I apparently acquired a virus on my pc. It has loaded itself into modules like etbadm and etbnuc inside the bin folder of Entirex.
Apparently this is widely known (but not by me). Just google etbadm or etbnuc.
Now the question. So far as I know, I have never installed Entirex on this computer. I have several SAG products on the computer; Adabas, Natural, Entire Connection, and NaturalOne. Which one would have installed Entirex?
I use Avast. I have several times received a message from Avast that they blocked an attempt from a module (etbadm and etbnuc) to execute.
Although I do have NaturalOne installed, it has been months since I used it. The messages have all been in the last couple of days.
If I have read some of the posts on the web correctly, viruses can use these modules as a hiding place. This is evidenced, say the articles, by the size of the modules. etbadm, say the articles should be 28kb, on my system it is 51kb. My etbnuc is 3.34 mb, whereas the articles say it should be 1.784kb.
I think I will simply uninstall NaturalOne for a “quick fix”, then investigate further.
I tracked down the license key. It is indeed part of NaturalOne (license key is in \common\conf\ Saglicensekey one82.xml). Is there anything else in the license key which would indicate to you what the size should be (or should i attach the license key itself)
for version 8.2.2.0 the two modules have the sizes as shown in the attachment. Note that this is for a 32-bit installation of EntireX. Please check if you have a 32 or 64 bit installation of EntireX.
Another Question. What might cause an attempt to run etbadm or etbnuc at startup time for my laptop? When I look at my startup list, neither NaturalOne nor EntireX is there.
I don’t know what the CheckPoint software is doing. But I doubt that it starts others services.
The Software AG EntireX Broker Admin service mentioned by Wolfgang is running per default (see attachment). You should stop the service and set the Startup type to Manual or Disabled.
Software AG EntireX Broker Admin must have autostart as its option, and probably when you install NaturalOne, part of entirex gets installed as well. I will have to see if I can get to change it since when I click on etbsrv, as you did to get the screen you posted, that screen “blinks”, but does not make itself available. I will play a bit to see if I can get to change it.