|
Next: Is this virus?
|
| Author |
Message |
External

Since: Apr 19, 2007 Posts: 16
|
(Msg. 1) Posted: Sun Feb 04, 2007 1:06 am
Post subject: malware removal Archived from groups: microsoft>public>windowsxp>newusers (more info?)
|
|
|
Hello, I need advice on how to remove a malware item which spyboot cannot
remove. Spyboot spotted a folder called BDE which is in the windows
directory, what I don't know whether the entire folder is malware or only
part of it. Is BDE a windows folder?, what I get with this is a pop up
advertising which after being closed keeps on opening. Please help me on how
to remove this manualy
Thank you for your assistance. I have xp home edition
Elly |
|
| Back to top |
|
 |  |
External

Since: Sep 29, 2006 Posts: 196
|
(Msg. 2) Posted: Sun Feb 04, 2007 2:48 am
Post subject: RE: malware removal [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
"elly" wrote:
> Hello, I need advice on how to remove a malware item which spyboot cannot
> remove. Spyboot spotted a folder called BDE which is in the windows
> directory, what I don't know whether the entire folder is malware or only
> part of it. Is BDE a windows folder?, what I get with this is a pop up
> advertising which after being closed keeps on opening. Please help me on how
> to remove this manualy
> Thank you for your assistance. I have xp home edition
>
Hi Elly,
Yes it is Adware folder created to let advertising po-up on your computer,
to remove follow these steps:
Locate the folder in these pathes and Delete:
C:\BDE
C:\Windows\BDE
C:\Windows\System32\BDE
C:\Program Files\BDE
Also open the Local search on your desktp and search for these files/foldrs:
Bdeclean.exe
Bdeclean.glc
b3bupdate
Then Open a run command andtype in:
regedit.exe click [OK]
On the Registry Editor locates these Keys and delete the Entries for the
Adware:
<Quote>//** [be careful in editing the registry, if you done in the wrong
way you will render your OS useless]**//
KEY_CLASSES_ROOT\s3d_auto_file
HKEY_CLASSES_ROOT\.b3dini
HKEY_CLASSES_ROOT\b3d_auto_file
HKEY_CLASSES_ROOT\b3dini_auto_file
HKEY_CLASSES_ROOT\BDEPLAYER.BDEPlayerCtrl
HKEY_CLASSES_ROOT\BDEPLAYER.BDEPlayerCtrl.1
HKEY_ALL_USERS\Software\Brilliant Digital Entertainment
HKEY_CLASSES_ROOT\BDESmartInstaller.BDESmartInstaller
HKEY_CLASSES_ROOT\BDESmartInstaller.BDESmartInstaller.1
HKEY_CLASSES_ROOT\BDESmartInstaller25.BDESmartInstaller25.1
HKEY_CLASSES_ROOT\BDESmartInstaller25.BDESmartInstaller25
HKEY_LOCAL_MACHINE\SOFTWARE\Brilliant Digital Entertainment
HKEY_CLASSES_ROOT\CLSID\{51958169-D5E3-11D1-AA42-0000E842E40A}
HKEY_CLASSES_ROOT\CLSID\{67925165-C4B6-11D2-B9C6-0000E84F59A6}
HKEY_CLASSES_ROOT\Interface\{51958167-D5E3-11D1-AA42-0000E842E40A}
HKEY_CLASSES_ROOT\Interface\{51958168-D5E3-11D1-AA42-0000E842E40A}
HKEY_CLASSES_ROOT\Typelib\{51958166-D5E3-11D1-AA42-0000E842E40A}
HKEY_CLASSES_ROOT\TypeLib\{82FC7881-AACC-11D2-B9C6-0000E842E40A}
HKEY_CLASSES_ROOT\Interface\{67925164-C4B6-11D2-B9C6-0000E84F59A6}
HKEY_CLASSES_ROOT\CLSID\{3EEC42B5-FB94-40D3-A588-BB54B383A7CB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bdeplayer
</Quote>
Also locate this Key:
[-] HKEY_Local machine\Software\Microsoft\Windows\CurrentVersion\Run = look
in the Right pane/window and locate this entry and delet:
"b3bUpdate"
"Bdeclean.exe"
"Bdeclean.lgc"
[-]HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\\CurrentVersion\RunOnce =
"b3bUpdate"
"Bdeclean.exe"
"Bdeclean.lgc"
Close the Registry Editor and then Run a Disk CleanUP and clear your Caches
and Temp files/folders.
