
http://www.safer-networking.org/index.php?page=tutorial
Other tutorials for Spybot S&D (Also must read)
http://www.bleepingcomputer.com/forums/index.php?showtutorial=43
http://tomcoyote.com/SPYBOT/index1.php
http://tomcoyote.com/SPYBOT/index2.php

This item below is designed to *prevent* installation of malware and the
like by comparing known CLSID's of these "bad guys" with what is in its
definitions. It doesn't remove anything, nor will it fix anything that is
already in your PC. Rather, it will prevent installation or re-installation
of the item once it has been removed either manually, or by the use of
another program which will perform the duty of removing the spyware.

SpywareBlaster (prevents installation of spyware, Trojans, etc.)
http://www.javacoolsoftware.com/spywareguard.html
SpywareBlaster Tutorial
http://www.bleepingcomputer.com/forums/index.php?showtutorial=49

SpywareGuard (companion program to SWB, above)
http://www.javacoolsoftware.com/spywareguard.html
SpywareGuard Tutorial
http://www.bleepingcomputer.com/forums/index.php?showtutorial=50

If you use Spybot S & D, be sure to clean *ONLY* the items displayed in
*RED*. DO NOT clean any items displayed in Black or Green at this time.

Lastly there is HijackThis. Hijack this is a very powerful, last resort type
of program which is generally best used in conjunction with help from those
who deal with the findings of the log created by the HijackThis scan. It
does nothing in the scan itself; it merely says what is in and running on
your PC. The items must be checked-marked to be "cleaned". You must
know *exactly* what you are checking-off before you proceed.
If you don't, you can quite possibly disable many useful and vital functions
of your PC. Remember; read the Tutorials, and seek help at SpywareInfo
Forums, Net-Integration, or TomCoyote forums for safety's sake.

HijackThis
http://www.spywareinfo.com/~merijn/downloads.html
If the preceding site is down, you may get HijackThis from Major Geeks
(amongst other sites as well)
Hijack This (from Major Geeks)
http://www.majorgeeks.com/download3155.html

HijackThis Tutorials **(MUST READ)**
http://www.spywareinfo.com/~merijn/htlogtutorial.html
http://www.bleepingcomputer.com/forums/index.php?showtutorial=42
http://hjt.wizardsofwebsites.com/

Where to seek help with your HijackThis scan log
SpywareInfo Forums
http://forums.spywareinfo.com/
other help forums for HijackThis:
Net-Integration
http://forums.net-integration.net/index.php?c=19
TomCoyote
http://forums.tomcoyote.com/index.php?showforum=27


More general info on Spyware, Malware, and other undesirable unwanted
spyware, etc:
Jim Eshelmans WSC Aumha site:
http://aumha.org/a/parasite.htm
more details from Jim and his site
http://www.aumha.org/a/quickfix.htm
His quick scan for parasites (scripting must be enabled for this to work)
http://www.aumha.org/a/noads.htm
Bugs, Glitches, and Stuff-Ups; Sandi Hardmeiers help site
http://inetexplorer.mvps.org/Darnit.htm


A free on-line Trojan scanner
GFI
http://www.windowsecurity.com/trojanscan/
PestPatrol on-line scan
http://www.pestscan.com/home.asp

HTH - and I wish your fledgling XP Dell PC a long fruitful life. Go forth,
prosper and multiply. ;-))
 
L

Lori

Dear Lucky,
Thank so much for your information. I got a very similar
reply from someone named Sandy under the category of
Security, Virus Discussions. Well, thrilled to say that
the combination of LSPFix, ugraded Adaware and Spybot has
gotten us up and running. I was too afraid of
HijackThis, so I left it all alone. And now that I was
able to get back online, I upgraded my version of etrust
EZ antivirus and it finally detected the exploit trojan
virus and deleted it.
One problem that is still remaining is that if I rescan
using the Spybot, even though it supposedly fixed the
problems before, PurityScan and RSOExploit still seems to
come up. I keep "fixing" it but they still show up.
But at least we're up and running. I thank you for your
full list of informative suggestions and links.
Lori
 
L

LuckyStrike

YW Lori. Glad things are back in order (to the degree that it is) ;-)

Here are some bits of info that may help with PurityScan:
http://sarc.com/avcenter/venc/data/adware.purityscan.html
http://www.pestpatrol.com/PestInfo/G/Grokster.asp

Here, from Sandi Hardmeiers site:
http://inetexplorer.mvps.org/data/winservn.htm

Also do a Find> files and folders, and look for a Sear1.exe, sear1 or for
something similar in your machine.

