Re: what is rmkbpaba.dll




"m.a" <ma.@xxxxxxxxxxx> wrote in message
news:ScTyj.229921$3m6.49573@xxxxxxxxxxxxxxxxxxxxxxxxxxxx

"Malke" <malke@xxxxxxxxxxxxxxx> wrote in message
news:OoKKhHTfIHA.1212@xxxxxxxxxxxxxxxxxxxxxxx
m.a wrote:

Hello,

My windows XP professional, had an adware and I removed it. But now I
am
getting an error at boot up that rmkbpaba.dll can not be found by
rundll.exe.

What is this file and how can I remove this error?

A quick Google for rmkbpaba.dll only brings up links to your post so this
is
a strong indication the file was part of malware. Since you didn't say
how
or with what you removed the malware, I can't tell whether your computer
is
truly clean. Please review the removal methods at this link to see if you
were that thorough:

http://www.elephantboycomputers.com/page2.html#Removing_Malware

If you were not, then you should run through at least some of the steps,
not
skipping the prep work. If you were that thorough, manage your Startup
matrix with the System Configuration Utility and/or the free Autoruns.

http://www.microsoft.com/technet/sysinternals/default.mspx - Autoruns

System Configuration Utility - Start>Run>msconfig [enter]

This brings up the System Configuration Utility. Look on the Startup tab
and
find the probable culprit. Uncheck the box next to its name, Apply and OK
out. You don't need to restart immediately, but the next time you do
you'll
get a dialog saying you've used the Utility. Just tick the box that says
in
effect, "don't bother me about this again".

Important - Do not use the System Configuration Utility to stop
processes.
Instead, use Start>Run>services.msc [enter] and do not stop any services
unless you really, really know what you're doing.

Malke
--
MS-MVP
Elephant Boy Computers
www.elephantboycomputers.com
Don't Panic!

Thanks,

I found the following dlls in my system and I removed them:

rmkbpaba.dll

hggffgd.dll

jcsysgen.dll

jkklm.dll



before removing them, I had popup in my IE even when it was not running.
Now I have not that side effects.



After removing these files, I did a windows XP repair install.



I am going to try to do your advice and find if there is any other malware
on my system.



Regards



ps: I removed theser files manually as no malware detection found them.



Hello,
I found that it relates to an entry in my windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
with the name of 20f3f088 with its value set to:
rundll32.exe "C:\WINDOWS\system32\rmkbpaba.dll",b


Regards


.



Relevant Pages

  • Re: what is rmkbpaba.dll
    ... a strong indication the file was part of malware. ... This brings up the System Configuration Utility. ... After removing these files, I did a windows XP repair install. ...
    (microsoft.public.windowsxp.general)
  • Re: MULTIPLE SCREENS APPEARANCE
    ... Also there are a couple of newsgroups that are geared toward malware issues. ... Looking in task manager will tell you if IE is running, even when no windows ... there is no benefit to running a registry cleaner. ... be gained by removing unused entries from the registry, ...
    (microsoft.public.windowsxp.general)
  • Re: windows xp help
    ... Your antivirus/antispyware programs could have removed the malware and left a reference to it in Startup OR if you didn't do any malware removal you need to. ... Important - Do not use the System Configuration Utility to stop processes. ... How to Troubleshoot By Using the Msconfig Utility in Windows XP - ...
    (microsoft.public.windowsxp.general)
  • Re: internet
    ... You find out what it is by 1) scanning for viruses and malware; 2) using the System Configuration Utility to see what is starting with Windows. ... If you connect with broadband, ...
    (microsoft.public.windowsxp.general)
  • Re: Do I have TOO MANY antivirus, antispyware, etc
    ... >computer is retarted again and I ran the Windows Live Safety Center Scan, ... Once malware infects the system, it generally runs as soon as the ... Connecting to the Internet without a firewall ... that you know what "opening" a file can do in terms of risk. ...
    (microsoft.public.windowsxp.security_admin)