ELITEMWV32.EXE virus How to get rid of it?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Ecin, May 13, 2005.

  1. Ecin

    Ecin Private First Class

    Hello,

    Somehow my computer got infected with spyware and this ELITEWMV32@.EXE has shown up in my startup. I removed it but it just comes back. Ran adaware and alot of stuff with the name Elite came up and I deleted it all. Also, went into my registry and deleted everything with this filename. I think I got rid of it however, the filename keeps coming back into my startup. It says the filename ELITEMWV32.EXE is in my windows systems32 folder. I checked and searched and the file does not exist. Ran adaware andNorton for Virus, andanother virus program and it didn't find anything.

    Why does this keep popping into my startup and is it doing anything? I also checked my programs running and nothing unusual there.

    Any advice please, thank you!
     
  2. Ecin

    Ecin Private First Class

    the real name of the file is ELITEMWV.EXE

    Iedited my post but it didn't change in the post... thanks for reading
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Typically you will see a line that loads one of these elitexxxxx.exe files in a HijackThis log. That entry must be fixed so that the file does not load at startup. Then you must boot into safe mode and got to the c:\windows\system32 (or c:\winnt\system32) folder and look for all filenames beginning with elite and ending with exe. There could be as many as 10 of them. Delete them all. You need to have viewing of hidden and system files enabled per the READ ME FIRST sticky. You should run the steps in that sticky thread too.
     
  4. Ecin

    Ecin Private First Class



    Thank you VERY much. I ram hijack this and found the entry that i needed to delete. Then went into safe mode and found 3 .exe files with the elite name. I deleted them and now it seems to be gone. No more running at bootup.


    Any idea what this thing did or was trying to do?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It causes popups on your PC. Many people are getting this lately. You may want to consider running thru the full cleaning procedures to make sure you do not have any other items hanging around. Experience has show that in most cases, where there is one problem, there are more. If you wish to run thru these procedures, here they are:


    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds