SearchMiracle.AdDownloader Trojan Downloader

  • Thread starter Thread starter Hamish
  • Start date Start date
H

Hamish

MAS doesn't seem to deal with this one , any suggestions?
It say it removes it, but always finds it agin next time..
give the following details also..

Infected files detected
c:\windows\system32\elitetpr32.exe

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersio
n\Run antiware
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersio
n\Run antiware
 
Hamish said:
-----Original Message-----
Infected files detected
c:\windows\system32\elitetpr32.exe

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersi o
n\Run antiware
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersi o
n\Run antiware

Hi

- Send a spywarereport to MS about this, menu tools.

- Try this tool:

http://www.simplytech.it/ETRemover/
 
If you are running SP2, open IE--->Tools--->Manage Add-
ons, and uncheck any
BHO's that you don't recognize.

Engel
 
If you run HijackThis

(Get HijackThis.exe from
http://tomcoyote.org/hjt/hjt199//HijackThis.exe

Save it to C:\hjt (new folder) then Open it and select
Scan Only)

you will see:

O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-
51D73BD81ABC} - C:\WINXP\EliteToolBar\EliteToolBar version
53.dll

O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-
0C15C5CA8DEF} - C:\WINXP\EliteToolBar\EliteToolBar version
53.dll

O4 - HKLM\..\Run: [antiware] C:\winxp\system32
\elitetpr32.exe

You may also see a ton of entries like:

O4 - HKLM\..\Run: [RuBkrclfmon.exe]
C:\WINXP\RuBkrclfmon.exe

O4 - HKLM\..\Run: [OUIagclfmon.exe]
C:\WINXP\OUIagclfmon.exe

and also:

O4 - HKLM\..\Run: [Windows Service Pack Auto Update]
C:\Documents and Settings\YourLoginName\figgaz.exe

O4 - HKLM\..\RunServices: [Microsoft Java Windows Update]
vlblhe.exe

O4 - HKLM\..\RunServices: [Microsoft Update] Svhost.exe

O4 - HKCU\..\Run: [Microsoft Update] Svhost.exe

The .exe files may change but if you google them you will
get no or only a few hits.

If you boot into Safe Mode (F8) choose the without
networking option and run HijackThis then select the Scan
Only option again and check all entries that match the
above then hit Fix Checked you should get rid of most of
it.

Then run AntiSpy with the 3 scan options enabled.

Wouldn't hurt to check the folder

C:\Documents and Settings\YourLoginName\

and remove any .exe files you find. This is not a place
where good .exe files live.


If you make a mistake you can tell HijackThis to restore
something or everything. View the List of Backups, select
the entries to be restored and press Restore.

If in doubt send the log to me at (e-mail address removed)

Ron
 
Back
Top