RBOT-ATT Removal: Remove RBOT-ATT Forever

Let our support team solve your problem with RBOT-ATT and repair RBOT-ATT right now!

Leave the detailed description of your RBOT-ATT problem in the form below. Our support team will contact you in several minutes and give a step-by-step instruction on how to fix RBOT-ATT problem. Please be specific. Do your best describing the problem. This will help us recommend right and complete RBOT-ATT problem removal solution.

Describe your problem here and we'll contact you in several minutes:

We'll reply you in 10 minutes or less
* Name:
* E-mail:
* Problem summary:
* Detailed problem
description:

We'll contact you in 10 minutes or less after you click on this button! Individual solution guaranteed!

Warning:

1) We hate spam as much as you do. We will not share your email with any third party or publish it anywhere. Your email is used only to contact you and give you RBOT-ATT removal solution.
2) All fields of this form are obligatory.

Guaranteed Problem Solution
Software Industry Professionals Member
Threat's description and solution are developed by Security Stronghold security team. Let professionals make your problems solved now!
Download solution for RBOT-ATT and init.exe
 now!

What is RBOT-ATT? Technical details of RBOT-ATT problem and RBOT-ATT removal tool

Methods for manual RBOT-ATT removal

Free download of a program that will solve your problem automatically

Free instant professional support in solving RBOT-ATT error from our Security Support Team

Threat's profile

Threat indicator: HIGH
Name of the threat: RBOT-ATT
Command or file name: init.exe
Threat type: Worm
Affected OS: Win32 (Windows 9x, Windows XP, Windows Vista)

RBOT-ATT intrusion method

RBOT-ATT copies its file(s) to your hard disk. Its typical file name is init.exe . Then it creates new startup key with name RBOT-ATT and value init.exe . You can also find it in your processes list with name init.exe or RBOT-ATT.

If you have further questions about RBOT-ATT, please fill in the form above and we'll contact you shortly.

» Download program to remove RBOT-ATT (RBOT-ATT Removal Tool)

Recommended Solution

If you are not sure what to delete, use our award winning program - RBOT-ATT Removal Tool.

RBOT-ATT Removal Tool will find and fully remove RBOT-ATT and all problems associated with RBOT-ATT virus.

Fast, easy, and handy, RBOT-ATT Removal Tool protects your computer against RBOT-ATT that does harm to your computer and breaks your privacy. RBOT-ATT Removal Tool scans your hard disks and registry and destroys any manifestation of RBOT-ATT. Standard anti-virus software can do nothing against malicious programs like RBOT-ATT. Remove RBOT-ATT straight away!

» Download RBOT-ATT Removal Tool now for free

How to fix RBOT-ATT

This problem can be solved manually by deleting all registry keys and files connected with RBOT-ATT, removing it from starup list and unregistering all corresponding DLLs. Additionally missing DLL's should be restored from distribution in case they are corrupted by RBOT-ATT.

To get rid of RBOT-ATT, you should:

1. Kill the following processes and delete the appropriate files:

no information

Warning: you should delete only those files which checksums are listed as malicious. There may be valid files with the same names in your system. We recommend you to use RBOT-ATT Removal Tool for safe problem solution.

2. Delete the following malicious folders:

no information

3. Delete the following malicious registry entries and\or values:

no information

Warning: If value is listed for some registry entries, you should only clear these values and leave keys with such values untouched. We recommend you to use RBOT-ATT Removal Tool for safe problem solution.

Here are the descriptions of problems connected with RBOT-ATT and init.exe we received earlier:



booting problem

Problem Summary: booting problem
when i boot my computer it prompts me to to enter my username and password, standard with all computers, after that it hangs and fails to continue and retains my desktop screen without icons and taskbar and i can\'t use it.

Our support has contacted the author of this message, E Fried, and helped to solve his problem.


pc windons server reiniciando no mesmo horario todo dia

Problem Summary: pc windons server reiniciando no mesmo horario todo dia
tenho uma maquina com S/O windowns server 2003 e de uns dias para ca ele esta reiniciando o mesmo horario todo dia

Our support has contacted the author of this message, rodrigo lopes, and helped to solve his problem.


booting problem

Problem Summary: booting problem
when i boot my computer it prompts me to to enter my username and password, standard with all computers, after that it hangs and fails to continue and retains my desktop screen without icons and taskbar and i can\'t use it. pliz help

Our support has contacted the author of this message, Ntethelelo, and helped to solve his problem.


