Mourning the loss of our friend, WhitPhil.
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
 
General Security
Tag Cloud
access audio black screen blue screen boot bsod connection crash dell desktop drivers dvd email error excel excel 2003 firefox hard drive hardware hdmi hijackthis internet keyboard laptop malware monitor motherboard network networking outlook problem recovery router safe mode screen slow sound spyware tdlwsp.dll trojan vba video virus vista vundo windows windows 7 windows vista windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
ati2dva.dll

Tip: Click here to scan for System Errors and Optimize PC performance
[ Sponsored Link ]

Closed Thread
 
Thread Tools
belch175's Avatar
Junior Member with 18 posts.
 
Join Date: Dec 2008
12-Dec-2008, 03:43 PM #1
ati2dva.dll
Hello,

I am having trouble with malware. My Symantec antivirus first found what it is calling a trojan, the file it identifies is ati2dva.dll. I have located the file, it says it is published by 120% alcohol. I have tried to quarantine it, clean it, delete it to no avail. I have even tried to delete it's registry keys, change it's binary, delete the file from dos prompt, everything I can think of. I am either told it the disk is full, write protected, or in use; or the file cannot be deleted. I read a thread that was posted on your site some time ago and tried to follow the instructions there with no success. Ran ComboFix, Hijack This, Malwarebytes, Ad-aware, etc. The good news is I no longer get pop-up messages saying I need to purchase some anti-malware program, the bad news is Symantec constantly and continously identifies it as a threat, my computer runs slow as a result of it continously identifying it and warning me. Computer runs fine with virus scan turned off or in safe mode but I cannot leave it like this. Do you have any suggestions to get me into this file or clean it.

FYI the registery key is:
{63608544-DEE0-49CA-BE63-C03E148FABBF}

and the file name is:
C:\WINDOWS\system32\ati2dva.dll

this was a subfile under the same registry key:
Inproc Server 32
Kenny94's Avatar
Distinguished Member with 2,158 posts.
 
Join Date: Dec 2004
Location: S.C
Experience: Malware Fighter
12-Dec-2008, 05:59 PM #2
Hi belch175 and Welcome to TSG

It's Vundo variant go here at:

http://forums.techguy.org/malware-re...st-before.html
belch175's Avatar
Junior Member with 18 posts.
 
Join Date: Dec 2008
12-Dec-2008, 07:30 PM #3
Thanks for the post Kenny, I followed the link in your text it took me to a post about Hijackthis. I've tried Hijackthis. Here is the line from the Hijackthis log that is causing all of the trouble:

O2 - BHO: (no name) - {63608544-DEE0-49CA-BE63-C03E148FABBF} - C:\WINDOWS\system32\ati2dva.dll

I click on the "fix checked" it says hijackthis is about to remove the BHO and all coresponding files from my system, but then nothing happens. The list goes blank, as soon as I run another scan there it is again.

I'm stumped.

According to permissions I have full access to it but as soon as I try to delete it, I get a message that "changes could not be saved to key".

I've even tried it in safe mode with explorer.exe killed from both regedit and CMD.
Kenny94's Avatar
Distinguished Member with 2,158 posts.
 
Join Date: Dec 2004
Location: S.C
Experience: Malware Fighter
12-Dec-2008, 07:53 PM #4
Post a full HijackThis log in the "Malware Removal & HijackThis Logs" Thread.. And one of us will help on this. You really should not be using ComboFix without supervision.. Because ComboFix is a very strong tool!

Thanks Kenny
belch175's Avatar
Junior Member with 18 posts.
 
Join Date: Dec 2008
12-Dec-2008, 07:59 PM #5
Alright will do thanks Kenny
Closed Thread Bookmark and Share

Tags
ati2dva.dll

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Smart Search

Find your solution!



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.

Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -5. The time now is 01:52 AM.
Copyright © 1996 - 2009 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2009, Jelsoft Enterprises Ltd.
Powered by Cermak Technologies, Inc.