Run a scan for Viruses and Malwares again to be sure all clean in some cases
the BDE is a Trojans, Borland Database Engine.
HTH.
Let us know.
Regards,
nass |
|
| Back to top |
|
 |  |
External

Since: Jun 18, 2006 Posts: 40
|
(Msg. 3) Posted: Mon Feb 05, 2007 8:56 am
Post subject: Re: malware removal [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
Hi Elly,
The other alternative is to run HijackThis, available here:
http://downloads.malwareremoval.com/HJTsetup.exe , with instructions here:
http://forum.malwareremoval.com/viewtopic.php?t=16805
--
Curt
http://dundats.mvps.org/
http://www.aumha.org/
"nass" <nass DeleteThis @discussions.microsoft.com> wrote in message
news:E9134C6E-0FDF-4419-9408-39DDE78B9A53@microsoft.com...
|
|
| "elly" wrote:
|
| > Hello, I need advice on how to remove a malware item which spyboot
cannot
| > remove. Spyboot spotted a folder called BDE which is in the windows
| > directory, what I don't know whether the entire folder is malware or
only
| > part of it. Is BDE a windows folder?, what I get with this is a pop up
| > advertising which after being closed keeps on opening. Please help me
on how
| > to remove this manualy
| > Thank you for your assistance. I have xp home edition
| >
|
| Hi Elly,
| Yes it is Adware folder created to let advertising po-up on your computer,
| to remove follow these steps:
| Locate the folder in these pathes and Delete:
| C:\BDE
| C:\Windows\BDE
| C:\Windows\System32\BDE
| C:\Program Files\BDE
|
| Also open the Local search on your desktp and search for these
files/foldrs:
| Bdeclean.exe
| Bdeclean.glc
| b3bupdate
|
| Then Open a run command andtype in:
| regedit.exe click [OK]
| On the Registry Editor locates these Keys and delete the Entries for the
| Adware:
| <Quote>//** [be careful in editing the registry, if you done in the wrong
| way you will render your OS useless]**//
| KEY_CLASSES_ROOT\s3d_auto_file
| HKEY_CLASSES_ROOT\.b3dini
| HKEY_CLASSES_ROOT\b3d_auto_file
| HKEY_CLASSES_ROOT\b3dini_auto_file
| HKEY_CLASSES_ROOT\BDEPLAYER.BDEPlayerCtrl
| HKEY_CLASSES_ROOT\BDEPLAYER.BDEPlayerCtrl.1
| HKEY_ALL_USERS\Software\Brilliant Digital Entertainment
| HKEY_CLASSES_ROOT\BDESmartInstaller.BDESmartInstaller
| HKEY_CLASSES_ROOT\BDESmartInstaller.BDESmartInstaller.1
| HKEY_CLASSES_ROOT\BDESmartInstaller25.BDESmartInstaller25.1
| HKEY_CLASSES_ROOT\BDESmartInstaller25.BDESmartInstaller25
| HKEY_LOCAL_MACHINE\SOFTWARE\Brilliant Digital Entertainment
| HKEY_CLASSES_ROOT\CLSID\{51958169-D5E3-11D1-AA42-0000E842E40A}
| HKEY_CLASSES_ROOT\CLSID\{67925165-C4B6-11D2-B9C6-0000E84F59A6}
| HKEY_CLASSES_ROOT\Interface\{51958167-D5E3-11D1-AA42-0000E842E40A}
| HKEY_CLASSES_ROOT\Interface\{51958168-D5E3-11D1-AA42-0000E842E40A}
| HKEY_CLASSES_ROOT\Typelib\{51958166-D5E3-11D1-AA42-0000E842E40A}
| HKEY_CLASSES_ROOT\TypeLib\{82FC7881-AACC-11D2-B9C6-0000E842E40A}
| HKEY_CLASSES_ROOT\Interface\{67925164-C4B6-11D2-B9C6-0000E84F59A6}
| HKEY_CLASSES_ROOT\CLSID\{3EEC42B5-FB94-40D3-A588-BB54B383A7CB}
|
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bdeplayer
| </Quote>
| Also locate this Key:
| [-] HKEY_Local machine\Software\Microsoft\Windows\CurrentVersion\Run =
look
| in the Right pane/window and locate this entry and delet:
| "b3bUpdate"
| "Bdeclean.exe"
| "Bdeclean.lgc"
|
| [-]HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\\CurrentVersion\RunOnce =
| "b3bUpdate"
| "Bdeclean.exe"
| "Bdeclean.lgc"
|
| Close the Registry Editor and then Run a Disk CleanUP and clear your
Caches
| and Temp files/folders.
