| | |
Please Help! i got rb4.tmp and many other rb.tmp files in my RecycleBin & cant del em
Thread Solved |
•
•
Join Date: Jan 2008
Posts: 38
Reputation:
Solved Threads: 0
Re: Please Help! i got rb4.tmp and many other rb.tmp files in my RecycleBin & cant del em
0
#11 Feb 1st, 2008
•
•
Join Date: May 2005
Posts: 3,204
Reputation:
Solved Threads: 188
Re: Please Help! i got rb4.tmp and many other rb.tmp files in my RecycleBin & cant del em
0
#12 Feb 1st, 2008
That's okay... this will clear all of them... btw, did you check out Telus and those rb.tmp files like I mentioned?
==You SHOULD clear all your system restore points because some have been infected.... AVG may have cleaned them, but we cannot be sure it found everything. So go control panel > system > system restore tab, check Turn off sys res on all drives, Apply and OK. Do it all again but uncheck that box, Apply and OK.
[[a quick way in is Start > run, paste: control sysdm.cpl,,4 -and OK]]
Now make a fresh, clean restore point: Start > programs > accessories > system tools > system restore and create a restore point now!!
[[the quick way to System Restore is Start > run, paste: %systemroot%\system32\restore\rstrui.exe -and OK]]
==You SHOULD clear all your system restore points because some have been infected.... AVG may have cleaned them, but we cannot be sure it found everything. So go control panel > system > system restore tab, check Turn off sys res on all drives, Apply and OK. Do it all again but uncheck that box, Apply and OK.
[[a quick way in is Start > run, paste: control sysdm.cpl,,4 -and OK]]
Now make a fresh, clean restore point: Start > programs > accessories > system tools > system restore and create a restore point now!!
[[the quick way to System Restore is Start > run, paste: %systemroot%\system32\restore\rstrui.exe -and OK]]
Deep, deep in the woods, but walking about.
•
•
Join Date: Jan 2008
Posts: 38
Reputation:
Solved Threads: 0
Re: Please Help! i got rb4.tmp and many other rb.tmp files in my RecycleBin & cant del em
0
#13 Feb 1st, 2008
•
•
Join Date: Jan 2008
Posts: 38
Reputation:
Solved Threads: 0
Re: Please Help! i got rb4.tmp and many other rb.tmp files in my RecycleBin & cant del em
0
#14 Feb 1st, 2008
I restarted my computer and the rb4.tmp files keep on appearing in the recycle bin. I'm having trouble disabling my Telus antivirus program because when i disable it on msconfig startup i end up disabling my internet connection as well but the rb4.tmp files seem to stop coming when i disabled all of that. Should i just reinstall my Telus antivirus program or should i first find a way to disable the antivirus program without disabling my internet connection to see if its the internet connectivity that is causing the problem of the rb4.tmp files appearing in my recycle bin.
•
•
Join Date: May 2005
Posts: 3,204
Reputation:
Solved Threads: 188
Re: Please Help! i got rb4.tmp and many other rb.tmp files in my RecycleBin & cant del em
0
#15 Feb 1st, 2008
In AVG you can click on "remove finally"; then, to ensure that no other points are infected but undiscovered you clear all your restore points and make a fresh one by the method I detailed.
Telus, I think, makes those rb/rb4.tmp files for its own purposes.... I proposed testing that by your disconnecting from the net and then disabling Telus [usually this is possible from a service's control panel - there should be no need to uninstall it. With Telus temporarily disabled you shouuld be able to delete those files in the recycle bin, but Telus will recreate them once restarted. [this is my ... what..? best guess... yeah... test it, they are no harm in the bin].
Telus, I think, makes those rb/rb4.tmp files for its own purposes.... I proposed testing that by your disconnecting from the net and then disabling Telus [usually this is possible from a service's control panel - there should be no need to uninstall it. With Telus temporarily disabled you shouuld be able to delete those files in the recycle bin, but Telus will recreate them once restarted. [this is my ... what..? best guess... yeah... test it, they are no harm in the bin].
Deep, deep in the woods, but walking about.
