help on seacrhmiracle

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sweetbriar, Sep 7, 2004.

  1. sweetbriar

    sweetbriar Private E-2

    Hi,
    I recently found searchmiracle infecting my computer and after searching google come across your web page and forums. After reading past posts on the issue I upgrade spybot and loaded adaware. I have run them several times now.
    I also updates XP and IE.
    I have just run Hijackthis and would like help on the output.

    Thanks
    Sweetbriar
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Before getting to a HijackThis log you must follow ALL the steps in this Sticky thread < READ ME FIRST: Basic Spyware, Trojan And Virus Removal >

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    Then you should read the below.

    NOTE: You should read the tutorial in this Sticky thread < Hijack This Tutorial And How To Post Your Log File >

    Do not post a HijackThis log until we ask you to and when we do it must be text document attachment to your message.

    Update! Due to Hijack This logs destroying search engine and web site searches, we now ask you do not post your Hijack This log file unless requested by us. It is for advanced users, so if you do not understand how to use it, you do not need it....yet. Instead, please tell us in your post what symptoms you are experiencing so we can try and resolve it that way. When, and if, we ask you to post your log file, please attach it as a file. To do this save the log file and select manage attachments in a new thread to upload it. All running programs should be closed, including your web browser, e-mail, items in the tray, anything you can close... Close before running Hijack This!


    Do NOT run Hijack This from the Desktop, a temp folder or choose run from the download. Place it in its own folder, for example C:\Program Files\HJT
     
  3. sweetbriar

    sweetbriar Private E-2

    I have run adaware, spybot, mcafee antispyware, adware spy. This removed many and now after numerous scans I am donw to regular 8 a scan.

    I have loaded HiJackthis into a folder on C and run a scan. Followed the tutorial and removed items relating to unwanted material on R1, O2, 016. This included removing the file elitebar in remove programs.

    Rebooted computer, rerun all the spyware again.

    Have just logged onto internet again and search miracle and elite have returned.

    Did Hyjackthis and they had returned to O2.

    Sweetbriar
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No go back and do all of what is in the link I gave you. Not some of it.

    And get rid of AdwareSpy. It is a rogue/fake spyware remover. See this: http://www.spywarewarrior.com/rogue_anti-spyware.htm

    What's a regular "8 a scan"?

    After you run ALL of what I gave you, we will discuss HijackThis logs.

    Did you use Ad-aware SE 1.04 ?
     
  5. sweetbriar

    sweetbriar Private E-2

    Chaslang

    Followed all to the letter.

    I still finidng the Elitebar returns to my computer. It comes back into IE and lists itself on program file list and in c:/windows even after removal during the computer clean.

    What next?

    Sweetbriar
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Post your HijackThis log (as a .txt file attachment) as per the HijackThis tutorial.
     
  7. sweetbriar

    sweetbriar Private E-2

    I ran everything again and what ever I did it seems to have done the job (I think). Please check and advise if otherwise.
     
    Last edited by a moderator: Sep 12, 2004
  8. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Im sorry, this is not how you do it. Your Hijack This is out of date, you cut and pasted, not attached and have so many programs running, your asking us to work twice as hard. Please close running programs, get newest version and attach it as a text file.

     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to go back and get the correct version of HjiackThis (v1.98.2) and look at the tutorial again.
    Log should be posted as .txt file attachment not inline.

    Please post a new log as a .txt file attachment. The current one shows no signs of EliteBar.

    Edit: Did not see you in there MA. Was about to do the same thing!
     
  10. sweetbriar

    sweetbriar Private E-2

    Downloaded newer version. Returned to safe mode and run hijackthis. Attached TEXT file.

    Sweetbriar
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must run HijackThis in normal boot mode. Not in safe mode.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    One advanced item that I can tell you that need to be fixed:
    O4 - HKLM\..\Run: [Sys29] C:\windows\system32\winrsv32.exe

    Run Task Manager and end the winrsv32.exe process if found.
    Then run HijackThis and fix the above line.
    Then boot in safe mode and delete C:\windows\system32\winrsv32.exe

    (NOTE: if you followed the READ ME FIRST thread, you should have already enable viewing of hidden files which may be needed to find the above file.)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds