X

Distinguished
Apr 6, 2004
61
0
18,630
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

Hi,
I've the Elite spyware on my PC. The file called during bootup is
c:\windows\system32\eliteymo32.exe but they've hidden it from view in
Explorer. I've turned on the "Show system files" options etc. but it
won't display. The value in the registry ('etbrun')keeps coming back seconds
after I delete it with regedit. I've tried ad-aware, xoftware, and
spysweeper but none remove it permanently.

How can I delete this file? I've Windows XP Professional.

Also is it possible to bring a class action lawsuit against
searchmedia.com for maliciously infecting so many PCs this way?

Thks.
 

Malke

Distinguished
Apr 6, 2004
3,000
0
20,780
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

x wrote:

> Hi,
> I've the Elite spyware on my PC. The file called during bootup is
> c:\windows\system32\eliteymo32.exe but they've hidden it from view in
> Explorer. I've turned on the "Show system files" options etc. but it
> won't display. The value in the registry ('etbrun')keeps coming back
> seconds after I delete it with regedit. I've tried ad-aware, xoftware,
> and spysweeper but none remove it permanently.
>
> How can I delete this file? I've Windows XP Professional.
>
> Also is it possible to bring a class action lawsuit against
> searchmedia.com for maliciously infecting so many PCs this way?
>
> Thks.

You need to run all malware removal tools in Safe Mode after making sure
you have the most recent versions. There is also an Elite Toolbar
removal tool. I've gotten it from www.majorgeeks.com, but have also
been warned that MajorGeeks has popups. Since I don't generally access
the site with Windows and in Windows use Mozilla or Firefox, I haven't
had that problem. So if you do go to MajorGeeks, just get the software
you want and don't click on any popup ads.

Go through these malware removal steps in Safe Mode:

First delete all Temporary and Temporary Internet Files. Then:

1) Scan in Safe Mode with current version (not earlier than 2004)
antivirus using updated definitions.

Before you remove malware, get LSPFix or WinSockFix for XP - see links
below.

2) Remove spyware with Spybot Search & Destroy and Ad-aware. These
programs are free, so use them both since they complement each other.
There is a new version of CWShredder from Intermute. I would not
install the other Intermute programs, however. Alternately, there are
CoolWebSearch malware removal steps at SilentRunners.

Be sure to update these programs before running, and it is a good idea
to do virus/spyware scans in Safe Mode. Make sure you are able to see
all hidden files and extensions (View tab in Folder Options).

If the malware remains even after you used Ad-aware and Spybot, you can
scan with HijackThis. HijackThis is an excellent tool to discover and
disable hijackers, but it requires expert skill. See below for
HijackThis links, including sites where you can post your HJT logs. A
combination of HijackThis and About:Buster works well in removing the
About:Blank homepage hijacker. Again, this is an expert tool and
novices should get help with it.

3) If you are running Windows ME or XP, you should disable/enable System
Restore after the system is clean because malware will be in the
Restore Points. With ME, you must disable System Restore completely.
With XP, you can delete all but the most recent (presumably clean)
System Restore point from the More Options section of Disk Cleanup
(Run>cleanmgr).

4) Make sure you've visited Windows Update and applied all security
patches. Do not install driver updates from Windows Update.

5) Run a firewall.

Links to help with malware:

Software/Methods:
http://www.safer-networking.org - Spybot Search & Destroy
http://www.lavasoftusa.com - Ad-aware
http://www.intermute.com/products/cwshredder.html
http://www.tomcoyote.com/hjt/ - HijackThis
http://www.intermute.com/spysubtract/cwshredder_download.html
http://www.silentrunners.org/sr_cwsremoval.html. - SilentRunners
http://www.cexx.org/lspfix.htm - Repair Winsock 2 settings after
removing spyware
http://www.spychecker.com/program/winsockxpfix.html - WinsockXPFix.exe

HijackThis:
http://www.aumha.org/a/hjttutor.htm - HijackThis tutorial by Jim
Eshelman
http://aumha.net - forums
http://spywarewarrior.com/viewforum.php?f=5 - Spyware Warrior HijackThis
forum
http://www.wilderssecurity.com/
http://forums.tomcoyote.org/

General:
http://aumha.net - look under "Security" for various forums
http://rgharper.mvps.org/cleanit.htm
http://mvps.org/winhelp2002/unwanted.htm
http://www.aumha.org/a/parasite.htm - The Parasite Fight
http://www.spywarewarrior.com/rogue_anti-spyware.htm

Malke
--
MS MVP - Windows Shell/User
www.elephantboycomputers.com
In Memoriam - MVP Alex Nichol
The world is diminished without him.
 
G

Guest

Guest
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

Q. "Is it possible to bring a class action lawsuit against searchmedia.com
for maliciously infecting so many PCs this way?"

A. Contact your local legal consul. This is not a forum for dispensing legal advice.


Unexplained computer behavior may be caused by deceptive software
http://support.microsoft.com/?­id=827315

Download Ad-aware SE and scan your PC for the presence of sp­yware:
http://www.download.com/3000-2144-10045910.html?part=69274&subj=dlpage&tag=button

Symantec Security Check
http://security.symantec.com/s­scv6/default.asp?langid=ie&ven­id=sym

Microsoft Windows AntiSpyware
http://www.microsoft.com/downloads/details.aspx?FamilyID=321cd7a2-6a57-4c57-a8bd-dbf62eda9671&displaylang=en

3 Simple Steps to Help Ensure the Protection of Your PC
http://www.microsoft.com/athom­e/security/protect/default.msp­x

--
Carey Frisch
Microsoft MVP
Windows XP - Shell/User
Microsoft Newsgroups

Get Windows XP Service Pack 2 with Advanced Security Technologies:
http://www.microsoft.com/athome/security/protect/windowsxp/choose.mspx

-------------------------------------------------------------------------------------------

"x" wrote:

| Hi,
| I've the Elite spyware on my PC. The file called during bootup is
| c:\windows\system32\eliteymo32.exe but they've hidden it from view in
| Explorer. I've turned on the "Show system files" options etc. but it
| won't display. The value in the registry ('etbrun')keeps coming back seconds
| after I delete it with regedit. I've tried ad-aware, xoftware, and
| spysweeper but none remove it permanently.
|
| How can I delete this file? I've Windows XP Professional.
|
| Also is it possible to bring a class action lawsuit against
| searchmedia.com for maliciously infecting so many PCs this way?
|
| Thks.
 

TRENDING THREADS