W32/Ramnit.a and W32/Ramnit.b - HELP!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by xZx, Jul 7, 2011.

  1. xZx

    xZx Private E-2

    About a week ago, my McAfee On Access Scanner kept popping up with messages saying that I was infected with W32/Ramnit.a and W32/Ramnit.b. I have done everything in the "Read and Run Me First" sticky and have attached the relevant logs below.

    Any help/advice on how to remove this infection would be greatly appreciated :)
     

    Attached Files:

  2. xZx

    xZx Private E-2

    More logs...
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please go here and start doing the online scans. Reboot after each scan and then attach the logs. You should run it three times!!
    eSet Online Scan.
     
  4. xZx

    xZx Private E-2

    Thank you for your response and sorry that I've taken so long to reply :). I've managed to run the ESET online scan twice (rebooting after each time)and have attached the logs.

    However, I couldn't run it a third time as it kept saying that it "cannot get updates. Is proxy configured?" My internet connection was working perfectly well and both IE8 and Firefox were working. I also don't use a proxy so I have no idea why it wasn't working.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ramnit infections have really become quit nasty and dangerous. We could attempt to remove it, and we have had some success in the past, but recently it has become even more trouble to remove. It is really safer to just bite the bullet and do a clean reinstall.

    The problem is that the damage caused by this infection really makes a PC unreliable/untrustworthy. PE file infectors like Ramnit, Virut,.... etc can infect all executable files (DLL, EXE, SCR....and many more and also HTML). These infections can open back doors that truly may compromise your computer and your security. These backdoors could allow a remote attacker to access and instruct the infected computer to download and execute more malicious files.

    In many cases the infected files (which could number in the thousands) cannot be disinfected properly by your anti-virus or by other scanning tools. Also when disinfection is attempted, the files often become corrupted and the system may become unstable or irrepairable. The longer Ramnit remains on a computer, the more files it may infect and/or corrupt so the degree of infection can vary.

    Ramnit is commonly spread via a flash drive (usb, pen, thumb, jump) infection where it copies the Ramnit worm using a random file name. The infection is often contracted by visiting remote, crack and keygen sites. These type of sites are a major source of system infection.

    So all the above being said, and please do take serious note of the warnings, do you really wish to attempt cleaning even though the stability and security of your be cannot be guaranteed? And also note that we could spend a lot of time trying to fix it and still fail due to the number of files that have been infected. What would you like to do?

    You are highly infected, so the best suggestion I can give you would be to do a clean install. :(
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds