i use spysweeper (symantec)for my spyware needs..... on latest scan it tells me that elitebar (elitemik.32.exe) program is running and i should close it for proper removal. how to do? Spysweeper is able to detect a bunch of spyware but slows to a snail when trying to remove them and then eventually doesn't respond. using IE windows98. Sweeper has always performed well.... clear and easy suggestions (if that is ever possibly) is greatly appreciated... i'm just a IT novice!....

Dani AI

Generated

This is a typical persistent toolbar/adware infection: components that install at startup, add browser helper objects/toolbars, and alter the hosts/search settings can block removers while Windows is running. was right to push for a focused diagnostic scan first; when on-system removal tools freeze, the safest next step is an offline, controlled cleanup so running components cannot protect themselves.

Recommended removal workflow (high level):

  1. Back up personal data to external media and unplug the PC from the network.
  2. Try an offline session: boot the machine into Safe Mode (or better, a clean PE/rescue environment) so the unwanted components do not load. Run up-to-date on-demand scanners or a bootable anti-malware rescue disc to remove executable files.
  3. With the system offline, repair persistent changes: remove unexpected startup entries, delete the malicious files found by the scanners, and restore the hosts file to its default state (remove any malicious redirections). Also clear or reset the browser’s add-ons/toolbars and search/homepage settings.
  4. Reboot normally and run a second full scan to confirm nothing restarted. Repeat offline removal if items persist.

Practical notes and cautions: many removers hang because the malicious process is active or protected; that is why offline rescue media or a preinstalled PE environment is often required. If removal leaves the system unstable or if multiple core settings were changed, a clean reinstall can be faster and safer than prolonged manual cleanup—especially on an old, unsupported OS. After cleanup, update antivirus definitions, verify browser defaults, and consider moving off an unsupported operating system to reduce future risk.

As suggested, a fresh diagnostic/log from a trusted scanner after these steps will confirm whether the infection was fully removed. If automated tools fail to remove all persistent items, professional offline repair or a reinstall is the prudent fallback.

Recommended Answers

All 3 Replies

There are different versions/variants of the Elitebar pest, and if you have an EliteBar infection you may have other "unwanted guests" as well.

Please do the following, and we'll show you what to do from there:


Download the free "HijackThis" detection and removal tool:

http://www.majorgeeks.com/download3155.html

Once downloaded, follow these instructions to install and run the program:

-------------------------------------------------------------------------------------------------------------------

Create a folder outside of any Temp/Temporary folders for HJT and move it there now. A folder such such as C:\HijackThis or C:\Spyware Tools\HijackThis will do.

The downloaded file is a "zipped" file, so you will have to unzip it before you can run it. Right-click on the hijckthis.zip file and choose the "Extract All..." option from the resulting pop-up menu; this will start XP's extraction wizard. Walk through the wizard's steps using its default selections. This will create a sub-folder named HijackThis, which contains the actual hijackthis.exe program. You just need to double-click on that to run it.

Run HijackThis, but do not have HJT fix anything yet; only have it scan your system! Once the scan is complete, the "Scan" button will turn into an option to "Save log...". Save the log in the folder you created for HiajckThis, open the log in Windows Notepad, and cut-n-paste the entire contents of the log here.


The log contents will tell us a lot about what "nasties" have crept into your system, and once we analyse the log we can tell you what to do from there.

DMR,

here's the log.....

Logfile of HijackThis v1.99.1
Scan saved at 12:06:34 PM, on 3/2/05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\RTVSCN95.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\DEFWATCH.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\HPZTSB07.EXE
C:\WINDOWS\SYSTEM\HPHMON04.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\VPTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\ELITEMIK32.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE
C:\WINDOWS\SYSTEM\HPHIPM11.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by MSN
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F1 - win.ini: run=hpfsched
O1 - Hosts: google.com
O1 - Hosts: altavista.com
O1 - Hosts: yahoo.com
O1 - Hosts: thehun.com
O1 - Hosts: lycos.com
O1 - Hosts: dogpile.com
O1 - Hosts: excite.com
O1 - Hosts: metacrawler.com
O1 - Hosts: search.com
O1 - Hosts: google.com
O1 - Hosts: altavista.com
O1 - Hosts: yahoo.com
O1 - Hosts: thehun.com
O1 - Hosts: lycos.com
O1 - Hosts: dogpile.com
O1 - Hosts: excite.com
O1 - Hosts: metacrawler.com
O1 - Hosts: search.com
O1 - Hosts: google.com
O1 - Hosts: altavista.com
O1 - Hosts: yahoo.com
O1 - Hosts: thehun.com
O1 - Hosts: lycos.com
O1 - Hosts: dogpile.com
O1 - Hosts: excite.com
O1 - Hosts: metacrawler.com
O1 - Hosts: search.com
O1 - Hosts: google.com
O1 - Hosts: altavista.com
O1 - Hosts: yahoo.com
O1 - Hosts: thehun.com
O1 - Hosts: lycos.com
O1 - Hosts: dogpile.com
O1 - Hosts: excite.com
O1 - Hosts: metacrawler.com
O1 - Hosts: search.com
O1 - Hosts: google.com
O1 - Hosts: altavista.com
O1 - Hosts: yahoo.com
O1 - Hosts: thehun.com
O1 - Hosts: lycos.com
O1 - Hosts: dogpile.com
O1 - Hosts: excite.com
O1 - Hosts: metacrawler.com
O1 - Hosts: search.com
O1 - Hosts: google.com
O1 - Hosts: altavista.com
O1 - Hosts: yahoo.com
O1 - Hosts: thehun.com
O1 - Hosts: lycos.com
O1 - Hosts: dogpile.com
O1 - Hosts: excite.com
O1 - Hosts: metacrawler.com
O1 - Hosts: search.com
O1 - Hosts: google.com
O1 - Hosts: altavista.com
O1 - Hosts: yahoo.com
O1 - Hosts: thehun.com
O1 - Hosts: lycos.com
O1 - Hosts: dogpile.com
O1 - Hosts: excite.com
O1 - Hosts: metacrawler.com
O1 - Hosts: search.com
O1 - Hosts: google.com
O1 - Hosts: altavista.com
O1 - Hosts: yahoo.com
O1 - Hosts: thehun.com
O1 - Hosts: lycos.com
O1 - Hosts: dogpile.com
O1 - Hosts: excite.com
O1 - Hosts: metacrawler.com
O1 - Hosts: search.com
O1 - Hosts: google.com
O1 - Hosts: altavista.com
O1 - Hosts: yahoo.com
O1 - Hosts: thehun.com
O1 - Hosts: lycos.com
O1 - Hosts: dogpile.com
O1 - Hosts: excite.com
O1 - Hosts: metacrawler.com
O1 - Hosts: search.com
O1 - Hosts: google.com
O1 - Hosts: altavista.com
O1 - Hosts: yahoo.com
O1 - Hosts: thehun.com
O1 - Hosts: lycos.com
O1 - Hosts: dogpile.com
O1 - Hosts: excite.com
O1 - Hosts: metacrawler.com
O1 - Hosts: search.com
O1 - Hosts: google.com
O1 - Hosts: altavista.com
O1 - Hosts: yahoo.com
O1 - Hosts: thehun.com
O1 - Hosts: lycos.com
O1 - Hosts: dogpile.com
O1 - Hosts: excite.com
O1 - Hosts: metacrawler.com
O1 - Hosts: search.com
O1 - Hosts: google.com
O1 - Hosts: altavista.com
O2 - BHO: &EliteSideBar - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - C:\WINDOWS\ELITES~1\ELITES~1.DLL
O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 53.dll
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 53.dll
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb07.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\SYSTEM\HPHMON04.EXE
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [antiware] C:\WINDOWS\SYSTEM\ELITEMIK32.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [rtvscn95] C:\PROGRA~1\SYMANT~1\SYMANT~1\rtvscn95.exe
O4 - HKLM\..\RunServices: [defwatch] C:\PROGRA~1\SYMANT~1\SYMANT~1\defwatch.exe
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
O8 - Extra context menu item: Web Savings - file://C:\Program Files\WebSavingsfromEbates\System\Temp\ebateswebsavings_script0.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra button: Privacy Champion - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\PROGRAM FILES\PRIVACY CHAMPION\PC.EXE (file missing)
O9 - Extra 'Tools' menuitem: Privacy Champion - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\PROGRAM FILES\PRIVACY CHAMPION\PC.EXE (file missing)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .mpga: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O16 - DPF: Dialpad US Java Applet -
O16 - DPF: {20309504-8D74-4762-82CE-856903876EEA} -
O16 - DPF: {AD684060-16D6-40C3-AF27-53956783430D} -
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} (CInstall Class) -
O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
O19 - User stylesheet: (file missing)


thks.-jackson

I have to head off to work right now, but I'll check back in 5 or 6 hours.

In the mean time:

There is a specific utility for removing EliteBar. Download it from the following link, read the instructions in the "readme.rtf" file that comes with it, and give it a try:

http://www.majorgeeks.com/download4465.html

Post a new HijackThis log after that.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.