•
•
Join Date: Jan 2008
Posts: 38
Reputation:
Solved Threads: 0
Re: Please Help! i got rb4.tmp and many other rb.tmp files in my RecycleBin & cant del em
0
#16 Feb 1st, 2008
I screwed up the title, i meant that i "can" delete the rb4.tmp files but they keep on coming back in the recycle bin everytime i restart my computer. What can i do to stop them from coming back to the recycle bin? This is a quote i found on another website about this it seems to inquire that there is still something infected that needs to be moved around to prevent further infection "The temporary files are created by the Anti-Virus in the Sympatico Security Manager. At start-up, the Anti-Virus engine scans the Recycle Bin for Viruses. The Recycle Bin is difficult to clean-up when it contains infected files. The temporary files are used to help move the files around and prevent an infected file from being restored by accident. You will notice that the original location of the temporary file is the Recycle Bin itself and that the file size is zero." thats from the www.misec.net website it might be the response from "their" antivirus program but i have no clue. Does this mean that i still have a virus somewhere that if i remove the virus the rb4.tmp files will stop appearing in the recycle bin?
For the restore point method, yes i deleted all the previous ones as you instructed and i created a new one.
Also will any of these files affect my sound or sound files if i remove them:
C:\System Volume Information\_restore{EBCB510F-B2E2-4905-9575-7F04221D52A4}\RP403\A0131478.exe ***This one is infected with Adware.180Solutions***
HKU\S-1-5-21-436374069-1284227242-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5929CD6E-2062-44A4-B2C5-2C7E78FBAB38} ***This one is infected with Adware.Generic***
For the restore point method, yes i deleted all the previous ones as you instructed and i created a new one.
Also will any of these files affect my sound or sound files if i remove them:
C:\System Volume Information\_restore{EBCB510F-B2E2-4905-9575-7F04221D52A4}\RP403\A0131478.exe ***This one is infected with Adware.180Solutions***
HKU\S-1-5-21-436374069-1284227242-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5929CD6E-2062-44A4-B2C5-2C7E78FBAB38} ***This one is infected with Adware.Generic***
•
•
Join Date: May 2005
Posts: 3,204
Reputation:
Solved Threads: 188
Re: Please Help! i got rb4.tmp and many other rb.tmp files in my RecycleBin & cant del em
0
#17 Feb 2nd, 2008
Ha! For a moment there I missed your point completely.... Sys Vol Inf is the directory which holds the restore points in each volume. A volume is commonly referred to as a drive such as, in this case, C:. You are safe....
Yes, I understood that you could delete those files but that they would be recreated. I know nothing about Sympatico but I can assure that your Virgin Telus will create those rb.tmp files... they are for its own use and are not dangerous. You know, if you DID have malware files in your bin and you then emptied it there would be no more malware in there for Telus to rename, would there? But there are normally no actual files in the recycle bin...This may help you understand: - when you delete a file all that is added into the recycle bin is the pathname of the file; the file itself remains exactly where it was on disk but is renamed using a simple algoritm. The file will remain where it was until you empty the recycle bin, then the space it occupies will be listed as available for overwriting and in the fullness of time may actually be overwritten. Until that time your file still exists and can be retrieved with software. Malware fights like crazy to prevent its files being deleted because of that renaming - it can no longer find elements of itself because it won't know the new names. So no malware files in the bin are being renamed by your Telus, it is creating files for its own use in there.
If you wish to check your sys further for malware, do this:
Clean:
==Download this temp file cleaner from http://www.atribune.org/ccount/click.php?id=1 --click in the download window to run it, and when ATF Cleaner opens go Select all, and then Empty Selected.
Next click Firefox [if you have that browser..] at the top, Select All again, and Empty Selected again. Follow that procedure also if you have Opera.
Close ATF.
Scan:
==Please use IE to do an online scan at panda:- http://www.pandasoftware.com/products/activescan?
-select a link to the scan... free online virus scan...., enter a valid? email and follow through, choosing My Computer for a full system scan.
Post the log it produces here.
Yes, I understood that you could delete those files but that they would be recreated. I know nothing about Sympatico but I can assure that your Virgin Telus will create those rb.tmp files... they are for its own use and are not dangerous. You know, if you DID have malware files in your bin and you then emptied it there would be no more malware in there for Telus to rename, would there? But there are normally no actual files in the recycle bin...This may help you understand: - when you delete a file all that is added into the recycle bin is the pathname of the file; the file itself remains exactly where it was on disk but is renamed using a simple algoritm. The file will remain where it was until you empty the recycle bin, then the space it occupies will be listed as available for overwriting and in the fullness of time may actually be overwritten. Until that time your file still exists and can be retrieved with software. Malware fights like crazy to prevent its files being deleted because of that renaming - it can no longer find elements of itself because it won't know the new names. So no malware files in the bin are being renamed by your Telus, it is creating files for its own use in there.
