RhumbRunner13
No alts, no "Iggy"
- Joined
- Jan 4, 2002
- Posts
- 3,463
I was running Ad-aware yesterday when half way through a warning box popped up saying Norton had found an unrepairable virus, Backdoor.Agent.B. I let Ad-aware finish and ran virus scan; no virii detected. I then ran Spybot S&D, got the same warning and this time it would not clear/close. I let SB finish and had to reboot to clear the warning.
I Googled B.A.B. and found Symantic's site that indicated to me that B.A.B. must be cleaned manually through Regedit. I printed the instructions and started the process (minus the back up of "system state"). I disabled "System Restore". I updated virus definitions and ran another virus scan. I started Regedit and navigated to: HKEY_LOCAL_MACHINE_SOFTWARE\Microsoft\Windows\CurrentVersion\Run
The directions then were "in the right pane, delete the value: "*<1-5 random characters>"= "RUNDLL32%System%\DLL filename).dll.StreamingDeviceSetup. The ONLY file I have even similiar to that is a NvCplDaemon subkey that reads, "RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup.
Is that the value I should delete? It doesn't appear to be the same value as what the directions say to delete
.
Further on in the instructions it says to navigate to:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows and to double click "Appinit_DLLs" in the right pane and then to "delete the following text from the Value Data box"........I have NO value in the box - it is blank!
Sooo.......what do you guys think? Do I have B.A.B or not? Could something in Ad-aware and SB S&D be triggering a false warning?
Much further into the process and I will be over my head as far as changing stuff. Think I should just take the 'puter to a Pro?
Rhumb
I Googled B.A.B. and found Symantic's site that indicated to me that B.A.B. must be cleaned manually through Regedit. I printed the instructions and started the process (minus the back up of "system state"). I disabled "System Restore". I updated virus definitions and ran another virus scan. I started Regedit and navigated to: HKEY_LOCAL_MACHINE_SOFTWARE\Microsoft\Windows\CurrentVersion\Run
The directions then were "in the right pane, delete the value: "*<1-5 random characters>"= "RUNDLL32%System%\DLL filename).dll.StreamingDeviceSetup. The ONLY file I have even similiar to that is a NvCplDaemon subkey that reads, "RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup.
Is that the value I should delete? It doesn't appear to be the same value as what the directions say to delete
Further on in the instructions it says to navigate to:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows and to double click "Appinit_DLLs" in the right pane and then to "delete the following text from the Value Data box"........I have NO value in the box - it is blank!
Sooo.......what do you guys think? Do I have B.A.B or not? Could something in Ad-aware and SB S&D be triggering a false warning?
Much further into the process and I will be over my head as far as changing stuff. Think I should just take the 'puter to a Pro?
Rhumb