0

i use spysweeper (symantec)for my spyware needs..... on latest scan it tells me that elitebar (elitemik.32.exe) program is running and i should close it for proper removal. how to do? Spysweeper is able to detect a bunch of spyware but slows to a snail when trying to remove them and then eventually doesn't respond. using IE windows98. Sweeper has always performed well.... clear and easy suggestions (if that is ever possibly) is greatly appreciated... i'm just a IT novice!....

2
Contributors
3
Replies
4
Views
12 Years
Discussion Span
Last Post by DMR
0

There are different versions/variants of the Elitebar pest, and if you have an EliteBar infection you may have other "unwanted guests" as well.

Please do the following, and we'll show you what to do from there:


Download the free "HijackThis" detection and removal tool:

http://www.majorgeeks.com/download3155.html

Once downloaded, follow these instructions to install and run the program:

-------------------------------------------------------------------------------------------------------------------

Create a folder outside of any Temp/Temporary folders for HJT and move it there now. A folder such such as C:\HijackThis or C:\Spyware Tools\HijackThis will do.

The downloaded file is a "zipped" file, so you will have to unzip it before you can run it. Right-click on the hijckthis.zip file and choose the "Extract All..." option from the resulting pop-up menu; this will start XP's extraction wizard. Walk through the wizard's steps using its default selections. This will create a sub-folder named HijackThis, which contains the actual hijackthis.exe program. You just need to double-click on that to run it.

Run HijackThis, but do not have HJT fix anything yet; only have it scan your system! Once the scan is complete, the "Scan" button will turn into an option to "Save log...". Save the log in the folder you created for HiajckThis, open the log in Windows Notepad, and cut-n-paste the entire contents of the log here.


The log contents will tell us a lot about what "nasties" have crept into your system, and once we analyse the log we can tell you what to do from there.

0

DMR,

here's the log.....

