MajorGeeks Support Forums IOBit Software

Go Back   MajorGeeks Support Forums > Majorgeeks.Com - Support Forums > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Reply
 
Thread Tools Display Modes
  #1  
Old 10-05-10, 11:04
OwenMelbz OwenMelbz is offline
Private E-2
 
Join Date: Oct 2010
Posts: 7
Thanks: 1
Thanked 0 Times in 0 Posts
Default Another Ramnit Victim :(

After reading a few of the other threads about Ramnit with no success I'm giving up and turning to the big guns.

Im running
Windows 7 Ultimate 64bit.
Eset Smart Security 4
Firefox 3.6 (Sandboxed)

The story goes:

Found a random popup in the background of firefox with a women talking to me about something, wasnt listening and then a livejasmin.com popup behind that.
Then suddently nod32 popped up saying that a varient of win32.ramnit.b was messing with some .html files coming from firefox.exe.

So i terminated firefox n everything then Ran a quick malwarebytes scan which came up with nothing interesting on a quick scan. So ran CCleaner and tidied everything up (while running nod32 full system scan and windows defender scan in background)

Booted up firefox again and started browsing. then suddently nod started alerting me about more threads from random .exe/dlls/html files scattered throughout my PC.

Have Run MGTools, MalwareBytes, SuperAntiSpyware and CCleaner.

Still getting the nasty little poppu saying infected files. This all started from about 2pm Today (GMT) so only 2-3 Hours into the infection.

Hope we can catch it in time! coz a format is sort of..impossible at the moment. As was a Dell machine with vista on it. Then I purchased a Digital copy of w7 Upgrade (wont do fresh installs ) and this was what 7 was released so my w7 cdkey is for upgrade only. so id have to install vista again first(which came pre-installed) so cant install that from retail discs. yada yada yada, u get the point im sure?.

Hope we sort this out

Thank you.

PENDING ATTACHMENTS (SOME SCANS ARE STILL SCANNING! AS ITS SEARCHING 3TB OF DATA ON 4 PHYSICAL DISKS)
Reply With Quote
Sponsored links
  #2  
Old 10-05-10, 11:31
OwenMelbz OwenMelbz is offline
Private E-2
 
Join Date: Oct 2010
Posts: 7
Thanks: 1
Thanked 0 Times in 0 Posts
Default Re: Another Ramnit Victim :(

Cant edit my post? so this isnt a BUMP!

UAC is disabled but when MGTools says Complete your file is at c:\mglogs.zip the file doesnt exist.

EDIT: Manually zipped unkeys and runkeys
Attached Files
File Type: zip MGtools.zip (25.5 KB, 1 views)

Last edited by OwenMelbz; 10-05-10 at 11:37..
Reply With Quote
  #3  
Old 10-05-10, 14:22
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 44,610
Thanks: 377
Thanked 4,196 Times in 3,986 Posts
Default Re: Another Ramnit Victim :(

Please run an eSet online scan and repeat it each time it finds something. Attach each log in your next reply. You may need to run it 2 or 3 times:

eSet Online Scan.

When it comes back clean, then see if you can run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). Attach that log if it runs.
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
  #4  
Old 10-05-10, 15:12
OwenMelbz OwenMelbz is offline
Private E-2
 
Join Date: Oct 2010
Posts: 7
Thanks: 1
Thanked 0 Times in 0 Posts
Default Re: Another Ramnit Victim :(

Quote:
Originally Posted by TimW View Post
Please run an eSet online scan and repeat it each time it finds something. Attach each log in your next reply. You may need to run it 2 or 3 times:

eSet Online Scan.

When it comes back clean, then see if you can run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). Attach that log if it runs.
okay eset is running its online scanner now, ill update thread with full eset logs soon as.

below is the malwarebytes log, super anti spyware log and the previous post is the MGTools log, named MGtools.zip
Reply With Quote
  #5  
Old 10-05-10, 15:15
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 44,610
Thanks: 377
Thanked 4,196 Times in 3,986 Posts
Default Re: Another Ramnit Victim :(

MBAM indicates that you did not fix what it found. And your previous MGLogs.zip is missing numerous logs. That is why I said to run eSet until it was clean and then try to run the getlogs. bat.
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
Sponsored links
  #6  
Old 10-05-10, 16:18
OwenMelbz OwenMelbz is offline
Private E-2
 
Join Date: Oct 2010
Posts: 7
Thanks: 1
Thanked 0 Times in 0 Posts
Default Re: Another Ramnit Victim :(

Quote:
Originally Posted by TimW View Post
MBAM indicates that you did not fix what it found. And your previous MGLogs.zip is missing numerous logs. That is why I said to run eSet until it was clean and then try to run the getlogs. bat.
Woops, I saved a log before fixing the errors, and after but i uploaded the before fix log. Ive uploaded the latest one.

another woops, i simply downloaded someone elses mglogs.zip to see what files it included, apparently theirs wasnt full.