\

Problem Summary: \
I am attaching my hijack log list to show you.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:06:51 AM, on 4/30/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\\WINDOWS\\System32\\smss.exe
C:\\WINDOWS\\system32\\winlogon.exe
C:\\WINDOWS\\system32\\services.exe
C:\\WINDOWS\\system32\\lsass.exe
C:\\WINDOWS\\system32\\Ati2evxx.exe
C:\\WINDOWS\\system32\\svchost.exe
C:\\Program Files\\Windows Defender\\MsMpEng.exe
C:\\WINDOWS\\System32\\svchost.exe
C:\\WINDOWS\\Explorer.EXE
C:\\WINDOWS\\system32\\spoolsv.exe
C:\\Program Files\\a-squared Free\\a2service.exe
C:\\PROGRA~1\\AVG\\AVG8\\avgwdsvc.exe
C:\\WINDOWS\\system32\\CTsvcCDA.EXE
C:\\WINDOWS\\eHome\\ehRecvr.exe
C:\\WINDOWS\\eHome\\ehSched.exe
C:\\Program Files\\Common Files\\Microsoft Shared\\VS7DEBUG\\MDM.EXE
C:\\Program Files\\Microsoft SQL Server\\MSSQL$INVENTORCONTENT\\Binn\\sqlservr.exe
C:\\Program Files\\Photodex\\ProShowGold\\ScsiAccess.exe
C:\\WINDOWS\\System32\\PAStiSvc.exe
C:\\WINDOWS\\system32\\svchost.exe
C:\\WINDOWS\\system32\\MsPMSPSv.exe
C:\\PROGRA~1\\AVG\\AVG8\\avgemc.exe
C:\\PROGRA~1\\AVG\\AVG8\\avgrsx.exe
C:\\Program Files\\AVG\\AVG8\\avgcsrvx.exe
C:\\WINDOWS\\system32\\dllhost.exe
C:\\WINDOWS\\system32\\Rundll32.exe
C:\\Program Files\\Creative\\Sound Blaster Live! 24-bit\\Surround Mixer\\CTSysVol.exe
C:\\WINDOWS\\system32\\dla\\tfswctrl.exe
C:\\Program Files\\QuickTime\\qttask.exe
C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe
C:\\PROGRA~1\\AVG\\AVG8\\avgtray.exe
C:\\Program Files\\Windows Defender\\MSASCui.exe
C:\\WINDOWS\\system32\\rundll32.exe
C:\\Program Files\\Winamp\\winampa.exe
C:\\Program Files\\Messenger\\msmsgs.exe
C:\\PROGRA~1\\PANICW~1\\POP-UP~1\\PSFree.exe
C:\\WINDOWS\\system32\\ctfmon.exe
C:\\Program Files\\Microsoft SQL Server\\80\\Tools\\Binn\\sqlmangr.exe
C:\\PROGRA~1\\AVG\\AVG8\\avgnsx.exe
\\?\\globalroot\\C:\\WINDOWS\\system32\\rundll32.exe
C:\\Program Files\\Mozilla Firefox\\firefox.exe
C:\\Program Files\\Trend Micro\\HijackThis\\HijackThis.exe

