trojan plus elitum.elitebar

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Rastabaxus, Mar 20, 2005.

  1. Rastabaxus

    Rastabaxus Private E-2

    Hi,

    I was browsing through your forums looking for help on removing this trojan horse (I know the file that is infected thanks to symantecs online scan but I don't know the best way of removing it). It is trojan.StartPage located in my system32/temperror32.dat.

    Note that the trojan was found while trying to get rid of Elitum.Elitebar (something to do with searchmiracle I think). I get the ads popping up every few seconds. Spybot found the elitum.elitebar.

    I went through the post about removing all these things. I downloaded all the programs and went step by step. The Elitum.Elitebar comes back after it is deleted from the registry. I have log files from adaware and spybot as well as a hijackthis log.

    I beleive that I have done everything that you have mentioned and this is still driving me crazy. Oh, I also went to searchmiracle.com and tried their uninstall file and it is as bad as the popups. You have to close it with the task manager.

    Please if you can help thanks...

    Scott
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try giving this a run first: EliteToolbar Remover

    If that does not help procede to the below steps!

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. Rastabaxus

    Rastabaxus Private E-2

    Do you have any advice about the trojan? I have left it because I didn't want to delete a file that my system needs... I am waiting to see if the popups come back right now. So far so good.

    Thanks for the quick reply by the way.... :D
     
  4. Rastabaxus

    Rastabaxus Private E-2

    Well I thought after using the program you suggested it would get rid of it but I am still getting the ads.

    I am attaching my hijackthis log.

    the ads come from ads1.searchmiracle.com and http://e.rnll.com

    There was one line in the hijackthis log that I have tried removing and it keeps coming back... it is..


    O4 - HKLM\..\Run: [etbrun] C:\windows\system32\eliterfk32.exe
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is this log from safe boot mode or normal boot mode. Please note that you installed HijackThis into a folder that we specifically requested that you not use. Please fix this.

    First a couple comments:
    1) You are running without an antivirus application. This is a very very bad idea.
    2) You do not have a software firewall installed. The one built-in to WinXP SP2 is not sufficient.

    You need to visit the below thread and take all the steps indicated:

    How to Protect yourself from malware!

    You have conime.exe running on your PC. Read the below. This is why you need an antivirus application and a firewall.

    conime.exe is a process which is registered as the BFGhost 1.0 Remote administration backdoor tool. This backdoor application can allow attackers to access your computer, stealing passwords and personal data. It is a registered security risk and should be removed immediately. Please see additional details regarding this process

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\system32\conime.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [etbrun] C:\windows\system32\eliterfk32.exe
    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\conime.exe
    C:\windows\system32\eliterfk32.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  6. Rastabaxus

    Rastabaxus Private E-2

    I did the things you mentioned and you should see them in hijackthis.

    First conime.exe is gone I believe...

    However eliterfk32.exe does not want to leave... I noticed in system32 that there are 9 other files elitebsu32.exe, eliteevo32.exe, elitewc32.exe, elitehod32.exe, eliteklc32.exe, elitebw32.exe, elitetfj32.exe, elitevsr32.exe, eliteztu32.exe

    I think after the other software and microsoft antispy has blocked eliterfk32.exe I am not getting pop ups now.

    Here is my new log and thanks for the help
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should boot into safe mode and have HJT fix the below entry (but make sure all browsers are closed - you had a browser running when you last posted your HJT log):

    O4 - HKLM\..\Run: [etbrun] C:\windows\system32\eliterfk32.exe

    After fixing exit HJT.
    Run Windows Explorer and delete:
    C:\windows\system32\eliterfk32.exe

    Also delete the others you mentioned:
    elitebsu32.exe, eliteevo32.exe, elitewc32.exe, elitehod32.exe, eliteklc32.exe, elitebw32.exe, elitetfj32.exe, elitevsr32.exe, eliteztu32.exe

    Then reboot in normal mode and post a new HJT log. If it comes back again you need to run msconfig and set it for Normal Startup. I need to see all things that may be hiding in your startup.
     
  8. Rastabaxus

    Rastabaxus Private E-2

    Ok,

    I think it is gone but here is another HJT log so you can check it out. I am not getting the popups anymore and I scanned the log and eliter did not come back.

    Thanks for the help
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  10. Rastabaxus

    Rastabaxus Private E-2

    Thanks for all your help. I think windows is even running faster and smoother if that is possible. I think I have learned a fair bit from this and will protect my computer better from this point on.

    I will recommend this site to anyone who needs help. Thanks and everyone who helps here deserve a medal for being super helpful and informative.

    Scott
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome Scott and thanks for recommending us to others! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds