Forums
Technology

How to get rid of a virus :(Trojan.Elitebar ) Archived From: Technology

  • Text Only
  • Classic
  • Page :
  • 1

I scanned my C: hard drive yesterday with Norton anti virus and got the message:

Scan type: Realtime Protection Scan
Event: Virus Found!
Virus name: Trojan.Elitebar
File: C:\\WINDOWS\\SYSTEM32\\eliteoks32.exe
Location: C:\\WINDOWS\\SYSTEM32
Computer: XXXXX
User: BrXXXXX
Action taken: Clean failed : Quarantine failed : Access denied
Date found: Tue Sep 27 11:48:01 2005


This message pops up every seconds and How do I get rid of it. Thanks in advance


Quick Summary is created and edited by users like you... Add FAQ's, Links and other Relevant Information by clicking the edit button in the lower right hand corner of this message.


Update your virus definitions to begin with.
Scan computer with trend housecall online scanning.



StarPilot said:From Symantecs website,scroll down for removal.

Thanks, I'll try this




Hey Bruce. How's it going?




This Elitum infection is Spyware.

Here is information from the Spywareinfo Forums concerning this parasite.



This infection is also known as Elitebar/EliteToolbar/EliteSidebar. It is not new, but this seems to be a newer variant of it.

Symptoms

The main symptom is an O4 in a HijackThis log, with one of the following names:

1) checkrun
2) etbrun
3) antiware
4) kalvsys
5) System service##, where ## represents a number

Examples of the O4 lines look like:

O4 - HKLM\\..\\Run: [checkrun] c:\\winnt\\system32\\eliteveu32.exe
O4 - HKLM\\..\\Run: [etbrun] C:\\winnt\\system32\\elitegss32.exe
O4 - HKLM\\..\\Run: [antiware] C:\\winnt\\system32\\elitekrs32.exe
O4 - HKLM\\..\\Run: [kalvsys] C:\\windows\\system32\\kalvhwl32.exe
O4 - HKLM\\..\\Run: [SystemService] C:\\WINDOWS\\etb\\pokapoka62.exe
O4 - HKLM\\..\\Run: [System service62] C:\\WINDOWS\\etb\\pokapoka62.exe
O4 - HKLM\\..\\Run: [lsass] c:\\windows\\system32\\elitejhs32.exe
O4 - HKLM\\..\\Run: [System service64] C:\\WINDOWS\\etb\\pokapoka64.exe
O4 - HKLM\\..\\Run: [System service65] C:\\WINDOWS\\etb\\pokapoka65.exe

New names might arise, so another symptom is any .exe file associated with an O4 beginning with the text elite* or pokapoka*

Resolution

Please download LQfix.exe and place it on your desktop.
Boot into Safe Mode.
Double-click LQfix.exe and click install.
Leave the default settings. If you change them, the fix will fail.
Make sure 'Launch LQfix' is checked. After clicking finish in the install, the fix will start.
Follow the prompts on the screen. Your system will reboot afterwards.
Your system may take longer than usual to start up this one time; please be patient.


if a Look2Me infection is present, you must remove it first using L2Mfix on Windows 2K/XP, or L2m9xfix on Windows 98/ME. Otherwise LQfix will not work!




Now, not having seen a HiJackThis log, I don't know if you have any other parasites on your system other than what Norton detected. There are a lot of spyware parasites that Norton and other AV programs will not detect.

If there are other parasites on your system, then you are best off reading the Spyware Help Guide. The most important part of it is running HiJackThs and posting the resulting log to one of the listed ASAP security forums.


Boot up in safe mode, then delete C:\\WINDOWS\\SYSTEM32\\eliteoks32.exe.

rudinator1 said:I scanned my C: hard drive yesterday with Norton anti virus and got the message:

Scan type: Realtime Protection Scan
Event: Virus Found!
Virus name: Trojan.Elitebar
File: C:\\WINDOWS\\SYSTEM32\\eliteoks32.exe
Location: C:\\WINDOWS\\SYSTEM32
Computer: XXXXX
User: BrXXXXX
Action taken: Clean failed : Quarantine failed : Access denied
Date found: Tue Sep 27 11:48:01 2005


This message pops up every seconds and How do I get rid of it. Thanks in advance


titewad said:Boot up in safe mode, then delete C:\\WINDOWS\\SYSTEM32\\eliteoks32.exe.

rudinator1 said:I scanned my C: hard drive yesterday with Norton anti virus and got the message:

Scan type: Realtime Protection Scan
Event: Virus Found!
Virus name: Trojan.Elitebar
File: C:\\WINDOWS\\SYSTEM32\\eliteoks32.exe
Location: C:\\WINDOWS\\SYSTEM32
Computer: XXXXX
User: BrXXXXX
Action taken: Clean failed : Quarantine failed : Access denied
Date found: Tue Sep 27 11:48:01 2005

This message pops up every seconds and How do I get rid of it. Thanks in advance


There is more to the problem than the .exe file. OP should follow the advise of DragonsLore.


isles1 said:titewad said:Boot up in safe mode, then delete C:\\WINDOWS\\SYSTEM32\\eliteoks32.exe.

rudinator1 said:I scanned my C: hard drive yesterday with Norton anti virus and got the message:

Scan type: Realtime Protection Scan
Event: Virus Found!
Virus name: Trojan.Elitebar
File: C:\\WINDOWS\\SYSTEM32\\eliteoks32.exe
Location: C:\\WINDOWS\\SYSTEM32
Computer: XXXXX
User: BrXXXXX
Action taken: Clean failed : Quarantine failed : Access denied
Date found: Tue Sep 27 11:48:01 2005

This message pops up every seconds and How do I get rid of it. Thanks in advance


There is more to the problem than the .exe file. OP should follow the advise of DragonsLore.



Wouldn't Symantec Information be more complete ?


If Symantec AV was designed to detect and remove all spyware, then there would be no need for any other tool that is designed to remove such parasites.

There is a lot more to spyware infections than just one or two files that may or may not be detected by symantec. There are registry entries, hidden files and other tricks used to try to prevent the parasites from being removed.


DragonsLore said:This Elitum infection is Spyware.

Here is information from the Spywareinfo Forums concerning this parasite.



This infection is also known as Elitebar/EliteToolbar/EliteSidebar. It is not new, but this seems to be a newer variant of it.

Symptoms

The main symptom is an O4 in a HijackThis log, with one of the following names:

1) checkrun
2) etbrun
3) antiware
4) kalvsys
5) System service##, where ## represents a number

Examples of the O4 lines look like:

O4 - HKLM\\..\\Run: [checkrun] c:\\winnt\\system32\\eliteveu32.exe
O4 - HKLM\\..\\Run: [etbrun] C:\\winnt\\system32\\elitegss32.exe
O4 - HKLM\\..\\Run: [antiware] C:\\winnt\\system32\\elitekrs32.exe
O4 - HKLM\\..\\Run: [kalvsys] C:\\windows\\system32\\kalvhwl32.exe
O4 - HKLM\\..\\Run: [SystemService] C:\\WINDOWS\\etb\\pokapoka62.exe
O4 - HKLM\\..\\Run: [System service62] C:\\WINDOWS\\etb\\pokapoka62.exe
O4 - HKLM\\..\\Run: [lsass] c:\\windows\\system32\\elitejhs32.exe
O4 - HKLM\\..\\Run: [System service64] C:\\WINDOWS\\etb\\pokapoka64.exe
O4 - HKLM\\..\\Run: [System service65] C:\\WINDOWS\\etb\\pokapoka65.exe

New names might arise, so another symptom is any .exe file associated with an O4 beginning with the text elite* or pokapoka*

Resolution

Please download LQfix.exe and place it on your desktop.
Boot into Safe Mode.
Double-click LQfix.exe and click install.
Leave the default settings. If you change them, the fix will fail.
Make sure 'Launch LQfix' is checked. After clicking finish in the install, the fix will start.
Follow the prompts on the screen. Your system will reboot afterwards.
Your system may take longer than usual to start up this one time; please be patient.


if a Look2Me infection is present, you must remove it first using L2Mfix on Windows 2K/XP, or L2m9xfix on Windows 98/ME. Otherwise LQfix will not work!




Now, not having seen a HiJackThis log, I don't know if you have any other parasites on your system other than what Norton detected. There are a lot of spyware parasites that Norton and other AV programs will not detect.

If there are other parasites on your system, then you are best off reading the Spyware Help Guide. The most important part of it is running HiJackThs and posting the resulting log to one of the listed ASAP security forums.

Thanks dragon lore and everyone else. I'll try this solution and let you guys know.


DragonsLore said:If Symantec AV was designed to detect and remove all spyware, then there would be no need for any other tool that is designed to remove such parasites.

There is a lot more to spyware infections than just one or two files that may or may not be detected by symantec. There are registry entries, hidden files and other tricks used to try to prevent the parasites from being removed.



Are you implying that Symantec's solution for this particular spyware is incomplete and/or incorrect ?


IQ70 said:Are you implying that Symantec's solution for this particular spyware is incomplete and/or incorrect ?Yes


ellory said:IQ70 said:Are you implying that Symantec's solution for this particular spyware is incomplete and/or incorrect ?Yes

Any comparisions of what extra the LQFix.exe does more than the Symantec's website suggests ?
I would be interested in checking it out.
Thanks


I'm sure that Norton's advice for the removal of that virus /spyware is good.

What I'm also sure about is that the likelihood of one and only infection is small (Analogy: If you see one mouse in your house, you likely have many)

This is why we are recommending you bring out the full battery of tools to ensure your PC is clean


 Close

Sign Me In
Nickname: 
Password: 
Remember My Login Information:

Forget your login information?

Not Already A Member?
Sign Up Now!



Disclaimer: By providing links to other sites, FatWallet.com does not guarantee, approve or endorse the information or products available at these sites, nor does a link indicate any association with or endorsement by the linked site to FatWallet.com.


While FatWallet makes every effort to post correct information, offers are subject to change without notice.
Some exclusions may apply based upon merchant policies.
© 1999-2010