Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of DiamondCS Support Forums > Trojan Defence Suite
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 4th, 2005, 08:07 AM
carbonrose carbonrose is offline
Infrequent Poster
 
Join Date: Apr 2005
Posts: 2
Default TDS-3 failing to delete r.bot, agobot from registry

I have been cleaning my PC over the last few weeks. I have used many tools and followed methods described in other forums to clean this PC.
I have now come down to only two remaining problems.
Only TDS-3 detects these issues.

Here is an exact copy of the log file from TDS-3

Scan Control Dumped @ 00:57:03 04-04-05

RegVal Trace: DDoS.RAT.rBot: HKEY_LOCAL_MACHINE
File: Software\Microsoft\Windows\CurrentVersion\RunServices [Sygate Personal Firewall=Sygate.exe]

RegVal Trace: DDoS.RAT.Agobot: HKEY_CURRENT_USER
File: Software\Microsoft\Ole [blah service=evosys.exe]

(DELETED) Positive identification (DLL): Adware.Ramdud (dll)
File: c:\windows\system32\winsrvs_1.dll

I have chosen to delete the two remaining files with TDS-3 and it confirms that they have been deleted.
but,
I restart the pc, run another check to be sure and they have been eliminated but they are still there.

I have used AVG, Ad-Aware, Spybot, CWshredder, trojan hunter, many online virus scanners, clean-up, windows washer, About Buster... Have used the action of safe mode with system restore disabled, Spybot immunize off and disabled, all hidden files and folders revealed.
But as I have previously mentioned, only TDS-3 detects these.


Is it safe to maually delete these from the reg.
or
Is there another issue with these two corrupt files. Am I doing something wrong perhaps.

Regards

CR.
  #2  
Old April 12th, 2005, 12:16 AM
carbonrose carbonrose is offline
Infrequent Poster
 
Join Date: Apr 2005
Posts: 2
Default Re: TDS-3 failing to delete r.bot, agobot from registry

Problem solved. No furthur assistance required.
If needing to see what was done please ask. Otherwise I will leave it as it is as no posts were put forward.
It was a long haul to get there.
  #3  
Old April 12th, 2005, 01:32 AM
Jooske's Avatar
Jooske Jooske is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Netherlands, EU near the sea
Posts: 9,713
Default Re: TDS-3 failing to delete r.bot, agobot from registry

Hello carbonrose,
Sorry for overlooking your posting and thus not reacting.
Glad you did solve the problem.
Would like a description what you did to solve it.
__________________
Jooske
"o_o"
  #4  
Old June 3rd, 2005, 05:01 AM
tiggy
 
Posts: n/a
Default Re: TDS-3 failing to delete r.bot, agobot from registry

Quote:
Originally Posted by carbonrose
Problem solved. No furthur assistance required.
If needing to see what was done please ask. Otherwise I will leave it as it is as no posts were put forward.
It was a long haul to get there.


Hi Carbonrose,
I have exactly your same problem with this message:
RegVal Trace: DDoS.RAT.rBot: HKEY_LOCAL_MACHINE
File: Software\Microsoft\Windows\CurrentVersion\RunServices [Sygate Personal Firewall=Sygate.exe]

Could you please explain how did you solve it?
Thanks a lot
Tiggy
  #5  
Old June 3rd, 2005, 08:11 AM
FanJ
 
Posts: n/a
Default Re: TDS-3 failing to delete r.bot, agobot from registry

Could it be that the solution is found here:

Run TDS-3 as admin :

RUN AS for TDS-3 - TRACE scan, multiple user problems
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archive of DiamondCS Support Forums > Trojan Defence Suite « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:42 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums