Ramnit A + H.virus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by rkane3000, May 19, 2011.

  1. rkane3000

    rkane3000 Private E-2

    This has hit my PC today but the symptoms are little different from what I've seen on other threads.

    I have ESET and the quarantine section is filling up literally every 5 seconds with a new threat, that is cleaned then put in there. At the moment I am using safe mode so do not see any attempts coming through.

    I have done a scan (attached) but this produced no threats at all, which I thought was strange. However, when I tried to open the log it crashes, as you can see in the image, it produces the bottom line result of items scans/threats etc but little other detail because "decompression could not complete. insufficient free memory or disc space". This is all in temp files, where the threats have been hitting.

    The only real symptom is the redirection to other sites on Firefox and my pc slowing down to deal with the constant quarantining of these threats?

    I understand that given the nature of Ramnit, a reinstall of Windows is the best solution but is that needed in this case and if not, then what can I do next to stop this?
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run this three times back to back and attach the results.

    Using ESET's Online Scanner

    I think a reinstall will probably be the best way to go though :(
     
  3. rkane3000

    rkane3000 Private E-2

    I've run the scan twice so far, the first time bought up 5 threats, the second time is clear - I will run a third time.

    However, once the scan finishes, I see no option to view the log or the threats to export it?
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please read ALL of this message including the notes before doing anything.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  5. rkane3000

    rkane3000 Private E-2

    Ah sh*t! Hate having to go through all this but will do, thanks for the info.

    I'll come back once I have the logs etc.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It might be a PITA however, what would be more of a PITA is if I simply told you to reinstall without fully knowing whether that is necessary or not. Sometimes people get lucky with Ramnet. Sometimes not, let's see what the case is for you.
     
  7. rkane3000

    rkane3000 Private E-2

    No I appreciate that, just moaning a little that's all :)

    I was going through the initial steps and deactivated UAC.

    After the restart back into Safe Mode, immediately after logging on it opens up an IE page and my desktop is completely wiped, nothing on there bar my Recylce Bin and desktop.ini file?

    Firefox has been wiped too, no bookmarks etc basically as if I had just installed it.

    Is a reinstall looking the best option? I have no idea what just happened.
     
  8. rkane3000

    rkane3000 Private E-2

    turned uac back on to see if that made a difference, it didn't so I booted back in safe mode but now can't turn uac off, i click on the option but it does nothing.

    i think a reinstall is looking the best.

    Previous to all the original wiping of my desktop, i had downloaded all the necessary apps for scanning, so they have gone too.
     
  9. rkane3000

    rkane3000 Private E-2

    I've attached logs for Combo, MWB and SaS. I couldn't get RootRepeal and MGTools to run, so have no logs for them.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, let's take our throughts away from the reinstall at the moment. I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run

    Doesn't matter that Rootrepeal will not run, but I would like to try and get MGTools to run. Try this:

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.

    Do you have logs from running those now?
     
  11. rkane3000

    rkane3000 Private E-2

    The log for TDSSkiller is attached, I still cant get MGtools to run, I've attached the screen grab for the error message it gives me.

    I am currently logged in as an admin via safe mode.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  13. rkane3000

    rkane3000 Private E-2

    Here are both of the logs
     

    Attached Files:

  14. rkane3000

    rkane3000 Private E-2

    sorry, here's the screen grab from MGTools from a little earlier
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Running from: c:\windows\system32\config\systemprofile\Desktop\ComboFix.exe <--- Combofix needs to be run directly from your desktop not where you have it. Please move it there before we continue.

    Java(TM) 6 Update 22 <--- uninstall outdated java

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\Windows\jautoexp.dat
    C:\ProgramData\ubu1g06qna22xo0d6g4fsrfg2do
    C:\ProgramData\q8d0koh7sty104n886j5381r151ce1n85cl3o47
    C:\ProgramData\~22994704r
    C:\ProgramData\~22994704
    C:\ProgramData\22994704
    c:\users\Rkane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mkyavjcm.exe
    c:\windows\is-J6VLO.exe
    C:\Windows\is-J6VLO.msg
    C:\Windows\is-J6VLO.lst
    Folder::
    c:\program files\eehnljsv
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "InnoSetupRegFile.0000000001"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    Go to C:\MGTools.exe and rename it to jumping.com so you have C:\jumping.com and see if it will run in order to produce a C:\MGlogs.zip. If it really will not then you will need to run OTL again as you did last time and attach the log.

    How are things running now?
     
  16. rkane3000

    rkane3000 Private E-2

    Combofix was downloaded to my desktop and has remained there since, that was the place I have run it from, I can assure you.

    As my desktop was completely wiped on safe mode yesterday, all I have had on there since yesterday are the various programmes and logs I've downloaded. See the screenshot...
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Attach the requested logs please and then we will deal with any remaining issues afterwards.
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do NOT, I repeat do not, run any temp file cleaner such as Ccleaner. Do not delete temp files manually yourself either.
     
  19. rkane3000

    rkane3000 Private E-2

    No I definitely won't, I am following your instructions as closely as possible. I only have CC cleaner on my normal desktop, not on my safe mode.

    I will rerun Combo again from desktop and post log.
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You do not need to re run it, you just need to follow my instructions and run the script I gave you. :) We are going to have to see what's going on in normal mode too soon.
     
  21. rkane3000

    rkane3000 Private E-2

    Sorry, that's what I meant, run combo via your instructions.

    Attached is the log for combo and zip for MGTools logs.

    Btw i've logged into normal mode, now and can see an improvement as my ESET is no longer being peppered every 5 seconds with threats.
     

