G
Guest
I seem to have a problem with what I believe to be an "RBOT" infection on my
Windows x64 Professional Edition as mentioned in the article below:
http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=39437
The reason is because in msconfig and hijackthis, I had the following item
starting up: adobereaderpro = directx.exe
This was similar to the startup items listed here:
http://www.sysinfo.org/startuplist.php?filter=adobereaderpro
The only difference is that I can't seem to find any mention of
adobereaderpro and directx.exe on the Internet anywhere. I am assuming
though, it is a variant of the same trojan virus.
In any case, my system was doing fine, until I installed the latest updates
on February 14th. Since then, my Internet slowed to a crawl. My Event
Viewer showed repeated errors of "Event ID 4226" which stated that all my
TCP/IP connections were used up. I tried using the EventID patcher, to edit
tcpip.sys and increase the number of connections from 10 to 100, but even
then the error continued. Only when I increased the number of connections to
1000 did my internet connection return to normal and the EventID 4226 no
longer occur.
So basically, I believe this trojan is using my TCP connections (as
mentioned in the initial link) and I can't seem to get rid of it. I cannot
find any direct.exe file on my hard drive, and even after I delete all the
registry keys involving adobereaderpro, the problem persists. I ran SpyBot
v1.4 and Windows Defender, both turned up nothing. I am running Trend Micro
HouseCall 6.5 and eTrust AntiVirus Web scanners at the moment.
But I was just wondering if anyone has any idea on how to fix this problem.
BTW, I've also noticed that either the Windows Updates or the Trojan has
edited my Windows Firewall settings such that they are controlled by a group
policy (i.e. I can't change the settings because they are greyed out). I
also think it is closing some of my services periodically for no reason (like
Windows Firewall/Internet Connection Sharing).
Any advice would be much appreciated.
Windows x64 Professional Edition as mentioned in the article below:
http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?ID=39437
The reason is because in msconfig and hijackthis, I had the following item
starting up: adobereaderpro = directx.exe
This was similar to the startup items listed here:
http://www.sysinfo.org/startuplist.php?filter=adobereaderpro
The only difference is that I can't seem to find any mention of
adobereaderpro and directx.exe on the Internet anywhere. I am assuming
though, it is a variant of the same trojan virus.
In any case, my system was doing fine, until I installed the latest updates
on February 14th. Since then, my Internet slowed to a crawl. My Event
Viewer showed repeated errors of "Event ID 4226" which stated that all my
TCP/IP connections were used up. I tried using the EventID patcher, to edit
tcpip.sys and increase the number of connections from 10 to 100, but even
then the error continued. Only when I increased the number of connections to
1000 did my internet connection return to normal and the EventID 4226 no
longer occur.
So basically, I believe this trojan is using my TCP connections (as
mentioned in the initial link) and I can't seem to get rid of it. I cannot
find any direct.exe file on my hard drive, and even after I delete all the
registry keys involving adobereaderpro, the problem persists. I ran SpyBot
v1.4 and Windows Defender, both turned up nothing. I am running Trend Micro
HouseCall 6.5 and eTrust AntiVirus Web scanners at the moment.
But I was just wondering if anyone has any idea on how to fix this problem.
BTW, I've also noticed that either the Windows Updates or the Trojan has
edited my Windows Firewall settings such that they are controlled by a group
policy (i.e. I can't change the settings because they are greyed out). I
also think it is closing some of my services periodically for no reason (like
Windows Firewall/Internet Connection Sharing).
Any advice would be much appreciated.