1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Trojan

Discussion in 'Security and Privacy' started by Kimberlee, 2004/06/17.

Thread Status:
Not open for further replies.
  1. 2004/06/17
    Kimberlee

    Kimberlee Inactive Thread Starter

    Joined:
    2004/04/25
    Messages:
    66
    Likes Received:
    0
    I just did a online virus scan with Panda. As the scan is going along - I see:

    Trojan horse Downloader.Rameh.E
    C:\Windows\System\Atpartner.dll

    and then:

    Trojan Horse Downloader.Rameh.E
    C:\Windows\System\Atpart~1.dll

    Now what?

    Thanks
     
  2. 2004/06/17
    Daizy

    Daizy Inactive

    Joined:
    2002/02/19
    Messages:
    2,965
    Likes Received:
    0

  3. to hide this advert.

  4. 2004/06/17
    Kimberlee

    Kimberlee Inactive Thread Starter

    Joined:
    2004/04/25
    Messages:
    66
    Likes Received:
    0
    Thanks Daizy....When I look for those files in Windows\System I can't find them :eek:

    I did a search for them and nothing came up. Am I doing something wrong?

    Thanks
     
  5. 2004/06/17
    Daizy

    Daizy Inactive

    Joined:
    2002/02/19
    Messages:
    2,965
    Likes Received:
    0
    Make double sure, by checking to make sure you've got your computer set to show hidden files and folders. Do your search.....
    Then do another scan at Housecall .
     
  6. 2004/06/17
    dobhar Lifetime Subscription

    dobhar Inactive

    Joined:
    2002/05/24
    Messages:
    924
    Likes Received:
    3
    Hi Kimberlee

    Make sure you have "Show hidden files and folders" checked off in "Folder Options ".

    1) Open "My Computer "
    2) Click on "Tools" in the menu
    3) Select "Folder Options "
    4) Select "View" tab
    5) Make sure "Show hidden files and folders" is selected

    If still can't see the files then deselect "Display the contents of system folders" in the same window above.

    Sorry Daizy didn't mean to step on you :eek: :D
     
    Last edited: 2004/06/17
  7. 2004/06/17
    Daizy

    Daizy Inactive

    Joined:
    2002/02/19
    Messages:
    2,965
    Likes Received:
    0
    :D Thank you dobhar
    You most certainly did NOT step on me. I should have included those instructions. So, thank you!
     
  8. 2004/06/17
    charlesvar

    charlesvar Inactive Alumni

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    Last edited: 2004/06/17
  9. 2004/06/17
    Kimberlee

    Kimberlee Inactive Thread Starter

    Joined:
    2004/04/25
    Messages:
    66
    Likes Received:
    0
    My OS is Win98. When I am in folder options - view, it doesn't give me the option to deselect "display the contents of system folders ". It does tell me that I can view hidden files and folders. Also, I have AVG as a virus scanner. The last time my system was in for repairs, my computer guy set it up so that AVG would do a "boot up scan" (this was a couple of months ago). I remember the first time I started the computer and I thought "this is great - it does a scan every time I start up the computer! ". I faithfully do updates on AVG every couple days, but I have never run a full scan :eek:

    I just did a full scan with AVG now and it tells me there was 1 infected file (the downloader.rehme one) and that it "healed" it. What exactly does this mean? Am I ok now? And since I have you here, :) does AVG scan for all kinds of pests or just certain ones?

    Thanks so much........
     
  10. 2004/06/17
    charlesvar

    charlesvar Inactive Alumni

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    Hi Kimberlee,

    I don't run AVG, but I can make some general comments:

    "Healed" here would mean the same, let's say in Norton AV, as repaired - meaning the file was stripped of it's infection.

    There should be also a quarantine option which means the AV didn't heal the infected file, but emptied it of it's contents and put that content into a folder where it's inert - can't execute.

    There should be a help file explaining this terminolgy in the AVG control panel.

    The major AV's do scan for things other than for viruses - someone familiar w/ AVG will have to give you more info or perhaps AVG's web site.

    Do you run Ad-Aware & SpyBot for other pests?

    http://www.lavasoft.de/software/adaware/ Download for Ad-Aware and do the full scan option.

    http://spybot.safer-networking.de/ SpyBot download and look thru this SpyBot thread below on this board http://www.windowsbbs.com/showthread.php?t=31729

    Regards - Charles
     
    Last edited: 2004/06/17
  11. 2004/06/17
    Kimberlee

    Kimberlee Inactive Thread Starter

    Joined:
    2004/04/25
    Messages:
    66
    Likes Received:
    0
    Thanks Charles. I do run Adaware and Spybot as well. Is it not true that these programs do find files, but that the damage is already done?

    Thanks
     
  12. 2004/06/17
    charlesvar

    charlesvar Inactive Alumni

    Joined:
    2002/02/18
    Messages:
    7,024
    Likes Received:
    0
    That's true of Ad-Aware free. There is a paid version of AAW that runs a resident preventive component - I think its called Pus.

    The new SSD - v1.3 - does have two new resident blocking components: SDHelper & Teatimer along w/ the immunize feature from v1.2

    Of course, that doesn't mean that something can't get thru. All these features, as with AV's, depend on signiture files of one sort or another. An endless war, I'm afraid.

    Regards - Charles
     
    Last edited: 2004/06/17
  13. 2004/06/17
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    This will work for 98, Restart in Dos Mode, and do these command.
    deltree C:\Windows\System\Atpart~1.dll
    Type a Y that you want to delete.

    I believe C:\Windows\System\Atpart~1.dll and C:\Windows\System\Atpartner.dll are the same file. The C:\Windows\System\Atpartner.dll has 9 letters in it's name, and dos is limited to 8 letters, the ~1 is used to make up the 8 letter name.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.