Computing.Net > Forums > Security and Virus > Rameh.E trojan impossible to delete

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Rameh.E trojan impossible to delete

Reply to Message Icon

Name: d.bowman
Date: November 19, 2004 at 00:19:38 Pacific
OS: windows xp
CPU/Ram: IntelPentium/512mb
Comment:

OBJECT:
C:\ Documents and Settings\myname\Local Settings\Temp\AAWTMP\C23416981\23D8217\ATPartners.dll
RESULT:
Trojan Horse Downloader.Rameh.E
STATUS:
Infected, embedded object

I run on Windows XP for OS.
I have scanned with: killme, Ad-adware SE, ccleaner, cwshredder, hsremove, pvlx2cleaner, Spybot search and destroy, stinger. spywaredoctor, AVG Free, about:Buster, spyware blaster and a few other ones i picked up.
A few have detected spyware, of which i took care of but only the AVG has detected the Rameh.E trojan and when i try to delete it or move it to a vault, i can't. i've also tryed to go to the location and remove it manually but cannot find it....it's embedded.
Any help REMOVING the sucker would be appreciated...our household is quite lost about what approach to take next.

also, before scanning, i disabled system restore temporarily and enabled viewing of hidden files, folders, and extentions as well as scanning in normal mode and safe mode.

thank you for any advice
d. bowman



Sponsored Link
Ads by Google

Response Number 1
Name: IronMan
Date: November 19, 2004 at 00:43:54 Pacific
Reply:


You might try these two online scanning services: TrojanScan and Anti-Trojan.org.

Keep System Restore turned off while the scans are run.


0

Response Number 2
Name: johnr
Date: November 19, 2004 at 01:16:42 Pacific
Reply:

As it's in your TEMP folder there won't be any problem deleting it - legitimate embedded files don't install themselves there. Start by trying to delete it in Safe Mode. Next, get a freeware program called 'MoveonBoot' - available from a lot of sites, but here's just one:

http://www.snapfiles.com/get/moveonboot.html

It lets you select the file which, as the name implies, is removed on boot-up so it hasn't got a chance to start. As always, of course, make sure you have your important data backed up - and disable system restore so the *** doesn't hang around.

"I know that I'm mad - I've always been mad..."


0

Response Number 3
Name: Mechanix2Go
Date: November 19, 2004 at 05:04:38 Pacific
Reply:

I guess your first paragraph is the report from one of your many scans.

If so, it seems odd that the scan found it and you say it's not there.

Try this:

attrib /s c:\ATPartners.dll

M2


0

Response Number 4
Name: blender
Date: November 20, 2004 at 07:57:36 Pacific
Reply:

d.bowman

"OBJECT:
C:\ Documents and Settings\myname\Local Settings\Temp\AAWTMP\C23416981\23D8217\ATPartners.dll"

That folder is created temporarily while running ad-aware.
If you have your antivirus enabled during the ad-aware scan....it will pick it up.

Once ad-aware scan is finished it deletes its temp folder.
Ad-aware temporarily creates a temp folder to uncompress zipped files to scan them if you have that option enabled.

Thats why you cannot find the trojan or the aawtmp folder. It no longer exists.

Ad-aware did remove the objects it found? Yes?

If subsequent ad-aware scans continue to pull up favoriteman....

Here's manual removal instructions near bottom of page for ATPartners Favoriteman varient:

http://www.doxdesk.com/parasite/FavoriteMan.html

Be sure to back up registry before attempting the suggessted removal.

How?:

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/199762382617?OpenDocument&src=sec_doc_nam

I never give up!

Windows Update


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Rameh.E trojan impossible to delete

Need to get rid of Rameh.E Trojan www.computing.net/answers/security/need-to-get-rid-of-ramehe-trojan/13724.html

Trojan downloader .Rameh.E www.computing.net/answers/security/trojan-downloader-ramehe/12341.html

Virus (attachment) impossible to delete www.computing.net/answers/security/virus-attachment-impossible-to-delete/987.html