Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Ads1.searchmiracle.com & eliteaej32.exe
   
BullGuard Antivirus Forum > General Security > Spyware > Ads1.searchmiracle.com & eliteaej32.exe  
Forum Quick Jump
 
New Topic Post reply to : Ads1.searchmiracle.com & eliteaej32.exe Printable version of : Ads1.searchmiracle.com & eliteaej32.exe
[ << Previous Thread | Next Thread >> ]

mdell
New Member


Date Joined Apr 2005
Total Posts : 2
 
   Posted 4-27-2005 7:01 (GMT +2)    Quote: Ads1.searchmiracle.com & eliteaej32.exeAlert an admin about: Ads1.searchmiracle.com & eliteaej32.exe
Hello,
 
I'm in need of assistance to remove some persistant pop-ups and ad programs that occur each time I start-up my computer. On each re-start I receive a pop-up for a $2.99 calling service and a green "Click Me "icon appears on my desktop. The same icon and an un-install icon for "Click-Me" appears in my start menu. The pop up windows I get are frequent and are usually from ads1.searchmiracle.com. I have HiJack This, Norton 2005, Ad-Aware, SpyBot, and Spysubtract installed but to no avail. My HiJack log is below; I have deleted the entry to eliteaej32.exe but it always appears again on the next scan. I have searched out this file as well but cannot find them on my system (I have hidden files, and system folders viewable) A solution or any advice would be very appreciated.
 
 
Logfile of HijackThis v1.99.1
Scan saved at 1:03:12 AM, on 4/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\interMute\SpySubtract\SpySub.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\Fpmb0.exe
C:\WINDOWS\system32\Wqot61.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.altavista.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\eliteaej32.exe
O4 - HKLM\..\Run: [4WPK7YA2H46ARN] C:\WINDOWS\system32\RnuQDC55.exe
O4 - HKLM\..\Run: [ASDPLUGIN] C:\WINDOWS\system32\canada.exe  -N
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 
I
Back to Top
 

Emilio (SVK)
Gold Member




Date Joined Jan 2005
Total Posts : 1876
 
   Posted 4-28-2005 10:59 (GMT +2)    Quote: Ads1.searchmiracle.com & eliteaej32.exeAlert an admin about: Ads1.searchmiracle.com & eliteaej32.exe
Hi Mdell

Download ScanSpyware
(Serial: 5426-7451-2543)

Download Mwav

Download SysClean (sysclean.com file)
Download pattern file
(unpack and copy with sysclean.com to the same folder)

Download TDS-3
Download TDS-3 update
(just re-copy radius.td3 file to the folder TDS-3)

Download CWShredder 2.14

Download CCleaner

http://www.docsdownloads.com/Tier1/dr-delete.htm

Download Advanced process termination
www.diamondcs.com.au/index.php?page=apt
(you don´t have to install it....it´s only executable utility)

install and check for updates....


PROCEDURE:
1.Turn off System restore

2.Reboot to the "Safe mode"

3.Show hidden files

4.Run Hijackthis:
Check:

O4 - HKLM\..\Run: [checkrun] C:\windows\system32\eliteaej32.exe
O4 - HKLM\..\Run: [4WPK7YA2H46ARN] C:\WINDOWS\system32\RnuQDC55.exe
O4 - HKLM\..\Run: [ASDPLUGIN] C:\WINDOWS\system32\canada.exe -N
Fix checked...........

5.Run Advanced Process Termination:(some may not exist)

C:\windows\system32\eliteaej32.exe
C:\WINDOWS\system32\RnuQDC55.exe
C:\WINDOWS\system32\canada.exe
C:\WINDOWS\system32\Fpmb0.exe
C:\WINDOWS\system32\Wqot61.exe
select and then press "ALL" button in PROCES CONTROL OPTIONS

6.Find and delete these files:(use Dr.Delete)(some may not exist)
C:\windows\system32\eliteaej32.exe
C:\WINDOWS\system32\RnuQDC55.exe
C:\WINDOWS\system32\canada.exe
C:\WINDOWS\system32\Fpmb0.exe
C:\WINDOWS\system32\Wqot61.exe

7.Scans:
run scan with Ad-AwareSE (full system scan, scan volume for ADS)
run scan with SpyBot
run scan with ScanSpyware (do complete scan)
run scan with CWShredder
run scan with Mwav (all scan options)
run scan with SysClean
run scan with TDS-3 (choose all choices to scan in SCAN CONTROL)

8.Cleaning
run CCleaner (analyze---run cleaner)

9.Enable System restore (reverse progress of disabling)

10.Reboot


post new log for check...thx


Emilio24

>Hijackthis< , >FireFox<

Back to Top
 

mdell
New Member


Date Joined Apr 2005
Total Posts : 2
 
   Posted 4-29-2005 4:19 (GMT +2)    Quote: Ads1.searchmiracle.com & eliteaej32.exeAlert an admin about: Ads1.searchmiracle.com & eliteaej32.exe
Emilio,
 
That seems to have done the trick. Before I received your reply, I had installed Spyware Doctor as well, which also claimed to have cleaned it but using the steps you outlined solved the problem for sure.
 
Thank-you for your time.
 
 
 
Logfile of HijackThis v1.99.1
Scan saved at 10:18:21 PM, on 4/28/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.altavista.com/
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Back to Top
 

Emilio (SVK)
Gold Member




Date Joined Jan 2005
Total Posts : 1876
 
   Posted 4-29-2005 12:33 (GMT +2)    Quote: Ads1.searchmiracle.com & eliteaej32.exeAlert an admin about: Ads1.searchmiracle.com & eliteaej32.exe
jut do this:

Download Hoster
members.aol.com/toadbee/hoster.zip

run Hoster -> Restore original hosts

that´s all...your log is clean....


Emilio24

>Hijackthis< , >FireFox<

Back to Top
 
New Topic Post reply to : Ads1.searchmiracle.com & eliteaej32.exe Printable version of : Ads1.searchmiracle.com & eliteaej32.exe
 
Forum Information
Currently it is Monday, May 21, 2012 11:00 PM (GMT +2)
There are a total of 82.921 posts in 18.688 threads.
In the last 3 days there were 2 new threads and 3 reply posts. View Active Threads
Who's Online
This forum has 33970 registered members. Please welcome our newest member, JohnKWagner.
26 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
BullGuard Support Hijacked :) (0)21-05-2012 19:36:34 (Andreea-Luciana Ostache)
Empty tmp folders (14)21-05-2012 19:31:13 (Andreea-Luciana Ostache)
Bogus BullGuard Websites (0)21-05-2012 14:37:08 (Robert Mateescu)
Multiple Virus Issues (7)19-05-2012 15:44:59 (Touch)