AdDownloader refuses to die

M

MomoCool

Hi all - can anyone please help me with this one... MSAS
detects and removes (or so it says)
SearchMiracle.AdDownloader (Trojan Downloader) and
SearchMiracle.EliteBar (Browser Plug-in). But when I
restart my PC (I'm running XP) MSAS detects them again.
I've run a full MSAS scan, and a full Norton Anti-Virus
scan, and I've turned off System Restore. Any suggestions
what I can try next?
Cheers - MomoCool
 
P

plun

MomoCool was thinking very hard :
SearchMiracle.AdDownloader (Trojan Downloader) and
SearchMiracle.EliteBar (Browser Plug-in).

Hi

- Please send a suspected spyware report to MS about this, menu tools
within MSAS.

Try this tool for removal:

http://www.simplytech.it/ETRemover/

Run this in safe mode:

"The only thing you have to do is to reboot your machine in Safe Mode
(just click the F8 key as the PC is starting, just before the MS
Windows flag
screen appears) and run the EliteToolbar Remover,
then click the "Kill Elite Toolbar" button and wait until it finishes
its work."

Please report back if it works.
 
M

MomoCool

Thanks for the speedy response plun :) ETRemover didn't
seem to fare any better - when I restart in "normal" mode
and run MSAS scan, they're b-a-a-a-c-k. I'll submit the
report to MS.
Cheers
Maurice
 
P

plun

MomoCool brought next idea :
Thanks for the speedy response plun :) ETRemover didn't
seem to fare any better - when I restart in "normal" mode
and run MSAS scan, they're b-a-a-a-c-k.

Hi

Never ending loop with new variants..... ;(

If you have time ? Try to run MSAS in safe mode with
all options checked.

Also remove all temporarily files before scanning.
I recommend this tool, www.ccleaner.com

Then I think its time for HijackThis to solve this and
go to a forum specialized in these logs.

http://www.aumha.org/a/quickfix.htm (step 7)

or one of these.

http://www.merijn.org/forums.html


HijackThis can be downloaded from:

http://www.merijn.org/files/hijackthis.zip

About HijackThis:

http://www.bleepingcomputer.com/forums/index.php?showtutorial=42
 
G

Guest

MomoCool, Stephen, download and run the "BHO Demon"
program; then "Hijack this" program: then cut and paste
the results from both here in your own thread.
It sounds like a nasty BHO bug.
||||||||||||||||||||||||||||||||||||||||||
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top