This is topic Elite Toolbar in forum Film-Yak at Film-Tech Forum ARCHIVE.
To visit this topic, use this URL:
https://ft-forum.com/ft/cgi-bin/ubb/ultimatebb.cgi?ubb=get_topic;f=8;t=004004
Posted by Scott D. Neff (Member # 185) on 04-09-2005, 03:58 PM:
Has anybody out there had the unfortunate luck to have the Elite Toolbar maliciously installed on your computer?
One of my friends has and it's extremely stubborn to all spy-ware, virus and pop-up blockers. It's annoying the crap out of him to the point where he wants to restore his entire computer from scratch.
Anybody?
Posted by Brad Miller (Member # 2) on 04-09-2005, 04:20 PM:
Removal tool
Personally I would just reinstall from scratch. I'm probably in the minority here, but it's not THAT big of a deal (at least to me) and it ensures that programs you have tried and found sucked are 100% wiped clean from the machine and any possible virus and various quirkiness is gone too.
Posted by David Stambaugh (Member # 1102) on 04-09-2005, 05:35 PM:
If he's on XP, has he installed SP2? Just curious.
Posted by Mark Lensenmayer (Member # 134) on 04-09-2005, 07:01 PM:
I had the unfortunate experience of having to remove ELITE TOOLBAR from one of the computers at my school. It was in the band room, and it was not very well kept up.
ELITE TOOLBAR keeps loading almost full screen ads every few seconds. It is the most annoying thing I've ever seen.
The Microsoft Anti-Spyware program should be able to take care of it, BUT have it do its work in SAFE MODE.
ELITE TOOLBAR is very sneaky. During the boot process, the control file is loaded into RAM, then it is deleted from the disk. Since it is RAM based, deleting the rest of the files just causes the RAM based routines to recreate the deleted files and registry settings. BUT, if you run it in safe mode, you can get to the files before they are loaded into RAM.
The Microsoft program runs well in safe mode. Even though it is officially a BETA program, is is actually a very good tool that they bought from another company in complete form.
If you are an expert level uses, you can use HIJACK THIS!. BUT, be aware that is is an EXPERT LEVEL tool only. DO NOT EVEN GET THIS IF YOU ARE NOT WELL VERSED IN REGISTRY EDITING.
Posted by Dean Kollet (Member # 1789) on 04-09-2005, 07:04 PM:
remove using the tool, and cease in the use of Internet Explorer. I'm surprised with all of the anti-popup/spyware software there is....Mozilla just doesn't put out a commercial saying, "this wouldn't be a problem if everyone just switched, and btw it's free"
Posted by Joe Redifer (Member # 3) on 04-09-2005, 08:14 PM:
If it is RAM based, couldn't you just force quit the process and then delete the file?
Posted by Randy Stankey (Member # 64) on 04-09-2005, 10:31 PM:
It probably creates a secret RAM disk, sectioning off a piece of memory, tricking the OS into thinking its a hard drive then reinstalling from there.
The technique has been around for years. I used to write programs that used it. There's lots of pitfalls to it, though... #1 among them was that, if the computer lost power your data was toast.
So, why not use that pitfall against it? Erase it from the drive then, while that data is still hiding in RAM, pull the plug on the computer. RAM goes Bye-Bye. Malware goes to the great Bit Bucket in the sky.
(Just spitballing.)
I'm with Brad. You should erase and reinstall your system at least once a year. It's really not that hard. It can be time-consuming but it's not hard.
Posted by Mark Lensenmayer (Member # 134) on 04-10-2005, 08:14 AM:
Joe,
The process is very well hidden. The file in memory is just storing the init file. It is moved there upon start and then is moved back to disk upon exit.
The big problem with the version of ELITE TOOLBAR I came across is that it works whether or not the browser is open, so a switch to FIREFOX or OPERA do no good. You could be doing word processing or games and the ads would keep coming. Cutting off the internet just popped up 404 boxes.
This is by FAR the nastiest one I've ever come across. I have some others in my lab that are hard to get rid of (SEP, ESyndicate) but they are NOWHERE near the problem that ELITE TOOLBAR created.