| Run a scan for Viruses and Malwares again to be sure all clean in some
cases
| the BDE is a Trojans, Borland Database Engine.
| HTH.
| Let us know.
| Regards,
| nass
| |
|
| Back to top |
|
 |  |
External

Since: Jun 18, 2006 Posts: 40
|
(Msg. 4) Posted: Mon Feb 05, 2007 9:47 am
Post subject: Re: malware removal [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
|
|
|
Hi Elly,
I neglected to mention after running HJT, *do not allow it to repair
anything*.
Submit your log to either:
http://aumha.net/viewforum.php?f=30 or,
http://forum.malwareremoval.com/viewforum.php?f=11 , and the experts there
can help you out.
--
Curt
http://dundats.mvps.org/
http://www.aumha.org/
"Curt Christianson" <curtchristnsn.TakeThisOut@NOSPAMyahoo.com> wrote in message
news:eAGPKXTSHHA.5012@TK2MSFTNGP04.phx.gbl...
| Hi Elly,
|
| The other alternative is to run HijackThis, available here:
| http://downloads.malwareremoval.com/HJTsetup.exe , with instructions
here:
|
| http://forum.malwareremoval.com/viewtopic.php?t=16805
|
| --
| Curt
|
| http://dundats.mvps.org/
| http://www.aumha.org/
|
|
| "nass" <nass.TakeThisOut@discussions.microsoft.com> wrote in message
| news:E9134C6E-0FDF-4419-9408-39DDE78B9A53@microsoft.com...
||
||
|| "elly" wrote:
||
|| > Hello, I need advice on how to remove a malware item which spyboot
| cannot
|| > remove. Spyboot spotted a folder called BDE which is in the windows
|| > directory, what I don't know whether the entire folder is malware or
| only
|| > part of it. Is BDE a windows folder?, what I get with this is a pop up
|| > advertising which after being closed keeps on opening. Please help me
| on how
|| > to remove this manualy
|| > Thank you for your assistance. I have xp home edition
|| >
||
|| Hi Elly,
|| Yes it is Adware folder created to let advertising po-up on your
computer,
|| to remove follow these steps:
|| Locate the folder in these pathes and Delete:
|| C:\BDE
|| C:\Windows\BDE
|| C:\Windows\System32\BDE
|| C:\Program Files\BDE
||
|| Also open the Local search on your desktp and search for these
| files/foldrs:
|| Bdeclean.exe
|| Bdeclean.glc
|| b3bupdate
||
|| Then Open a run command andtype in:
|| regedit.exe click [OK]
|| On the Registry Editor locates these Keys and delete the Entries for the
|| Adware:
|| <Quote>//** [be careful in editing the registry, if you done in the wrong
|| way you will render your OS useless]**//
|| KEY_CLASSES_ROOT\s3d_auto_file
|| HKEY_CLASSES_ROOT\.b3dini
|| HKEY_CLASSES_ROOT\b3d_auto_file
|| HKEY_CLASSES_ROOT\b3dini_auto_file
|| HKEY_CLASSES_ROOT\BDEPLAYER.BDEPlayerCtrl
|| HKEY_CLASSES_ROOT\BDEPLAYER.BDEPlayerCtrl.1
|| HKEY_ALL_USERS\Software\Brilliant Digital Entertainment
|| HKEY_CLASSES_ROOT\BDESmartInstaller.BDESmartInstaller
|| HKEY_CLASSES_ROOT\BDESmartInstaller.BDESmartInstaller.1
|| HKEY_CLASSES_ROOT\BDESmartInstaller25.BDESmartInstaller25.1