If you wish to check your sys further for malware, do this:
Clean:
==Download this temp file cleaner from http://www.atribune.org/ccount/click.php?id=1 --click in the download window to run it, and when ATF Cleaner opens go Select all, and then Empty Selected.
Next click Firefox [if you have that browser..] at the top, Select All again, and Empty Selected again. Follow that procedure also if you have Opera.
Close ATF.
Scan:
==Please use IE to do an online scan at panda:- http://www.pandasoftware.com/products/activescan?
-select a link to the scan... free online virus scan...., enter a valid? email and follow through, choosing My Computer for a full system scan.
Post the log it produces here.
Deep, deep in the woods, but walking about.
•
•
Join Date: Jan 2008
Posts: 38
Reputation:
Solved Threads: 0
Re: Please Help! i got rb4.tmp and many other rb.tmp files in my RecycleBin & cant del em
0
#18 Feb 3rd, 2008
Ok, i downloaded the atf cleaner and deleted all the temp files.
I also ran the scan from panda and this is the log:
Incident Status Location
Potentially unwanted tool:application/myway Not disinfected hkey_classes_root\clsid\{014DA6C9-189F-421a-88CD-07CFE51CFF10}
Adware:adware/savenow Not disinfected Windows Registry
Potentially unwanted tool:application/myglobalsearch Not disinfected HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{37B85A21-692B-4205-9CAD-2626E4993404}
Adware:adware/abox Not disinfected Windows Registry
Dialer:dialer.asl Not disinfected HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1426AC5-8CE5-4A00-B71E-011D35709AC6}
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\user\Cookies\user@doubleclick[1].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\user\Cookies\user@tribalfusion[1].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\user\Desktop\SDFix.exe[SDFix\apps\Process.exe]
Adware:Adware/SaveNow Not disinfected C:\Downloads\BSINSTALL.exe
Virus:Bck/MIRCBased.BI Disinfected C:\Program Files\mIRC\mirc.exe
I also ran the scan from panda and this is the log:
Incident Status Location
Potentially unwanted tool:application/myway Not disinfected hkey_classes_root\clsid\{014DA6C9-189F-421a-88CD-07CFE51CFF10}
Adware:adware/savenow Not disinfected Windows Registry
Potentially unwanted tool:application/myglobalsearch Not disinfected HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{37B85A21-692B-4205-9CAD-2626E4993404}
Adware:adware/abox Not disinfected Windows Registry
Dialer:dialer.asl Not disinfected HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1426AC5-8CE5-4A00-B71E-011D35709AC6}
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\user\Cookies\user@doubleclick[1].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\user\Cookies\user@tribalfusion[1].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\user\Desktop\SDFix.exe[SDFix\apps\Process.exe]
Adware:Adware/SaveNow Not disinfected C:\Downloads\BSINSTALL.exe
Virus:Bck/MIRCBased.BI Disinfected C:\Program Files\mIRC\mirc.exe
•
•
Join Date: May 2005
Posts: 3,204
Reputation:
Solved Threads: 188
Re: Please Help! i got rb4.tmp and many other rb.tmp files in my RecycleBin & cant del em
1
#19 Feb 3rd, 2008
It looks like Panda broke your mIRC - you may have to reinstall that.
Is that the BearShare installer in C:\Downloads? C:\Downloads\BSINSTALL.exe - if so, it is okay.
If MyGlobalSearch is listed in Add/Rmv pgms, uninstall it.
=I see that you have MyWay Search Assistant. You can get rid of it... first see if it is listed in Add/Remove pgms list - remove it if able, then..
Go start > run, paste:
MsiExec.exe /X {78d944d7-a97b-4004-ab0a-b5ad06839940} -and Enter. If it is found click yes at the prompt.
Next delete the MyWay files/folder in Program Files [use myway as a search string...].
This next will clean up the bad entries that Panda found in your registry:
==Please copy the text between the lines to a notepad [format/wordwrap unchecked] and save as fixkey.reg, as type "all files", to your desktop; dclick it to run... agree; if it opens in notepad instead rclick the icon [file], choose Open with, Registry editor....