Ive sorted the permissions out which wouldnt let mgtools create file inside c:\ and have attached it below.

eset is still scanning, even though its been on 99% for about 40 mins now.

Thankyou for your patience.
Attached Files
File Type: txt mbam-log-2010-10-05 (19-17-18).txt (3.4 KB, 3 views)
File Type: zip MGlogs.zip (166.5 KB, 2 views)
Reply With Quote
  #7  
Old 10-05-10, 16:23
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 44,610
Thanks: 377
Thanked 4,196 Times in 3,986 Posts
Default Re: Another Ramnit Victim :(

Well, let's see what eSet finds.
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
  #8  
Old 10-05-10, 17:00
OwenMelbz OwenMelbz is offline
Private E-2
 
Join Date: Oct 2010
Posts: 7
Thanks: 1
Thanked 0 Times in 0 Posts
Default Re: Another Ramnit Victim :(

Quote:
Originally Posted by TimW View Post
Well, let's see what eSet finds.
here is the 1st eset scan (although called eset2) took 6 hours!! wooo

2nd scan log coming once its completed (most likely tomorrow morning for me) ie 8 hours time.
Attached Files
File Type: txt eset2.txt (4.5 KB, 2 views)
Reply With Quote
  #9  
Old 10-05-10, 17:03
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 44,610
Thanks: 377
Thanked 4,196 Times in 3,986 Posts
Default Re: Another Ramnit Victim :(

Quote:
Originally Posted by OwenMelbz View Post
2nd scan log coming once its completed (most likely tomorrow morning for me) ie 8 hours time.
Not a problem, I will be here.
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
  #10  
Old 10-06-10, 02:49
OwenMelbz OwenMelbz is offline
Private E-2
 
Join Date: Oct 2010
Posts: 7
Thanks: 1
Thanked 0 Times in 0 Posts
Default Re: Another Ramnit Victim :(

morning

Right eset online finished and chucked the attached log out.

then ran mg tools again and attached a new version of that

thanks :D
Attached Files
File Type: txt eset online.txt (808 Bytes, 1 views)
File Type: zip MGlogs.zip (156.8 KB, 1 views)
Reply With Quote
Sponsored links
  #11  
Old 10-06-10, 13:58
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 44,610
Thanks: 377
Thanked 4,196 Times in 3,986 Posts
Default Re: Another Ramnit Victim :(

Looks better. What issues are you currently having, if any?
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
  #12  
Old 10-06-10, 14:00
OwenMelbz OwenMelbz is offline
Private E-2
 
Join Date: Oct 2010
Posts: 7
Thanks: 1
Thanked 0 Times in 0 Posts
Default Re: Another Ramnit Victim :(

Quote:
Originally Posted by TimW View Post
Looks better. What issues are you currently having, if any?

nod32 keeps popping up saying Win32/Ramnit.B is in random files. but all scans show pretty clean apart from stuff i know about.
Reply With Quote
  #13  
Old 10-06-10, 14:01
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 44,610
Thanks: 377
Thanked 4,196 Times in 3,986 Posts
Default Re: Another Ramnit Victim :(

Run the eSet online scan one more time. We want to do this until it doesn't find anything.
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
Reply

Tags
64bit, ramnit, windows 7

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Ramnit.a infection wgodfrey Malware Removal 17 10-11-10 07:51
W32.Ramnit - Does anyone REALLY know what this does? latekhed Malware Removal 1 09-24-10 07:31
Ramnit.A infection stuartr Malware Removal 9 08-29-10 15:51
Ramnit.A - Help Needed! bnrcktts Malware Removal 1 08-08-10 14:56


All times are GMT -5. The time now is 02:17.


MajorGeeks.Com Home Page
| Admin Tools | All In One | Anti-Spyware | Anti-Virus | Appearance | Backup | Benchmarking | BIOS | Browsers | Covert Ops |
Data Recovery | Diagnostics | Drive Cleaners | Drive Utilities | Drivers | Driver Tools Ergonomics | Firewalls | Games | Game Tweaks | Graphics | Input Devices | Internet Tools | Macintosh | Mail Utilities | Memory | Messaging | Monitoring | Microsoft | Multimedia | Networking | Office Tools | Process Management | Processor | Registry | Security | System Info | Toys | Video | Miscellaneous
|

-->
Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger