Computing.Net > Forums > Security and Virus > Rameh.E trojan impossible to delete

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Rameh.E trojan impossible to delete

Reply to Message Icon

Original Message
Name: d.bowman
Date: November 19, 2004 at 00:19:38 Pacific
Subject: Rameh.E trojan impossible to delete
OS: windows xp
CPU/Ram: IntelPentium/512mb
Comment:

OBJECT:
C:\ Documents and Settings\myname\Local Settings\Temp\AAWTMP\C23416981\23D8217\ATPartners.dll
RESULT:
Trojan Horse Downloader.Rameh.E
STATUS:
Infected, embedded object

I run on Windows XP for OS.
I have scanned with: killme, Ad-adware SE, ccleaner, cwshredder, hsremove, pvlx2cleaner, Spybot search and destroy, stinger. spywaredoctor, AVG Free, about:Buster, spyware blaster and a few other ones i picked up.
A few have detected spyware, of which i took care of but only the AVG has detected the Rameh.E trojan and when i try to delete it or move it to a vault, i can't. i've also tryed to go to the location and remove it manually but cannot find it....it's embedded.
Any help REMOVING the sucker would be appreciated...our household is quite lost about what approach to take next.

also, before scanning, i disabled system restore temporarily and enabled viewing of hidden files, folders, and extentions as well as scanning in normal mode and safe mode.

thank you for any advice
d. bowman


Report Offensive Message For Removal


Response Number 1
Name: IronMan
Date: November 19, 2004 at 00:43:54 Pacific
Reply:


You might try these two online scanning services: TrojanScan and Anti-Trojan.org.

Keep System Restore turned off while the scans are run.


Report Offensive Follow Up For Removal

Response Number 2
Name: johnr
Date: November 19, 2004 at 01:16:42 Pacific
Reply:

As it's in your TEMP folder there won't be any problem deleting it - legitimate embedded files don't install themselves there. Start by trying to delete it in Safe Mode. Next, get a freeware program called 'MoveonBoot' - available from a lot of sites, but here's just one:

http://www.snapfiles.com/get/moveonboot.html

It lets you select the file which, as the name implies, is removed on boot-up so it hasn't got a chance to start. As always, of course, make sure you have your important data backed up - and disable system restore so the *** doesn't hang around.

"I know that I'm mad - I've always been mad..."


Report Offensive Follow Up For Removal

Response Number 3
Name: Mechanix2Go
Date: November 19, 2004 at 05:04:38 Pacific
Reply:

I guess your first paragraph is the report from one of your many scans.

If so, it seems odd that the scan found it and you say it's not there.

Try this:

attrib /s c:\ATPartners.dll

M2


Report Offensive Follow Up For Removal

Response Number 4
Name: blender
Date: November 20, 2004 at 07:57:36 Pacific
Reply:

d.bowman

"OBJECT:
C:\ Documents and Settings\myname\Local Settings\Temp\AAWTMP\C23416981\23D8217\ATPartners.dll"

That folder is created temporarily while running ad-aware.
If you have your antivirus enabled during the ad-aware scan....it will pick it up.

Once ad-aware scan is finished it deletes its temp folder.
Ad-aware temporarily creates a temp folder to uncompress zipped files to scan them if you have that option enabled.

Thats why you cannot find the trojan or the aawtmp folder. It no longer exists.

Ad-aware did remove the objects it found? Yes?

If subsequent ad-aware scans continue to pull up favoriteman....

Here's manual removal instructions near bottom of page for ATPartners Favoriteman varient:

http://www.doxdesk.com/parasite/FavoriteMan.html

Be sure to back up registry before attempting the suggessted removal.

How?:

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/199762382617?OpenDocument&src=sec_doc_nam

I never give up!

Windows Update


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home



Results for: Rameh.E trojan impossible to delete

Need to get rid of Rameh.E Trojan
    Summary: AVG popped up a message saying it had found Downloader.Rameh.E but did not detect it when I ran a scan. Ad-Aware, Spybot and Housecall (trendmicro site)all failed to detect it. All scans were run wi...
www.computing.net/answers/security/need-to-get-rid-of-ramehe-trojan/13724.html

Trojan downloader .Rameh.E
    Summary: Hi I as well have the dreaded Rameh. E Trojan Downloader. I am running Win 2000 pro and for some reason I can not find where you sent the system restore off. I am running AVG, Ad-Aware and Sygate an...
www.computing.net/answers/security/trojan-downloader-ramehe/12341.html

Virus (attachment) impossible to delete
    Summary: Thank you. I did try the housecall. But I had the feeling it got killed, just like with Virusscan from McAfee. (or it was because of my problem with my fauly modem driver through which my PC sometimes...
www.computing.net/answers/security/virus-attachment-impossible-to-delete/987.html








Which MP3 player do you have?

iPod/iPhone
Zune
Something Else
None


View Results

Poll Finishes Today.
Discuss in The Lounge
Poll History






Data Recovery Software