Another WIn32/Ramnit infection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by nunoH, Apr 12, 2011.

  1. nunoH

    nunoH Private E-2

    Hello everybody, I just read a couple of threads on here and you seem like a helpful bunch. Whenever I get infections I usually cope by just reading someone elses thread, but this one seems like it needs more attention.

    I just got some kind of browser hijacker earlier today, managed to clean it up with mbam and eset online. In the end I did scans with spybot and mbam and the results shwoed no infections. Just to make sure I did a scan with Avira free edition and all of a sudden it started beeping like crazy with a Ramnit.C infection plus some weird html viruses? Most of these were infected Adobe CS5 files and a whole new directory on my cameras memory card which was plugged in (i deleted the folder straight away and ejected the card).

    I am currently in safe mode and started doing another eset online scan, 15mins so far and already one threat, this time not Ramnit.C, but Ramnit.A?!

    Any hints on how should I proceed? Should I keep doing eset until its clean? And whats with all the infected files in my Adobe CS5, can Eset fix them?

    Thank you in advance!

    Edit: 20mins on the first Eset online scan and it found a second threat - 'a variant of Win32/Kryptik.MOD trojan'.
     
    Last edited: Apr 12, 2011
  2. nunoH

    nunoH Private E-2

    Ok, its currently scanning the Adobe program files folder with 3500 infected files so far. I really hope I can fix that...
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Yes you need to run ESET's Online scans a minimum of 3 times however please take note of the below warning about Ramnit infections.



     
  4. nunoH

    nunoH Private E-2

    Thanks for the quick reply. I am aware of that, but have to give it a go anyway... So far things dont look good. I uninstalled programs with major folders infected (Like all adobe products, ATI drivers and tools). However, the infection has spread faster than expected. Im on my 6th ESET run, and threats found seem to be randomly changing. On 2nd and 4th run things seemed to have gone quiet, however on all other runs at least 2k threats have been found. I am gonna do a couple more runs for the sake of it and then if theres no change to the situation Im gonna head to the pc store to get an external hard drive to try and save some pictures/music/movies (careful not to copy the infection).

    EDIT: Log from ESET online added.
     

    Attached Files:

    • log.zip
      File size:
      60.6 KB
      Views:
      2
    Last edited: Apr 13, 2011
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Correct assesment. A reinstall is highly recommended. Your system has been extremely compromised.

    Yes this is what Ramnit and other PE file infectors do and that is the reason why reinstalls are needed. And in addition, this infection opens up backdoors on your PC which means your security may have been totally compromised.

    You must be extremely careful on what is backed up and reused because just 1 bad file could start the whole process over again. Whatever you backup, make sure that you scan that copied files with ESET Online by scanning the external drive. If you put any executable or html type files on the external drive and if you access that drive from this infected PC, you will infect the files.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds