hankg
05-21-2005, 06:56 PM
Hello,
I found this board through googling elitenzm32.exe and found this thread:
http://www.pcguide.com/vb/showthread.php?p=227686
Having a tough time getting rid of elitenxzm32.exe. If you delete it it comes back under new names until the reboot. If you disable it from loading in msconfig it comes right back. Same if you remove it with hijackthis. Tried killing it with killbox, hunting it down through the registry and removing anything I could find related to elite, elitesearch toolbar, etc..
All the other 232 objects and programs have been ripped out of this machine with the exception of this last one. Aurora and coolwebsearch were a piece of cake compared to this.
Here is the current hijackthis log.
Logfile of HijackThis v1.99.0
Scan saved at 6:42:29 PM, on 5/21/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALURIA~2\asKernel.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\rdpclip.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\WINDOWS\system32\svchost.exe
C:\spywareremove\hijackthis199.exe
C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [sunasServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe
O4 - HKLM\..\Run: [sunasDtServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitenzm32.exe
O23 - Service: Aluria Security Center Spyware Eliminator Service - Unknown - C:\PROGRA~1\ALURIA~2\ascserv.exe
O23 - Service: asKernel - Unknown - C:\PROGRA~1\ALURIA~2\asKernel.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Symantec AntiVirus Client - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
askernel is Aluria's spyware removal as they said they could do it. :(
PPmemcheck, cookiepatrol and pestpatrol are PestPatrol
Dewatch is NAVC Enterprise
Any tips would sure be appreciated.
I found this board through googling elitenzm32.exe and found this thread:
http://www.pcguide.com/vb/showthread.php?p=227686
Having a tough time getting rid of elitenxzm32.exe. If you delete it it comes back under new names until the reboot. If you disable it from loading in msconfig it comes right back. Same if you remove it with hijackthis. Tried killing it with killbox, hunting it down through the registry and removing anything I could find related to elite, elitesearch toolbar, etc..
All the other 232 objects and programs have been ripped out of this machine with the exception of this last one. Aurora and coolwebsearch were a piece of cake compared to this.
Here is the current hijackthis log.
Logfile of HijackThis v1.99.0
Scan saved at 6:42:29 PM, on 5/21/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALURIA~2\asKernel.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\rdpclip.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe
C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\WINDOWS\system32\svchost.exe
C:\spywareremove\hijackthis199.exe
C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [sunasServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasServ.exe
O4 - HKLM\..\Run: [sunasDtServ] C:\Program Files\Sunbelt Software\CounterSpy Client\sunasDtServ.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [checkrun] C:\windows\system32\elitenzm32.exe
O23 - Service: Aluria Security Center Spyware Eliminator Service - Unknown - C:\PROGRA~1\ALURIA~2\ascserv.exe
O23 - Service: asKernel - Unknown - C:\PROGRA~1\ALURIA~2\asKernel.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Symantec AntiVirus Client - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
askernel is Aluria's spyware removal as they said they could do it. :(
PPmemcheck, cookiepatrol and pestpatrol are PestPatrol
Dewatch is NAVC Enterprise
Any tips would sure be appreciated.