Posted by Bobby Henderson (Member # 840) on 04-10-2005, 10:56 AM:
I agree with the restoring the system from scratch. No spyware can survive "format c:". System restore discs from companies like Dell can get the operating system reinstalled in a relatively short amount of time.
This is also another argument for using an app like Norton Ghost. It creates a mirrored backup of your boot disc (or the contents of the entire machine). You can kill off spyware effectively without having to reinstall all your applications from scratch.
Still, I recommend formatting and reinstalling apps at least once every year or so. The Windows registry can get loaded down with crap after awhile. Doing a clean reinstall will speed up lots of comuter systems. The only downside to this is you may have to "reactivate" certain programs like Adobe Photoshop. A low level format will erase the machine ID it creates as part of the activation process.
Posted by Joe Redifer (Member # 3) on 04-10-2005, 12:07 PM:
So how does one actually GET this Elite toolbar? I'd love to try it out on my Mac.
Posted by Scott D. Neff (Member # 185) on 04-10-2005, 12:32 PM:
But what if you want to save files from your computer to reinstall on your new computer? Couldn't the spyware be hiding in one of them?!!?!?
And I assume he has SP2 installed cause he just got a brand new Dell like 6 months ago... I suppose it would have come with it right?
Posted by David Stambaugh (Member # 1102) on 04-10-2005, 12:46 PM:
Six months ago might be right around when Dell transitioned to SP2, so it's possible he got SP1a from the factory. A quick and easy way to find out is boot the system and look at the first XP splash screen. If there's a copyright date in the lower-left, it's pre-SP2. If there's no copyright date, it's SP2.
Posted by Kyle McEachern (Member # 2250) on 04-10-2005, 01:15 PM:
Another quick/easy way of figuring out if SP2 is installed on a system is by booting the system up, and during the boot-time Windows splash screen (Windows logo on a black background with a blue or green progress bar going by), if it says "Home Edition" or "Professional Edition" under "Windows XP", then it's pre-SP2...SP2 still HAS Home/Pro editions, it just doesn't tell you which is which in text on the loading screen (though you can tell anyways, since Home = green progress bar, Pro = blue bar)
Posted by Joe Redifer (Member # 3) on 04-10-2005, 06:12 PM:
So how does one actually GET this Elite toolbar? I'd love to try it out on my Mac.
Posted by Kyle McEachern (Member # 2250) on 04-10-2005, 06:57 PM:
quote: Joe Redifer
So how does one actually GET this Elite toolbar? I'd love to try it out on my Mac.
Microsoft Virtual PC 7
Posted by Joe Redifer (Member # 3) on 04-10-2005, 07:10 PM:
I shall now attempt to rephrase the question:
What are you slacks doing to get this thing on your computer in the first place?
Posted by Mark Lensenmayer (Member # 134) on 04-10-2005, 08:15 PM:
I really can't say where the Elite toolbar comes from. I did the repair in mid-February, and it had only been around a few weeks. The machine was not from my lab, so I can't say where it came from.
A quick internet search was also unclear about its source. I think it is likely installed by P2P programs that claim to get free music, or a game program. High school students like the ones I work with would likely be attracted to something like that.
Posted by Scott D. Neff (Member # 185) on 04-11-2005, 12:52 AM:
I didn't get it. A friend of mine did... probably through Limewire.
Posted by Jason M Miller (Member # 2597) on 04-12-2005, 10:44 PM:
quote: Bobby Henderson
This is also another argument for using an app like Norton Ghost. It creates a mirrored backup of your boot disc (or the contents of the entire machine). You can kill off spyware effectively without having to reinstall all your applications from scratch.
DO NOT DO THIS if you have a virus or spyware installed, all GHOST does is create an image of all files, including the infected ones.
Posted by Phil Hill (Member # 371) on 04-12-2005, 11:38 PM:
I agree Jason, the "Ghost" sucks! The best way I found to get rid of those pesky pests is to go to Symantec (Norton's) website and follow their instructions. It is important to do the deletions from the "safe" mode and temporarily turn off "Restore"...
Posted by Bobby Henderson (Member # 840) on 04-13-2005, 12:37 PM:
It goes without saying apps like Ghost are useless if you're not also using anti-virus and anti-spyware applications. However, lots of IT people swear by Ghost. It can save you a hell of a lot of time if you make regular backups of your boot disc.
There's a lot of malware and spyware that will give you no choice but to format your hard disc to get rid of it. I had to do that to a friend's computer when he got nailed with the Cool Web Search browser hijack. Nothing would get rid of it. Then he had to spend hours reinstalling all his applications. Graphics people can kill a bunch of time just having to reinstall the fonts they use. Ghost will make short work of all that.
Posted by Dean Kollet (Member # 1789) on 04-13-2005, 12:51 PM:
I tell ya what, just b/c I'm a nice guy and I'm feeling in the nice mood, I'll fix it for free. Just get me a remote desktop connection with your friend, and I'll get rid of it
Posted by Dominic Espinosa (Member # 2122) on 04-13-2005, 01:39 PM:
Okay, here's the dealio. IE as most M$ products are, is wildly insecure and exploitable. The best thing you can do (if you've got a legit copy of Windows) is to stay updated via MS Update. However, this will not fix al the problems you experience. The best thing you can do is to completely remove IE (On certain installations, such as the old Windows 9x family) you simply cannot remove IE. Post lawsuit copies however allow you to uninstall it.
What oh what will I use to browse?
Netscape, Firefox, Mozilla, whatever you want! They're all virtually the same. Some people also like Opera.
I'm presonally using Netscape Beta 9 and it works SO much better than IE.
Finally, the MS Spyware Beta app is actually good. It does what it's intended, which it should since MS made the damn os vulnerable anyway, they ought to know how to fix it.
And if you're really fanatical, the best thing you can do is run Linux. Either on your router PC or on your workstation.
I can't run Linux on some of mine because my girlfriend isn't Linux friendly and I still need some software that relies on Windows.
However the security and flexability of a Linux router is great. Some full-funcational routers such as those by Netopia and Linksys allow blacklist features of sorts which are useful if a repeat offender is attacking your system. You can "blacklist" his entire network if you want.
I do this with spammers all the time.
And a final argument for the "screw it and reload".
What Brad does is a good idea. Depending on how heavily you use your computer you should reformat and reload every 6-12 months, maybe longer if you don't use it that much.
There are imaging programs of all kinds. I can't remember which is the best but I do think Syquest makes one that's good.
Look over at maximumpcmag.com and there should be some listed or hit the geek sites.
The idea here is to make an image of everything on your hard disk that you install, including drivers with updates and patches, apps, whatever.
Then if the shit hits the fan you can reload from this image of a pristine, fully loaded install.
Moreover, the frequent reformat does several things:
1.) it keeps your system free of clutter
2.) it forces you to organize your important files
3.) it just feels good.
Posted by Randy Stankey (Member # 64) on 04-13-2005, 01:55 PM:
Wanna' REALLY stop viruses & spyware in their tracks?
(I mean, aside from tossing out that piece of Microsoft crap on your desk and getting another computer.)
Try Deep Freeze
It makes a mirror backup of your (presumably clean) computer's configuration and reverts back to that image every time you restart the computer. To top it all off, it can be set to reboot the computer after one hour of no user activity.
It may be a PITA for the average user but it's a Godsend for computers in the college/institutional environment. People can go downloading any kind of virus, malware, P2P trojans or what have you to their heart's content but, one hour later, it's all wiped out!
When the system is set up with Deep Freeze, it can be given a "Thaw Space" in which saved files are kept but are not deleted every hour. This allows users to save their documents long enough to print them out and/or take them home on a floppy, thumb drive or network them home.
There are a lot of situations where you probably wouldn't want to use it but on unattended or public machines, you should look into it.
Powered by Infopop Corporation
UBB.classicTM
6.3.1.2