|| HKEY_CLASSES_ROOT\BDESmartInstaller25.BDESmartInstaller25
|| HKEY_LOCAL_MACHINE\SOFTWARE\Brilliant Digital Entertainment
|| HKEY_CLASSES_ROOT\CLSID\{51958169-D5E3-11D1-AA42-0000E842E40A}
|| HKEY_CLASSES_ROOT\CLSID\{67925165-C4B6-11D2-B9C6-0000E84F59A6}
|| HKEY_CLASSES_ROOT\Interface\{51958167-D5E3-11D1-AA42-0000E842E40A}
|| HKEY_CLASSES_ROOT\Interface\{51958168-D5E3-11D1-AA42-0000E842E40A}
|| HKEY_CLASSES_ROOT\Typelib\{51958166-D5E3-11D1-AA42-0000E842E40A}
|| HKEY_CLASSES_ROOT\TypeLib\{82FC7881-AACC-11D2-B9C6-0000E842E40A}
|| HKEY_CLASSES_ROOT\Interface\{67925164-C4B6-11D2-B9C6-0000E84F59A6}
|| HKEY_CLASSES_ROOT\CLSID\{3EEC42B5-FB94-40D3-A588-BB54B383A7CB}
||
|
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bdeplayer
|| </Quote>
|| Also locate this Key:
|| [-] HKEY_Local machine\Software\Microsoft\Windows\CurrentVersion\Run =
| look
|| in the Right pane/window and locate this entry and delet:
|| "b3bUpdate"
|| "Bdeclean.exe"
|| "Bdeclean.lgc"
||
|| [-]HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\\CurrentVersion\RunOnce
=
|| "b3bUpdate"
|| "Bdeclean.exe"
|| "Bdeclean.lgc"
||
|| Close the Registry Editor and then Run a Disk CleanUP and clear your
| Caches
|| and Temp files/folders.
|| Run a scan for Viruses and Malwares again to be sure all clean in some
| cases
|| the BDE is a Trojans, Borland Database Engine.
|| HTH.
|| Let us know.
|| Regards,
|| nass
||
|
| |
|
| Back to top |
|
 |  |
| Related Topics: | Malware and ???? - Someone in my family must have gone into a site and guess what. I get two warnings on my task bar. SYSTEM ALERT: MALWARE THREATS your computer is infected with a back door Trojan that allows the remote attacker to perform various malicious actions...
Malware question - Hi, I've read that one can download trojans and other malware by simply going to a site like youtube. Is this true? Thanks.
Login Removal Help - I want to simply turn on my computer and have it go directly to my desktop, but all of a sudden I cannot do that without being prompted to login. I am not on a network; just my home PC, and I am the only one who uses it. I went to *user accounts* and....
Printer removal - Hi, We have recently converted from Novell to Windows 2003 server. Unfortunately, we did not remove the netware pinters before we removed the Novell client. Is there any simple way to remove these printers? Thanks for any and all help. John H
File Removal - I have a file sitting on my Add/Remove program that has been removed manually, every time I try to install the updated version of this it says that I need to delete the older version first, I have tried to do this in every way I can think of to no.. |
|
You can post new topics in this forum You can reply to topics in this forum You can edit your posts in this forum You can delete your posts in this forum You can vote in polls in this forum
|
|
|
|