R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=20008&gct=&gc=1&q=
R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=20008&gct=&gc=1&q=
R1 - HKCU\\Software\\Microsoft\\Internet Explorer\\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirect?o=20008&gct=&gc=1&q=%s
R1 - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings,ProxyServer = 172.17.1.3:80
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\\Program Files\\AskSearch\\bin\\DefaultSearch.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\\Program Files\\AVG\\AVG8\\avgssie.dll
O2 - BHO: (no name) - {B2BA40A2-74F0-42BD-F434-12345A2C8953} - (no file)
O4 - HKLM\\..\\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\\..\\Run: [UpdReg] C:\\WINDOWS\\UpdReg.EXE
O4 - HKLM\\..\\Run: [CTSysVol] C:\\Program Files\\Creative\\Sound Blaster Live! 24-bit\\Surround Mixer\\CTSysVol.exe /r
O4 - HKLM\\..\\Run: [dla] C:\\WINDOWS\\system32\\dla\\tfswctrl.exe
O4 - HKLM\\..\\Run: [QuickTime Task] \"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime
O4 - HKLM\\..\\Run: [SunJavaUpdateSched] \"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\"
O4 - HKLM\\..\\Run: [PinnacleDriverCheck] C:\\WINDOWS\\system32\\PSDrvCheck.exe -CheckReg
O4 - HKLM\\..\\Run: [AVG8_TRAY] C:\\PROGRA~1\\AVG\\AVG8\\avgtray.exe
O4 - HKLM\\..\\Run: [Windows Defender] \"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide
O4 - HKLM\\..\\Run: [autochk] rundll32.exe C:\\WINDOWS\\system32\\autochk.dll,_IWMPEvents@16
O4 - HKLM\\..\\Run: [WinampAgent] \"C:\\Program Files\\Winamp\\winampa.exe\"
O4 - HKCU\\..\\Run: [MSMSGS] \"C:\\Program Files\\Messenger\\msmsgs.exe\" /background
O4 - HKCU\\..\\Run: [PopUpStopperFreeEdition] \"C:\\PROGRA~1\\PANICW~1\\POP-UP~1\\PSFree.exe\"
O4 - HKCU\\..\\Run: [ctfmon.exe] C:\\WINDOWS\\system32\\ctfmon.exe
O4 - HKCU\\..\\Run: [Diagnostic Manager] C:\\DOCUME~1\\THEABE~1\\LOCALS~1\\Temp\\3117293484.exe
O4 - HKCU\\..\\Run: [norunautochk] rundll32.exe C:\\DOCUME~1\\THEABE~1\\protect.dll,_IWMPEvents@16
O4 - HKCU\\..\\Run: [autochk] rundll32.exe C:\\DOCUME~1\\NETWOR~1\\protect.dll,_IWMPEvents@16
O4 - HKUS\\S-1-5-18\\..\\Run: [] C:\\WINDOWS\\TEMP\\f4m0q0wrnz.exe (User \'SYSTEM\')
O4 - HKUS\\S-1-5-18\\..\\Run: [Windows Resurections] C:\\WINDOWS\\TEMP\\f4m0q0wrnz.exe (User \'SYSTEM\')
O4 - HKUS\\S-1-5-18\\..\\Run: [Diagnostic Manager] C:\\WINDOWS\\TEMP\\3836232438.exe (User \'SYSTEM\')
O4 - HKUS\\S-1-5-18\\..\\Run: [autochk] rundll32.exe C:\\DOCUME~1\\LOCALS~1\\protect.dll,_IWMPEvents@16 (User \'SYSTEM\')
O4 - HKUS\\S-1-5-18\\..\\Run: [A00FE3CB6.exe] C:\\WINDOWS\\TEMP\\_A00FE3CB6.exe (User \'SYSTEM\')
O4 - HKUS\\.DEFAULT\\..\\Run: [] C:\\WINDOWS\\TEMP\\f4m0q0wrnz.exe (User \'Default user\')
O4 - S-1-5-18 Startup: ChkDisk.dll (User \'SYSTEM\')
O4 - .DEFAULT Startup: ChkDisk.dll (User \'Default user\')
O4 - Startup: ChkDisk.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\AdobeCollabSync.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\\Program Files\\Common Files\\Autodesk Shared\\acstart16.exe
O4 - Global Startup: Service Manager.lnk = C:\\Program Files\\Microsoft SQL Server\\80\\Tools\\Binn\\sqlmangr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\\PROGRA~1\\MICROS~2\\OFFICE11\\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files\\Java\\jre1.5.0_11\\bin\\ssv.dll
O9 - Extra \'Tools\' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\\Program Files\\Java\\jre1.5.0_11\\bin\\ssv.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\\Program Files\\Paltalk Messenger\\Paltalk.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\\PROGRA~1\\MICROS~2\\OFFICE11\\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\\Program Files\\Messenger\\msmsgs.exe
O9 - Extra \'Tools\' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\\Program Files\\Messenger\\msmsgs.exe
O10 - Broken Internet access because of LSP provider \'c:\\windows\\temp\\ntdll64.dll\' missing
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1172285023921
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1215481976031
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - http://www.photodex.com/pxplay.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\\Program Files\\AVG\\AVG8\\avgpp.dll
O18 - Filter hijack: text/html - {5e2d9754-ba4d-442c-b345-4769c0d17bf9} - (no file)
O20 - Winlogon Notify: !SASWinLogon - C:\\Program Files\\SUPERAntiSpyware\\SASWINLO.DLL
O20 - Winlogon Notify: avgrsstarter - C:\\WINDOWS\\SYSTEM32\\avgrsstx.dll
O20 - Winlogon Notify: __c00E8310 - C:\\WINDOWS\\system32\\__c00E8310.dat
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\\Program Files\\a-squared Free\\a2service.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\\WINDOWS\\system32\\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\\WINDOWS\\system32\\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\\Program Files\\Common Files\\Autodesk Shared\\Service\\AdskScSrv.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\\PROGRA~1\\AVG\\AVG8\\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\\PROGRA~1\\AVG\\AVG8\\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\\WINDOWS\\system32\\CTsvcCDA.EXE
O23 - Service: ScsiAccess - Unknown owner - C:\\Program Files\\Photodex\\ProShowGold\\ScsiAccess.exe
O23 - Service: STI Simulator - Unknown owner - C:\\WINDOWS\\System32\\PAStiSvc.exe

--
End of file - 8648 bytes

Our support has contacted the author of this message, Greg Abel, and helped to solve his problem.


init.exe problem

Problem Summary: init.exe problem
I have windows xp and it has come up with a init.exe problem

Our support has contacted the author of this message, Alan Ritchie, and helped to solve his problem.

Next threat: RBOT-ATU »

Learn more about RBOT-ATT and init.exe »

« Back to catalog

Solution: 11134
Home | Partners | Shop | Support | Contact Us | Privacy Policy | Sitemap

Copyright © 2003-2009 Security Stronghold. All Rights Reserved.