    Attached Files:

  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to put ComboFix DIRECTLY on your desktop, not here:
    Running from: c:\windows\system32\config\systemprofile\Desktop\ComboFix.exe

    Your MGLogs. did not populate as it should have. Did you allow it to run until it told you it was finished?

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2


    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      smtmp*
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * System look log
    * C:\MGlogs.zip
     
  23. rkane3000

    rkane3000 Private E-2

    As you can see in my screenshot below, my combofix is directly on my desktop, as it has been since the DL. The screenshot has the properties window open and it still shows this same location. I have attached it again to this post. I understand that the log earlier showed that it was placed somewhere else but the image shows where it has remained.

    I originally let MGlogs run by itself until it was finished, with no interference and have just done so again.

    Both times I have run MGTools and have had no licence agreement to agree to. The second time I located GetLogs.bat file, right click, run as admin and it went straight to the CMD screen to run.
     

    Attached Files:

  24. rkane3000

    rkane3000 Private E-2

    sorry, this is the screen grab
     

    Attached Files:

  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please do this, click Start, Run and enter cmd and click OK. This will open a command prompt window. In the command prompt window, enter the below commands each followed by the enter key. Note there is a space after the cd

    cd \MGtools
    GetLogs.bat

    Does this produce a C:\MGlogs.zip? Hopefully a complete set of logs this time ;)
    How is the desktop situation in normal mode? Everything as it should be?
     
  26. rkane3000

    rkane3000 Private E-2

    When i run it via this method, once I enter:

    cd \MGtools
    GetLogs.bat

    It states access denied and Registry Editor repeatedly appears to ask for permission, again and again and....

    Unfortunately, it produces no log as request after request appears.

    With regards to my normal desktop, all is normal and no more threats from Ramnit appearing every 5 seconds.
     
  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK then let's go with OTL instead. Run that again and attach the log like you did before. :)
     
  28. rkane3000

    rkane3000 Private E-2

    Here's the OTL scan.

    This was run in normal mode and I noted that the location of Combofix on my desktop now reads C:\Users\Rkane\Desktop. Perhaps the previous location was due to it being run in safe mode?
     

    Attached Files:

    • OTL.Txt
      File size:
      80.6 KB
      Views:
      3
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It will be a while until Kestrel is back on. What malware issues are you still having, if any?
     
  30. rkane3000

    rkane3000 Private E-2

    Since the last combofix scan, I have been running in normal mode with no issues that I can see.
     
  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let us know if you start having any malware issues. In the meantime:

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  32. rkane3000

    rkane3000 Private E-2

    Sure, will do.

    Given the severity of Ramnit, I was considering a reinstall of Windows as the best option - how am I able to check if I have been lucky in getting rid of this completely?
     
  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Given the fact that Eset is not finding any more infected files, I'm pretty well sure you are clean. Nothing is showing up in any of your logs, so unless you are just still uncertain that you are clean, a reformat and install is probably not needed. But it is up to you.

    We always suggest that after an infection, you use a different computer to change all your online passwords. ;)
     
  34. rkane3000

    rkane3000 Private E-2

    Ok guys, thanks for all your help :)
     
  35. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. ;)
     
  36. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello there. If the below folders exist still...

    • C:\Users\Rkane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Vista Recovery
    • C:\Users\Rkane\AppData\Local\ubu1g06qna22xo0d6g4fsrfg2do
    • C:\Users\Rkane\AppData\Local\q8d0koh7sty104n886j5381r151ce1n85cl3o47

    You need to use Windows Explorer to delete them. Reboot the machine > check back to their locations and tell us whether they are gone for good or if they are still there.
     
  37. rkane3000

    rkane3000 Private E-2

    Hey Kes.

    I did find Windows Vista Recovery. I did not find C:\Users\Rkane\AppData\Local\ubu1g06qna22xo0d6g4fsrfg2do in this location but I did find through searching:

    ubu1g06qna22xo0d6g4fsrfg2do.vir in C:\Qoobox\Quaratine\C is this Combofix quarantine?

    I also found q8d0koh7sty104n886j5381r151ce1n85cl3o47.vir in the same Qoobox location.

    I am still confused about this Combofix issue, as I have only DL and run it from the desktop. Yet when I followed the instructions set below by TimW to uninstall it, it could not locate it. I understand that indicates it was not run on the desktop but I insist it was!

    Should running Combo in safe mode affect it in anyway?
     
    Last edited: May 22, 2011
  38. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm, if you have not followed final steps yet then please do the following.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    c:\windows\system32\config\systemprofile
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.
     
  39. rkane3000

    rkane3000 Private E-2

    Ok, this time I ran this procedure in normal mode so hopefully the log is as it should be.

    C:\Users\Rkane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Vista Recovery

    q8d0koh7sty104n886j5381r151ce1n85cl3o47.vir

    ubu1g06qna22xo0d6g4fsrfg2do.vir



    are still in Qoobox quarantine.
     

    Attached Files:

  40. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes. I should have noticed this myself. Never mind. All is well :) You can definately follow final steps.
     
  41. rkane3000

    rkane3000 Private E-2

    Ah, so the confusion on it's location was due to it being run in safe mode?

    Will run through those steps now.

    Thanks so much for your help.

    So I guess I've been pretty lucky with Ramnit.
     
  42. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes ;)

    You were very lucky, most ramnit victims wind up reformatting. :)
     
  43. rkane3000

    rkane3000 Private E-2

    I think I saw it quite quickly and caught most of it in quarantine and switched to safe mode so that helped.

    A massive thank you again, once again you guys saved my ***!

    :)
     
  44. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. Safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds