Elitebar and searchmiracle.com

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by danabob2, Sep 11, 2004.

  1. danabob2

    danabob2 Private E-2

    Okay, I have read and done the Basic Spyware, Trojan And Virus Removal
    instructions several times but each time that I boot I have problems again...tons of popups seeming to come from searchmiracle.com. I am sure there is something, somewhere that I am missing but I sure can't find it.

    Please help. I am at the end of my rope.

    System Info:

    Windows XP - SP2
    Home Edition Version 2002
    Dell Inspiron I51000
    Pentium 4 2.4 GHz
    512 RAM
    40 gig hard drive

    I have cleaned the hijack this log several times after posting it to the "hijack this analyzer" that you was listed in one of your posts but still they come back.

    Does my frustration come through? Thank you.
     
  2. danabob2

    danabob2 Private E-2

    I have finally gotten rid of all my issues. I bought Norton Antivirus 2005, uninstalled McAfee, and just kept deleting any questionable files as reported by hijackthis.de unless I could find on Google what those files were for. It finally paid off and nothing has come back.
     
  3. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

  4. DOOMIV

    DOOMIV Private E-2

    Well, I hope you can help me also..I have tried everything to get ride of this parasite but no luck I have followed the guidance given by other posts on this subject. I am seriiously contemplating a new install....but that seems like a really bad attitude to give in to these idiots who do this sort of thing. Can you help me plz.. here is my HJT logfile

    Thanks
     

    Attached Files:

    Last edited by a moderator: Sep 27, 2004
  5. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Well.. You should start a new thread, but I will try and assist. Please check add\remove programs for anything unusual to remove like shopping, all toolbars, etc. Heres some to remove:

    I would remove this program, SP2 has popup blocking:
    C:\Program Files\Enigma Software
    Group\SpyHunter\PopupBlocker\EnigmaPopupStop.exe

    Keep removing:
    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
    http://searchmiracle.com/sp.php
    Nasty Entries with this kind of homepages should always be fixed. This entry should be fixed by HijackThis!
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
    http://searchmiracle.com/sp.php
    Nasty Entries with this kind of homepages should always be fixed. This entry should be fixed by HijackThis!
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
    http://searchmiracle.com/sp.php
    Nasty Entries with this kind of homepages should always be fixed. This entry should be fixed by HijackThis!
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    http://www.searchmiracle.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    C:\WINDOWS\SYSTEM\blank.htm
    O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81C3A} -
    C:\WINDOWS\EliteBar\ELITEB~1.DLL
    O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA880F} -
    C:\WINDOWS\EliteBar\ELITEB~1.DLL
    O4 - HKLM\..\Run: [EnigmaPopupStop] C:\Program Files\Enigma Software
    Group\SpyHunter\PopupBlocker\EnigmaPopupStop.exe
    O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) -
    https://www.plaxo.com/down/release/PlaxoInstall.cab

    I am assuming the SyncroAd lines are bad as well, but would like to ask Chaslang.
     
  6. danabob2

    danabob2 Private E-2

    Just for future reference for someone. I followed the "before you post" spyware instructions on this site several times before I did the following to be sure I had everything possible removed.

    Somewhere in the posts I found a link to a hijackthis log analyzer that really, really helped when I had done everything else.

    http://hijackthis.de/index.php?langselect=english

    I have bookmarked it and used it to help several other folks. If and this is a big if, you are very, very comfortable in removing items using HJT and deleting the files it identifies in safe mode or in doing it via remove programs then this analyzer can be very helpful. I also then cleaned everything up via HSRemove. Like I said in my earlier post...Anything that this analyzer put a ? beside and I didn't know immediately (like special Dell software), I searched Google to see if I could find anything. If I found bad news or nothing at all, I deleted it. I found that most files that really belonged in Microsoft directories were documented. This is not 100% and you can get in trouble but it is what I did.

    I am sure someone will tell me I did something wrong but it worked for me.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes SyncroAd is an adware delivery system. I have mentioned that it should be removed via Add/Remove Programs in a couple of threads. Here is one of them:
    http://forums.majorgeeks.com/showthread.php?t=43228
     
  8. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    It does not recognize most executables and tags everything in certain sections as bad, which could cause some problems to stop working. Its a nice guideline, but only if you take each yellow and red item and look it up on a search engine like Google.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds