Rameh.b trojan NOD canot remove

Discussion in 'NOD32 version 2 Forum' started by Huwge, Oct 13, 2004.

Thread Status:
Not open for further replies.
  1. Huwge

    Huwge Guest

    I've just downloaded the trial version after uninstalling NAV. NOD has found the following file C:\Windows\System\shnahiatt.dll-Win32/Trojandownloader.Rameh.B trojan. NOD says it cannot clean this file and gives me the option to delete, rename or leave.

    Help please !
     
  2. Blackspear

    Blackspear Global Moderator

    Joined:
    Dec 2, 2002
    Posts:
    15,115
    Location:
    Gold Coast, Queensland, Australia
    Hi Huwge can you follow the steps located here.

    These steps are fairly comprehensive and should make sure your system is clean...

    Lets us know how you go...

    Cheers :D
     
  3. Huwge

    Huwge Guest

    Thanks for the fast reply. I run Win98SE which is not supported by Ewidio. I run Sygate FW. Will NOD be able to remove the infection if I run it in safe mode ?.

    Thanks
     
  4. Blackspear

    Blackspear Global Moderator

    Joined:
    Dec 2, 2002
    Posts:
    15,115
    Location:
    Gold Coast, Queensland, Australia
    Yes, that post is a good general one for cleaning and confirming that a system is clean, it also has some world class prevention and removal tools in regards to spyware...

    Cheers :D
     
  5. Huwge

    Huwge Guest

    Thanks for the fast reply. Unfortunately it wasnt plain sailing. When I clicked on Nod32 I got the blue screen of death and then a black screen with a cursor and HDlight constantly on, had to reset. Any other suggestions please ?

    Thanks
     
  6. Blackspear

    Blackspear Global Moderator

    Joined:
    Dec 2, 2002
    Posts:
    15,115
    Location:
    Gold Coast, Queensland, Australia
    Nod32 gave you the option of deleting, use that option, then try another reboot into safe mode and a further scan...

    Cheers :D
     
  7. Blackspear

    Blackspear Global Moderator

    Joined:
    Dec 2, 2002
    Posts:
    15,115
    Location:
    Gold Coast, Queensland, Australia
    Failing this, there are further removal instructions here

    Cheers :D
     
  8. Huwge

    Huwge Guest

    I deleted the item before I saw the last post. I still get the crash in Safemode with NOD but scan now shows up clean. Only other change I noticed is that the floppy light comes on for a few seconds just before the Desktop shos up on screen. Hopefully that trojan is gone now
     
  9. Blackspear

    Blackspear Global Moderator

    Joined:
    Dec 2, 2002
    Posts:
    15,115
    Location:
    Gold Coast, Queensland, Australia
    As Nod32 has been placed on a compromised system, can you continue with the steps in the above thread, leave out Ewido and Safe Mode, download the other programs, update and run them, this will confirm your system is clean...

    Let us know how you go...

    Cheers :D
     
    Last edited: Oct 13, 2004
  10. Huwge

    Huwge Guest

    Everything shows all clear now.....thanks. One quick question, I dont see EMON anywhere. I am on broadband and run Outlook Express. Is it disabled in the Trial Version or am I missing something?

    Thanks
     
  11. Blackspear

    Blackspear Global Moderator

    Joined:
    Dec 2, 2002
    Posts:
    15,115
    Location:
    Gold Coast, Queensland, Australia
    Good to see everything is now clean.

    EMON is for MS Outlook only.

    Cheers :D
     
  12. jayt

    jayt Registered Member

    Joined:
    Aug 30, 2004
    Posts:
    345
    Location:
    PA - USA
    Just a suggestion. Since you are running Win9x, you might want to download and use A2 squared. It works on Win9x and is almost as good as ewido, and it is free. :D

    You can find it here: http://www.emsisoft.com/en/software/free/
     
  13. Blackspear

    Blackspear Global Moderator

    Joined:
    Dec 2, 2002
    Posts:
    15,115
    Location:
    Gold Coast, Queensland, Australia
    Thanks for that JayT, I'm adding it to that thread for Win98 users.

    Cheers :D
     
  14. jayt

    jayt Registered Member

    Joined:
    Aug 30, 2004
    Posts:
    345
    Location:
    PA - USA
    You are more than welcome Blackspear. After all the help you guys have given me, I am happy to be able to contribute something to the forum. :)
     
Thread Status:
Not open for further replies.