Warning: iconv_mime_decode() [function.iconv-mime-decode]: Malformed string in /home/secureg/public_html/lib/standard.lib.php on line 2251
trojan.startup.nameshifter.EW/wingu/EZ
trojan.startup.nameshifter.EW/wingu/EZ

trojan.startup.nameshifter.EW/wingu/EZ

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
trojan.startup.nameshifter.EW/wingu/EZ ML 08-16-2005
Posted by =?Utf-8?B?TUw=?= on August 16, 2005, 6:11 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello,

Microsoft AntiV picked up the above referenced trojans, with over 100,000
certificates/signatures. MAV keeps freezing during the removal process and I
can't remove them. Anyone have ideas on removal?

M.

Posted by David H. Lipman on August 16, 2005, 6:36 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Hello,
|
| Microsoft AntiV picked up the above referenced trojans, with over 100,000
| certificates/signatures. MAV keeps freezing during the removal process and I
| can't remove them. Anyone have ideas on removal?
|
| M.

Microsoft AV ? { snickers }


Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

It is a self-extracting ZIP file that contains the Kixtart Script Interpreter {
http://kixtart.org Kixtart is CareWare } three batch files, five Kixtart
scripts, one Link
(.LNK) file, a PDF instruction file and two utilities; UNZIP.EXE and WGET.EXE.
It will
simplify the process of using; Sophos, Trend and McAfee Anti Virus Command Line
Scanners to
remove
viruses, Trojans and various other malware.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal
Mode. This
way all the components can be downloaded from each AV vendor’s web site.
The choices are; Sophos, Trend, McAfee, Exit the menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you
can
download the files and perform a scan in Normal Mode. Once you have downloaded
the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode
[F8 key
during boot] and re-run the menu again and choose which scanner you want to run
in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive
PDF help
file.

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
FireWall to allow it to download the needed AV vendor related files.

* * * Please report back your results * * *

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by =?Utf-8?B?TUw=?= on August 22, 2005, 5:16 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Dave and Ron,

Thanks to both of you for your help. I've kicked most of the 50+ viruses,
trojans, spyware, etc, etc, that my 15 year old nephew downloaded with his
with "free" software from Kaaza. What a mess!

Here'a an update on your suggestions:

Multi AV tool worked beautifully (like it's ability to remove infected files
as it scans vs waiting until the end to remove). I used McAfee and Trend and
removed most of the spyware and trojans.

MS AntiSpyware- running it in Safe mode did the trick! The freezing was due
to its using up a LOT of memory. I was impressed that MAS picked up a number
of trojans and spyware that Multi AV, Adaware, Spybot, Stinger didn't
...among them lolita, armageddon, coolwebsearch and a bunch of others I can't
recall right now.

Thanks again, both suggestions were extremly useful.

ML.

"David H. Lipman" wrote:

>
> | Hello,
> |
> | Microsoft AntiV picked up the above referenced trojans, with over 100,000
> | certificates/signatures. MAV keeps freezing during the removal process and I
> | can't remove them. Anyone have ideas on removal?
> |
> | M.
>
> Microsoft AV ? { snickers }
>
>
> Download MULTI_AV.EXE from the URL --
> http://www.ik-cs.com/programs/virtools/Multi_AV.exe
>
> It is a self-extracting ZIP file that contains the Kixtart Script Interpreter {
> http://kixtart.org Kixtart is CareWare } three batch files, five Kixtart
scripts, one Link
> (.LNK) file, a PDF instruction file and two utilities; UNZIP.EXE and WGET.EXE.
It will
> simplify the process of using; Sophos, Trend and McAfee Anti Virus Command
Line Scanners to
> remove
> viruses, Trojans and various other malware.
>
> C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
> This will bring up the initial menu of choices and should be executed in
Normal Mode. This
> way all the components can be downloaded from each AV vendor’s web site.
> The choices are; Sophos, Trend, McAfee, Exit the menu and Reboot the PC.
>
> You can choose to go to each menu item and just download the needed files or
you can
> download the files and perform a scan in Normal Mode. Once you have downloaded
the files
> needed for each scanner you want to use, you should reboot the PC into Safe
Mode [F8 key
> during boot] and re-run the menu again and choose which scanner you want to
run in Safe
> Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.
>
> When the menu is displayed hitting 'H' or 'h' will bring up a more
comprehensive PDF help
> file.
>
> To use this utility, perform the following...
> Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
> Choose; Unzip
> Choose; Close
>
> Execute; C:\AV-CLS\StartMenu.BAT
> { or Double-click on 'Start Menu' in C:\AV-CLS }
>
> NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
> FireWall to allow it to download the needed AV vendor related files.
>
> * * * Please report back your results * * *
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>
>

Posted by David H. Lipman on August 22, 2005, 6:02 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Dave and Ron,
|
| Thanks to both of you for your help. I've kicked most of the 50+ viruses,
| trojans, spyware, etc, etc, that my 15 year old nephew downloaded with his
| with "free" software from Kaaza. What a mess!
|
| Here'a an update on your suggestions:
|
| Multi AV tool worked beautifully (like it's ability to remove infected files
| as it scans vs waiting until the end to remove). I used McAfee and Trend and
| removed most of the spyware and trojans.
|
| MS AntiSpyware- running it in Safe mode did the trick! The freezing was due
| to its using up a LOT of memory. I was impressed that MAS picked up a number
| of trojans and spyware that Multi AV, Adaware, Spybot, Stinger didn't
| ...among them lolita, armageddon, coolwebsearch and a bunch of others I can't
| recall right now.
|
| Thanks again, both suggestions were extremly useful.
|
| ML.
|

Thank you for updating the thread.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by Ron Chamberlin on August 16, 2005, 8:33 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi ML,
Boot into Safe Mode (F8) at startup;
Empty your temporary files AND your Temporary Internet Files* C:\Documents
and Settings\Username\Local Settings\Temporary Internet Files folder ;
Run the scan while in safe mode;
If you are running SP2, open IE--->Tools--->Manage Add-ons, and uncheck any
BHO's that you don't recognize.

Ron Chamberlin
MS-MVP



*The .tif are Temporary Internet Files, and are stored in a different barn
than 'normal' temp files.
Here's how I kludge thru to them: Open Windows Explorer--->C:\Documents and
Settings. Then it's to the Tool Bar--->Folder Options--->View--->Hidden
Files and Folders and check the box "Show hidden files and folders" > Now
expand C:\Documents and Settings and under each user you will now see a
folder "Local Settings". Open that puppy and choose Temporary Internet
Files. I am not concerned about the cookies therein, but everything else
can go for now.

> Hello,
>
> Microsoft AntiV picked up the above referenced trojans, with over 100,000
> certificates/signatures. MAV keeps freezing during the removal process and
> I
> can't remove them. Anyone have ideas on removal?
>
> M.



Similar ThreadsPosted
wvurs.dll Trojan.Startup.NameShifter.HN January 6, 2006, 1:19 am
trojan.bho.nameshifter.dk July 22, 2005, 12:46 pm
WinXP, trojan hidden startup locations??? April 10, 2007, 8:47 am
BLock Programs From Startup August 12, 2005, 3:51 pm
A new startup process SlowDowncpu.exe gets added July 20, 2005, 1:36 am
aim virus: my startup acts like its being used for the first time September 28, 2005, 6:00 pm
error message on startup 'windows can't find January 7, 2006, 10:47 pm
Trojan August 2, 2005, 8:42 pm
Trojan August 19, 2005, 6:31 pm
trojan by icq November 4, 2005, 6:40 am

The site map in XML format XML site map

Contact Us | Privacy Policy