__________________________________________________________
Windows Registry Editor Version 5.00
[-HKU\S-1-5-21-436374069-1284227242-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5929CD6E-2062-44A4-B2C5-2C7E78FBAB38}]
[-HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WhenUSave]
[-HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{37B85A21-692B-4205-9CAD-2626E4993404]
[-HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1426AC5-8CE5-4A00-B71E-011D35709AC6}]
[-HKCR\clsid\{014DA6C9-189F-421a-88CD-07CFE51CFF10}]
__________________________________________________________
Please say how things are after a restart.
Is that the BearShare installer in C:\Downloads? C:\Downloads\BSINSTALL.exe - if so, it is okay.
If MyGlobalSearch is listed in Add/Rmv pgms, uninstall it.
=I see that you have MyWay Search Assistant. You can get rid of it... first see if it is listed in Add/Remove pgms list - remove it if able, then..
Go start > run, paste:
MsiExec.exe /X {78d944d7-a97b-4004-ab0a-b5ad06839940} -and Enter. If it is found click yes at the prompt.
Next delete the MyWay files/folder in Program Files [use myway as a search string...].
This next will clean up the bad entries that Panda found in your registry:
==Please copy the text between the lines to a notepad [format/wordwrap unchecked] and save as fixkey.reg, as type "all files", to your desktop; dclick it to run... agree; if it opens in notepad instead rclick the icon [file], choose Open with, Registry editor....
__________________________________________________________
Windows Registry Editor Version 5.00
[-HKU\S-1-5-21-436374069-1284227242-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5929CD6E-2062-44A4-B2C5-2C7E78FBAB38}]
[-HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WhenUSave]
[-HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{37B85A21-692B-4205-9CAD-2626E4993404]
[-HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1426AC5-8CE5-4A00-B71E-011D35709AC6}]
[-HKCR\clsid\{014DA6C9-189F-421a-88CD-07CFE51CFF10}]
__________________________________________________________
Please say how things are after a restart.
Last edited by gerbil; Feb 3rd, 2008 at 10:49 pm.
Deep, deep in the woods, but walking about.
•
•
Join Date: Jan 2008
Posts: 38
Reputation:
Solved Threads: 0
Re: Please Help! i got rb4.tmp and many other rb.tmp files in my RecycleBin & cant del em
0
#20 Feb 4th, 2008
Alright, so far i searched "myway" under "all files and folder" when i right click 'My Computer' and go to search. It found nothing under myway. I also did not find MyWay Search Assistant in my Add/Remove pgms list nor did i find MyGlobalSearch. If your sure that I have them on my computer then maybe you could find another way for me to find them and get rid of them.
I also pasted exactly: MsiExec.exe /X {78d944d7-a97b-4004-ab0a-b5ad06839940} in my run and i got this message "This action is only valid for products that are currently installed."
I also deleted the BSinstall. It was BearShare that i removed a while ago but forgot to remove the installer.
I also copied the text between the lines as you instructed and ran the fixkey.reg from my desktop. I'm also curious to know what that one does.
Thank you so much so far. You're really helping me out alot.
I also pasted exactly: MsiExec.exe /X {78d944d7-a97b-4004-ab0a-b5ad06839940} in my run and i got this message "This action is only valid for products that are currently installed."
I also deleted the BSinstall. It was BearShare that i removed a while ago but forgot to remove the installer.
I also copied the text between the lines as you instructed and ran the fixkey.reg from my desktop. I'm also curious to know what that one does.
Thank you so much so far. You're really helping me out alot.
![]() |
Other Threads in the Viruses, Spyware and other Nasties Forum
- Previous Thread: Computer really messed up please help
- Next Thread: Win32 Service Error
| Thread Tools | Search this Thread |
adware anti-malware anti-virussitesaccessissue antivirus apple attack audio backtoschoolspeech bar blackhat botnet botnets china commercial commercials conficker connect control crosssitescripting cyber cybercrime cyberwarfare ddos domains e-mafia email europe exam facebook fake fancheckvirus gaming gtaiv gumblar halloween hijack internet iphone kaspersky legal logfiles mail malware mcafee mega-d messagelabs microsoft mobile msn nazi news obama onlinethreats paedophile panel parents phishing police policeprovirusmba-mblockedinternetaccess president privacy pro problem redirect redirecting reliability report research risk rogueantivirus samhain sans scareware school search security seopoisoning sites software spam spyware spywareexternalwindows7adminstratortrojans sqlinjection symantec system teen translate trojan unabletoaccessanti-virussites unwanted update usa virus viruses vista war warning windows worm zeroday






