Hijacker . Elite Toolbar (Summary)
Software Name: Elite Toolbar
Company Name: Enternet Media, Inc.
Product Name: Elite Toolbar
Classification: Hijacker
Website: http://www.searchmiracle.com
Brief:
Uses deceptive messages to entice installation. Can be silently installed by other downloaders. Hijacks your web browse, displays advertisements, and can silently download files. **You may need to run a Deep Scan while in Safe Mode.**
IMPORTANT!
Some of the Hijacker.Elite Toolbar components
are listed below. The list is compiled as a reference. The list might
not be complete and it doesn't represent instructions for manual removal.
We DO NOT recommend manual removal. Incorrect removal
of certain software might make your computer unstable or even unusable.
Removal of adware component might affect the related ad-supported software.
If you suspect that you have an unwanted instance of Elite Toolbar
installed on your computer we recommend a free
audit of your system with INAC Anti Spyware.
Elite Toolbar might create following folders (and inject its files inside
the folders):
- %FAVORITES%\Casino & Adult
- %FAVORITES%\Homelife & Travel
- %WINDOWS%\EliteBar
- %FAVORITES%\Casino & Carrers
- %WINDOWS%\EliteToolBar
- %WINDOWS%\EliteSideBar
- %PROGRAM_FILES%\WebSpecials
- %FAVORITES%\Finances & Business
- %FAVORITES%\Health & Insurance
- %WINDOWS%\etb
Elite Toolbar might create following files (some of the files might be
loaded in memory while the software is running):
- %PROFILE%\Local Settings\Temp4453.dll
- %WINDOWS%\Downloaded Program Files\v2.dll
- %SYSTEM%\bhosave.dat
- %SYSTEM%\bkmsf32.dat
- %SYSTEM%\winssp32.exe
- %SYSTEM%\winxsf32.exe
- %PROFILE%\Local Settings\Temp\silent_install.exe
- %WINDOWS%\Downloaded Program Files\v3.dll
- %PROFILE%\Local Settings\Temp\silent.exe
- %PROFILE%\Local Settings\Temp\protector.exe
- %SYSTEMDRIVE%\sidebDD.exe
- %SYSTEMDRIVE%\upgradetb093.exe
- %FAVORITES%\Living\Dating.lnk
- %FAVORITES%\Living\Find a Degree.lnk
- %FAVORITES%\Living\Find a job.lnk
- %FAVORITES%\Living\Home.lnk
- %FAVORITES%\Living\Insurance.lnk
- %FAVORITES%\Shop\Auctions.lnk
- %FAVORITES%\Shop\Books.lnk
- %FAVORITES%\Shop\Computers.lnk
- %FAVORITES%\Shop\Discount.lnk
- %FAVORITES%\Shop\Flowers.lnk
- %FAVORITES%\Shop\Golf.lnk
- %FAVORITES%\Shop\Jewelry.lnk
- %FAVORITES%\Shop\Movies.lnk
- %FAVORITES%\Shop\Music.lnk
- %FAVORITES%\Shop\Online Store.lnk
- %FAVORITES%\Shop\Perfume.lnk
- %FAVORITES%\Shop\Sleepwear.lnk
- %FAVORITES%\Technology\Adware Remover.lnk
- %FAVORITES%\Technology\Anti-Virus.lnk
- %FAVORITES%\Technology\PC Cleaner.lnk
- %FAVORITES%\Technology\Tech & gadgets.lnk
- %PROFILE%\Local Settings\Temp94046.dll
- %PROFILE%\Local Settings\Temp\bb.exe
- %WINDOWS%\sideb.exe
- %WINDOWS%\Downloaded Program Files\gdnUS208.exe
- %WINDOWS%\Downloaded Program Files\OSDEB.OSD
- %WINDOWS%\Downloaded Program Files\CONFLICT.1\gdnUS208.exe
- %SYSTEM%\desktop.exe
- %SYSTEM%\doolsav.dat
- %SYSTEM%\dwge.exe
- %SYSTEM%\efvee.exe
- %SYSTEM%\tvmk10ez.dll
- %SYSTEM%\csmrs.exe
- %SYSTEM%\csmss.exe
- %SYSTEM%\kalvopa32.exe
- %WINDOWS%\nt_hide*.dll
- %WINDOWS%\pokapoka*.exe
- %WINDOWS%\etb\nt_hide*.dll
- %WINDOWS%\etb\pokapoka*.exe
- %WINDOWS%\etb\xud_*.dll
Elite Toolbar is often accompanied by the following tracking cookies:
n/a
Elite Toolbar might create following registry keys (and inject subkeys
and values):
- HKEY_LOCAL_MACHINE\SOFTWARE\backup\EliteBar
- HKEY_CLASSES_ROOT\CLSID\{02C20140-76F8-4763-83D5-B660107B7A11}
- HKEY_CLASSES_ROOT\CLSID\{28CAEFF3-0F18-4036-B504-51D73BD81C3A}
- HKEY_CLASSES_ROOT\CLSID\{825CF5BD-8862-4430-B771-0C15C5CA880F}
- HKEY_CLASSES_ROOT\Interface\{A74CD7DE-EA6F-11D4-ABF3-000102378429}
- HKEY_CLASSES_ROOT\Interface\{A74CD7DF-EA6F-11D4-ABF3-000102378429}
- HKEY_CLASSES_ROOT\TypeLib\{A74CD7DD-EA6F-11D4-ABF3-000102378429}
- HKEY_LOCAL_MACHINE\SOFTWARE\Elitum
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\v2cab
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{28CAEFF3-0F18-4036-B504-51D73BD81C3A}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\*/v2.dll*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EliteBar Internet Explorer Toolbar
- HKEY_USERS\*\Software\LQ
- HKEY_CLASSES_ROOT\CLSID\{02C20140-76F8-4763-83D5-B660107BABCD}
- HKEY_CLASSES_ROOT\CLSID\{28CAEFF3-0F18-4036-B504-51D73BD81ABC}
- HKEY_CLASSES_ROOT\CLSID\{825CF5BD-8862-4430-B771-0C15C5CA8DEF}
- HKEY_CLASSES_ROOT\PLOT.PlotCtrl.1
- HKEY_LOCAL_MACHINE\SOFTWARE\Elitum\EliteToolBar
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\v3cab
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\*/v3.dll*
- HKEY_CLASSES_ROOT\CGBand.BHO
- HKEY_CLASSES_ROOT\CGBand.BHO.1
- HKEY_CLASSES_ROOT\CGBand.CGBandObj
- HKEY_CLASSES_ROOT\CGBand.CGBandObj.1
- HKEY_CLASSES_ROOT\CGBand.UICGBandObj
- HKEY_CLASSES_ROOT\CGBand.UICGBandObj.1
- HKEY_CLASSES_ROOT\CLSID\{0A1D22C3-37BE-470C-9C29-E3074EE0574B}
- HKEY_CLASSES_ROOT\CLSID\{BE8D0059-D24D-4919-B76F-99F4A2203647}
- HKEY_CLASSES_ROOT\CLSID\{ED103D9F-3070-4580-AB1E-E5C179C1AE41}
- HKEY_CLASSES_ROOT\Interface\{276B0903-EB4B-46FF-8304-F093DEF69DE7}
- HKEY_CLASSES_ROOT\Interface\{4AFF987A-773B-48E4-AEE8-08EBDDBDADF8}
- HKEY_CLASSES_ROOT\Interface\{A9B28EF6-ABF3-463B-A3D8-4D0D0BADFADC}
- HKEY_CLASSES_ROOT\Interface\{CAAB3B3F-E815-47D9-94FD-8BB9143C0077}
- HKEY_CLASSES_ROOT\Interface\{DBF33E89-1784-42AC-ADE4-A428F56550A3}
- HKEY_CLASSES_ROOT\Interface\{ED646219-20BF-41E5-80FD-EE49021DA599}
- HKEY_CLASSES_ROOT\TypeLib\{8AA59E15-6E81-415C-B299-1ADFB50C8E1A}
- HKEY_CLASSES_ROOT\TypeLib\{CA9FC31A-6F35-4493-B629-E64BD6170A17}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Cache\http://teenstrax.com/desktop.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Cache\http://teenstrax.com/gamma.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Cache\http://www.teenstrax.com/ysb.exe
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{28CAEFF3-0F18-4036-B504-51D73BD81ABC}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ED103D9F-3070-4580-AB1E-E5C179C1AE41}
- HKEY_LOCAL_MACHINE\SOFTWARE\ohbbackup
Elite Toolbar might create following registry values:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{825CF5BD-8862-4430-B771-0C15C5CA880F}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Sys29
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|*\v2.dll
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{825CF5BD-8862-4430-B771-0C15C5CA880F}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{825CF5BD-8862-4430-B771-0C15C5CA8DEF}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|*\v3.dll
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{825CF5BD-8862-4430-B771-0C15C5CA8DEF}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects|{28CAEFF3-0F18-4036-B504-51D73BD81ABC}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Reliability\UserDefined|kalvsys
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|kalvsys
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|WebSpecials
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Run|WebSpecials
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|WIN95DEFVIEW
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|App32dll
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|checkrun
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|System service66
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|System service65
Elite Toolbar might create registry values with following data:
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Main|*|http://www.searchmiracle.com*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Main|*|http://searchmiracle.com*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer|SearchURL|http://searchmiracle.com*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main|*|http://www.bettersearch.biz*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer|*|http://searchmiracle.com*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Search|*|http://www.searchmiracle.com*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|antiware|*\elite*32.exe
- HKEY_USERS\*\Software\Microsoft\Internet Explorer|SearchURL|*search345quest*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Main|Search Page|*search345quest*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Main|Search Bar|*search345quest*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\Main|*|*www.the818search-co.com*
- HKEY_USERS\*\Software\Microsoft\Internet Explorer|*|*www.the818search-co.com*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|*|*\pokapoka*.exe
Elite Toolbar might insert following entries in the HOSTS file:
n/a
Click
here to scan your computer for Elite Toolbar free of charge
|