Unsolved
This post is more than 5 years old
3 Posts
0
4523
October 18th, 2004 20:00
Hmmmm What are these
Not much info to give but I'll try.
First getting a dvdarb.exe in process and also in windows/driver cache there is that exe and 2 files with it, rbadvd.ini and rbadvd.bak1 . any attempt to deletes these files (hidden system folders) fails, they recreate themselves.
Also there is a antieula.exe that wont close. no info found so far on either one. any help would go a long ways thatnks.
Norton does not see either one of these and neither does dos. Booting to a disk to use dos to see them shows nothing as if they werent there. Deleted them in the registry worked for all of one second then they came back.
Thanks
Gogot
No Events found!


Midnight Star
4.8K Posts
0
October 18th, 2004 23:00
First download and install the following programs:
1) AdAware SE Personal; check for malware-signature updates.
2) Spybot S&D; check for malware-signature updates.
3) Asquared2 from www.emsisoft.com; check for trojan-signature updates.
4) HiJackThis; v1.98.2.
5) LSPFix from CEXX.org.
First, browse to www.trendmicro.com and run their online virus scanner. Let's see if it can remove the re-infector.
Next, run Asquared2, AdAware SE Personal, and Spybot S&D (one at a time).
Watch out when removing problems like NewDotNet. If you 'fix' them with these programs, you could loose internet connectivity (that's where LSPfix will come in). If your not sure whats what, just do a GOOGLE on the problem, it should turn up something as reference. Then just see if anyone else has had problems using either of these programs to fix the 'baddie'.
If they have any problems fixing things they find, try running them again from "Safe Mode".
After that, place HiJackThis in it's own folder (not in a temp directory), and run it. Click "Scan", then "Save log". Copy/paste the text from notepad, and post it back. Don't attempt to 'fix' anything, no matter how strange it looks, unless your sure about what the entries are.
Mike.
Gogot
3 Posts
0
October 19th, 2004 12:00
cghost
302 Posts
0
October 19th, 2004 13:00
gogot
If you are not getting hits on a particular file, it is probably a bad file. If you get something that you think is bad, you could try renaming it to see if that helps the problems. The problem with renaming or fixing just an apparent bad file is that many times there is another reloader somewhere that is less obvious. Posting a hijackthis log from one of your troubled machines would allow the people here to see your problem processes in the environment of all processes running on the machine and maybe offer you a suggestion that would allow you to get the machine fixed.
Regards.
cg
tjpm12
77 Posts
0
October 20th, 2004 11:00
Hi. Firstly, you sound very capable. Experience has indicated that a SYSTEM RESTORE is necessary after deleting in the Registry Editor. This might well be done OFF-LIne. Restore is at start/help support/RESTORE. It can't hurt to delet the cookies as well. start/explorer/tools/options/delete cookies
This is just a bystanders proposal.
Gogot
3 Posts
0
October 20th, 2004 14:00
Tried all of these and still nothing. security here prevents me from posting our hyjackthis logs, wish I could. Our programer wrote a script that worked for about one hour than it came back again under yet back with a differant name each time. They decided to wipe all infected computers but 2 ( the 2 for research). We did confirm it is sending out data somewhere. Realy want to nail this bugger down but not being able to even know its name is a head ache and half, or it point of origin. At least it has yet to anything other than s*cking memory and cpu resources.
Again thanks all for the help.
Gogot.
tjpm12
77 Posts
0
October 20th, 2004 16:00
tjpm12
77 Posts
0
October 20th, 2004 16:00