Logfile of HijackThis v1.99.1
Scan saved at 12:06:34 PM, on 3/2/05
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\RTVSCN95.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\DEFWATCH.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\HPZTSB07.EXE
C:\WINDOWS\SYSTEM\HPHMON04.EXE
C:\PROGRAM FILES\SYMANTEC_CLIENT_SECURITY\SYMANTEC ANTIVIRUS\VPTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\ELITEMIK32.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE
C:\WINDOWS\SYSTEM\HPHIPM11.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.yahoo.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchmiracle.com/sp.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.yahoo.com/start.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by MSN
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F1 - win.ini: run=hpfsched
O1 - Hosts: 64.124.222.169 google.com
O1 - Hosts: 64.124.222.169 altavista.com
O1 - Hosts: 64.124.222.169 yahoo.com
O1 - Hosts: 64.124.222.169 thehun.com
O1 - Hosts: 64.124.222.169 lycos.com
O1 - Hosts: 64.124.222.169 dogpile.com
O1 - Hosts: 64.124.222.169 excite.com
O1 - Hosts: 64.124.222.169 metacrawler.com
O1 - Hosts: 64.124.222.169 search.com
O1 - Hosts: 64.124.222.169 google.com
O1 - Hosts: 64.124.222.169 altavista.com
O1 - Hosts: 64.124.222.169 yahoo.com
O1 - Hosts: 64.124.222.169 thehun.com
O1 - Hosts: 64.124.222.169 lycos.com
O1 - Hosts: 64.124.222.169 dogpile.com
O1 - Hosts: 64.124.222.169 excite.com
O1 - Hosts: 64.124.222.169 metacrawler.com
O1 - Hosts: 64.124.222.169 search.com
O1 - Hosts: 64.124.222.169 google.com
O1 - Hosts: 64.124.222.169 altavista.com
O1 - Hosts: 64.124.222.169 yahoo.com
O1 - Hosts: 64.124.222.169 thehun.com
O1 - Hosts: 64.124.222.169 lycos.com
O1 - Hosts: 64.124.222.169 dogpile.com
O1 - Hosts: 64.124.222.169 excite.com
O1 - Hosts: 64.124.222.169 metacrawler.com
O1 - Hosts: 64.124.222.169 search.com
O1 - Hosts: 64.124.222.169 google.com
O1 - Hosts: 64.124.222.169 altavista.com
O1 - Hosts: 64.124.222.169 yahoo.com
O1 - Hosts: 64.124.222.169 thehun.com
O1 - Hosts: 64.124.222.169 lycos.com
O1 - Hosts: 64.124.222.169 dogpile.com
O1 - Hosts: 64.124.222.169 excite.com
O1 - Hosts: 64.124.222.169 metacrawler.com
O1 - Hosts: 64.124.222.169 search.com
O1 - Hosts: 64.124.222.169 google.com
O1 - Hosts: 64.124.222.169 altavista.com
O1 - Hosts: 64.124.222.169 yahoo.com
O1 - Hosts: 64.124.222.169 thehun.com
O1 - Hosts: 64.124.222.169 lycos.com
O1 - Hosts: 64.124.222.169 dogpile.com
O1 - Hosts: 64.124.222.169 excite.com
O1 - Hosts: 64.124.222.169 metacrawler.com
O1 - Hosts: 64.124.222.169 search.com
O1 - Hosts: 64.124.222.169 google.com
O1 - Hosts: 64.124.222.169 altavista.com
O1 - Hosts: 64.124.222.169 yahoo.com
O1 - Hosts: 64.124.222.169 thehun.com
O1 - Hosts: 64.124.222.169 lycos.com
O1 - Hosts: 64.124.222.169 dogpile.com
O1 - Hosts: 64.124.222.169 excite.com
O1 - Hosts: 64.124.222.169 metacrawler.com
O1 - Hosts: 64.124.222.169 search.com
O1 - Hosts: 64.124.222.169 google.com
O1 - Hosts: 64.124.222.169 altavista.com
O1 - Hosts: 64.124.222.169 yahoo.com
O1 - Hosts: 64.124.222.169 thehun.com
O1 - Hosts: 64.124.222.169 lycos.com
O1 - Hosts: 64.124.222.169 dogpile.com
O1 - Hosts: 64.124.222.169 excite.com
O1 - Hosts: 64.124.222.169 metacrawler.com
O1 - Hosts: 64.124.222.169 search.com
O1 - Hosts: 64.124.222.169 google.com
O1 - Hosts: 64.124.222.169 altavista.com
O1 - Hosts: 64.124.222.169 yahoo.com
O1 - Hosts: 64.124.222.169 thehun.com
O1 - Hosts: 64.124.222.169 lycos.com
O1 - Hosts: 64.124.222.169 dogpile.com
O1 - Hosts: 64.124.222.169 excite.com
O1 - Hosts: 64.124.222.169 metacrawler.com
O1 - Hosts: 64.124.222.169 search.com
O1 - Hosts: 64.124.222.169 google.com
O1 - Hosts: 64.124.222.169 altavista.com
O1 - Hosts: 64.124.222.169 yahoo.com
O1 - Hosts: 64.124.222.169 thehun.com
O1 - Hosts: 64.124.222.169 lycos.com
O1 - Hosts: 64.124.222.169 dogpile.com
O1 - Hosts: 64.124.222.169 excite.com
O1 - Hosts: 64.124.222.169 metacrawler.com
O1 - Hosts: 64.124.222.169 search.com
O1 - Hosts: 64.124.222.169 google.com
O1 - Hosts: 64.124.222.169 altavista.com
O1 - Hosts: 64.124.222.169 yahoo.com
O1 - Hosts: 64.124.222.169 thehun.com
O1 - Hosts: 64.124.222.169 lycos.com
O1 - Hosts: 64.124.222.169 dogpile.com
O1 - Hosts: 64.124.222.169 excite.com
O1 - Hosts: 64.124.222.169 metacrawler.com
O1 - Hosts: 64.124.222.169 search.com
O1 - Hosts: 64.124.222.169 google.com
O1 - Hosts: 64.124.222.169 altavista.com
O1 - Hosts: 64.124.222.169 yahoo.com
O1 - Hosts: 64.124.222.169 thehun.com
O1 - Hosts: 64.124.222.169 lycos.com
O1 - Hosts: 64.124.222.169 dogpile.com
O1 - Hosts: 64.124.222.169 excite.com
O1 - Hosts: 64.124.222.169 metacrawler.com
O1 - Hosts: 64.124.222.169 search.com
O1 - Hosts: 64.124.222.169 google.com
O1 - Hosts: 64.124.222.169 altavista.com
O2 - BHO: &EliteSideBar - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - C:\WINDOWS\ELITES~1\ELITES~1.DLL
O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINDOWS\EliteToolBar\EliteToolBar version 53.dll
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINDOWS\EliteToolBar\EliteToolBar version 53.dll
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb07.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\SYSTEM\HPHMON04.EXE
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [antiware] C:\WINDOWS\SYSTEM\ELITEMIK32.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [rtvscn95] C:\PROGRA~1\SYMANT~1\SYMANT~1\rtvscn95.exe
O4 - HKLM\..\RunServices: [defwatch] C:\PROGRA~1\SYMANT~1\SYMANT~1\defwatch.exe
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
O8 - Extra context menu item: Web Savings - file://C:\Program Files\WebSavingsfromEbates\System\Temp\ebateswebsavings_script0.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra button: Privacy Champion - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\PROGRAM FILES\PRIVACY CHAMPION\PC.EXE (file missing)
O9 - Extra 'Tools' menuitem: Privacy Champion - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\PROGRAM FILES\PRIVACY CHAMPION\PC.EXE (file missing)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .mpga: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O16 - DPF: Dialpad US Java Applet - http://www.dialpad.com/applet/src/vscp.cab
O16 - DPF: {20309504-8D74-4762-82CE-856903876EEA} - http://66.154.18.136/npd/load8.exe
O16 - DPF: {AD684060-16D6-40C3-AF27-53956783430D} - http://www.xpehbam.biz/exploit.exe
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} (CInstall Class) - http://www.spywarestormer.com/files2/Install.cab
O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.zestyfind.com/app/DS4/DS4.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O19 - User stylesheet: (file missing)


thks.-jackson

0

I have to head off to work right now, but I'll check back in 5 or 6 hours.

In the mean time:

There is a specific utility for removing EliteBar. Download it from the following link, read the instructions in the "readme.rtf" file that comes with it, and give it a try:

http://www.majorgeeks.com/download4465.html

Post a new HijackThis log after that.

This topic has been dead for over six months. Start a new discussion instead.
Have something to contribute to this discussion? Please be thoughtful, detailed and courteous, and be sure to adhere to our posting rules.