There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
General Security
Tag Cloud
access acer asus bios bsod computer crash driver drivers error ethernet excel freeze gaming google gpu graphics hard drive hardware hdmi internet laptop malware memory monitor motherboard mouse network printer problem ram registry router server slow software sound svchost.exe trojan usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
ati2dva.dll

Reply  
Thread Tools
belch175's Avatar
Junior Member with 18 posts.
 
Join Date: Dec 2008
12-Dec-2008, 04:43 PM #1
ati2dva.dll
Hello,

I am having trouble with malware. My Symantec antivirus first found what it is calling a trojan, the file it identifies is ati2dva.dll. I have located the file, it says it is published by 120% alcohol. I have tried to quarantine it, clean it, delete it to no avail. I have even tried to delete it's registry keys, change it's binary, delete the file from dos prompt, everything I can think of. I am either told it the disk is full, write protected, or in use; or the file cannot be deleted. I read a thread that was posted on your site some time ago and tried to follow the instructions there with no success. Ran ComboFix, Hijack This, Malwarebytes, Ad-aware, etc. The good news is I no longer get pop-up messages saying I need to purchase some anti-malware program, the bad news is Symantec constantly and continously identifies it as a threat, my computer runs slow as a result of it continously identifying it and warning me. Computer runs fine with virus scan turned off or in safe mode but I cannot leave it like this. Do you have any suggestions to get me into this file or clean it.

FYI the registery key is:
{63608544-DEE0-49CA-BE63-C03E148FABBF}

and the file name is:
C:\WINDOWS\system32\ati2dva.dll

this was a subfile under the same registry key:
Inproc Server 32
Kenny94's Avatar
Account Disabled with 2,481 posts.
 
Join Date: Dec 2004
Location: S.C
12-Dec-2008, 06:59 PM #2
Hi belch175 and Welcome to TSG

It's Vundo variant go here at:

http://forums.techguy.org/malware-re...st-before.html
belch175's Avatar
Junior Member with 18 posts.
 
Join Date: Dec 2008
12-Dec-2008, 08:30 PM #3
Thanks for the post Kenny, I followed the link in your text it took me to a post about Hijackthis. I've tried Hijackthis. Here is the line from the Hijackthis log that is causing all of the trouble:

O2 - BHO: (no name) - {63608544-DEE0-49CA-BE63-C03E148FABBF} - C:\WINDOWS\system32\ati2dva.dll

I click on the "fix checked" it says hijackthis is about to remove the BHO and all coresponding files from my system, but then nothing happens. The list goes blank, as soon as I run another scan there it is again.

I'm stumped.

According to permissions I have full access to it but as soon as I try to delete it, I get a message that "changes could not be saved to key".

I've even tried it in safe mode with explorer.exe killed from both regedit and CMD.
Kenny94's Avatar
Account Disabled with 2,481 posts.
 
Join Date: Dec 2004
Location: S.C
12-Dec-2008, 08:53 PM #4
Post a full HijackThis log in the "Malware Removal & HijackThis Logs" Thread.. And one of us will help on this. You really should not be using ComboFix without supervision.. Because ComboFix is a very strong tool!

Thanks Kenny
belch175's Avatar
Junior Member with 18 posts.
 
Join Date: Dec 2008
12-Dec-2008, 08:59 PM #5
Alright will do thanks Kenny
Reply

Tags
ati2dva.dll

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 05:09 AM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.