There is supposed to be an Un-installer for it. The link is here. However, I
am usually a bit wary of using a Spyware Installing leeches un-installer to
remove what *they* install! Kind of the Fox in the Hen-house if you know
what I mean. Normally, I don't recommend that which I haven't done, tried,
or installed myself. This is one that is an exception, inasmuch as I've not
had troubles with having PurityScan on my machine. Therefore, a caveat:
Proceed at your own risk if you choose this route.
http://www.purityscan.com/ps_uninstaller.exe
More info and results about the un-installer
http://computercops.biz/postp206374.html

Couldn't readily locate anything on the RSOExploit. If I find anything else,
I'll get back to you.
 
L

Lori

Lucky,
You are so sweet. Thanks for getting back to me again.
What I thought was RSO was DSOExploit. I took a chance
when they came up again on the Spybot and actually
removed the five registry keys from the regitry. When I
scanned again, it congratulated me for having a clean
scan. Hope I didn't do anything stupid. And the
purityscan didn't show up that time. We'll see what
happens later.
I did try to download the uninstaller for the Purityscan
but it said my security settings wouldn't allow me to
access it. So I left it alone, thinking it may be
a "sign" not to do it.
Thanks again for being so caring.
Lori
 
L

LuckyStrike

I should have tried variants of that which you mistakenly wrote as RSO...
admittedly, there was a faint recollection of a DSOExploit in the back of my
head, yet I didn't connect the dots. Sorry.

Glad you've gotten it resolved then. However, I clicked the link to download
the un-installer and that was a possibility, and I run very tight security
on my machine. You must be set-up even more stringently than I. <G>

Here is a link for surfing the Internet safely. I never allow Active
Scripting or ActiveX in the Internet zone. I do not allow any programs to be
installed or run without my consent, and then I always scan for virus, and
spyware first.

How to surf the Internet more safely with Internet Explorer
http://www.infinisource.com/techfiles/surf-safe.html
How to Use Security Zones in Internet Explorer
Microsoft Knowledge Base Article - 174360
http://support.microsoft.com/default.aspx?scid=kb;EN;Q174360&LN=EN

Anyway, you are most welcome, and I am glad to be of service. Please post to
these newsgroups at any time you may feel the need for assistance. ;-)
--

LuckyStrike
(e-mail address removed)
--------------------------------------------------------------------


Lori said:
Lucky,
You are so sweet. Thanks for getting back to me again.
What I thought was RSO was DSOExploit. I took a chance
when they came up again on the Spybot and actually
removed the five registry keys from the regitry. When I
scanned again, it congratulated me for having a clean
scan. Hope I didn't do anything stupid. And the
purityscan didn't show up that time. We'll see what
happens later.
I did try to download the uninstaller for the Purityscan
but it said my security settings wouldn't allow me to
access it. So I left it alone, thinking it may be
a "sign" not to do it.
Thanks again for being so caring.
Lori
<snipped...>
 
L

Lori

Well, happy to report that all is very well and there
have been no more popups or detections of malware,
viruses or spyware today. You are very kind and I
appreciate your help and suggestions more than you know.
Hopefully some day someone can return the favor when you
need it. Better yet, hope you never need it. Thanks
again.
Lori
 
L

LuckyStrike

You're most welcome Lori. I am glad you've achieved some satisfaction. Take
care, and happy (and safe) surfing. ;-)

PS - thank you for your kind wishes. <s>
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top