Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

new trojan!!!!!!!!!!!!! help please proffitt

Jun 13, 2005 4:36AM PDT

OS Loveph sp2
install:clean
cable connection with norton 2004 uptodate

so whenever i try to open IE and goto www.dictionary.com i get to that but if click on any links IE closes and iam pretty sure that this due to some spywares and to be precise a trojan infact
name is trojan.startup.nameshifter.h.trojan and only MS antispyware pciks this up
adaware found 95 and deleted them and spybought found 100 and them in safe mode
now everytime i run MS antispyware it says that this trojan is present and only msantispyware picks this
the location of the exe file is in program files and the name of the folder is some randomly generated one
for me it is utmtst and i cannot delete this folder
if i try to delete the startup entry from hklm\...\run
and then open regedit the entry is there once again
i tried to find the startup in hkr\comfile,hkr\piffile,hkr\batfile,hkr\htafile,hkr\pifile
i amm planning for hijack this next but the registry entry keeps coming
in normal mode i see that 2 exe's which are those trojans and i keep ending them and they reappear as soon as i end like svchost
i tried to rename the exe files to txt's but access denied
the name of the exe is RORsTS.exe and i believe that this is a randomly generated name
also i have system restore off and at this point i have no clue what to do next
i think if i could delete the folder i could get rid of this
if i scan the particular folder with NAV it says it is clean
i tried to take ownership of the folder and then tried to give full permission for the current user and every one and cannot even rename the folder
i get a message "access is denied" the message you get when you try to rename the softwaredistribution folder with automatic update turned on or BITS service turned on
so i have no clue what to do next may be i can try to delete the folder in recovery console after renaming the system file in recovery console so that i will have access to program files folder
the folder i am mentioning is the location of the exe file which is shown by MS antispyware
BTW i can open all the links in safe mode with n/w and reregistered hlink.dll as well
no error report in eventvwr

any ideas or suggesstions pleaseeeeeeeeee
i hope profitt will have an answer for this
and if any more info is required i am glad to give it
with regards
gopi

Discussion is locked

- Collapse -
2 things.
Jun 13, 2005 4:41AM PDT
- Collapse -
thanks bob and ......
Jun 13, 2005 5:51AM PDT

for your prompt response and i should have posted in virus forum but i knew you will reply promptly and also would have known some specific tool for this trojan something like stinger
and regarding the startup manager i will run and let you know the results
and i will post you the results if i could get rid of this nasty one
one question how good is stinger?
i mean is it only for the backdoor worms and its variants or for general trojans
and regarding mozilla i think this will be workaround bcos the trojan will still be there if i am not wrong
with regards
gopi

- Collapse -
Use stinger.
Jun 13, 2005 5:54AM PDT

It's a good tool that I've used in that suite without checking if the pest is there. I let it kill off what it finds along with the other tools, then we look again and maybe move to HIJACKTHIS.

As to another browser, it's not a workaround. It keeps many out of trouble.

Bob

- Collapse -
Absolutely
Jun 13, 2005 6:35AM PDT

I have had 0 problems since I started using Firefox. IE is good for 1 thing only, windows updates.