Hello all - I'm in trouble with a new virus called RAMNIT.I

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by geze, Nov 27, 2010.

  1. geze

    geze Private E-2

    Hi folks,
    I know how to handle in a basic way my computer at home.
    This time I've got paralyzed by a virus called RAMNIT.I
    No major antivirus provider I checked has a specific definition yet.(McAfee, Karspersky, Microsoft)

    Any ideas?

    Thanks in advance,

    geze
     
  2. Colemanguy

    Colemanguy MajorGeek

    Goto the malware forum, run the read me and post your logs per the instructions, good luck!
     
  3. geze

    geze Private E-2

    Hi Major Geek,

    Here you have the first 4 items requested in the Procedure.

    One more to come.

    geze
     

    Attached Files:

  4. geze

    geze Private E-2

    Hi Major Geek,

    This is the 5th and lat log requested from Procedure.

    Please let me know if you want something else.

    Tks.

    geze
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please go here and start running back to back scans. Attach the first three so we can see how bad the infection is.
    eSet Online Scan.
     
  6. geze

    geze Private E-2

    Hi Major Geek

    Disregard this question.




    geze
     
    Last edited: Nov 27, 2010
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should be able to, but let me give you this warning after looking at your other logs:

    Ramnit infections have really become quit nasty and dangerous. We could attempt to remove it, and we have had some success in the past, but recently it has become even more trouble to remove. It is really safer to just bite the bullet and do a clean reinstall.

    The problem is that the damage caused by this infection really makes a PC unreliable/untrustworthy. PE file infectors like Ramnit, Virut,.... etc can infect all executable files (DLL, EXE, SCR....and many more and also HTML). These infections can open back doors that truly may compromise your computer and your security. These backdoors could allow a remote attacker to access and instruct the infected computer to download and execute more malicious files.

    In many cases the infected files (which could number in the thousands) cannot be disinfected properly by your anti-virus or by other scanning tools. Also when disinfection is attempted, the files often become corrupted and the system may become unstable or irrepairable. The longer Ramnit remains on a computer, the more files it may infect and/or corrupt so the degree of infection can vary.

    Ramnit is commonly spread via a flash drive (usb, pen, thumb, jump) infection where it copies the Ramnit worm using a random file name. The infection is often contracted by visiting remote, crack and keygen sites. These type of sites are a major source of system infection.

    So all the above being said, and please do take serious note of the warnings, do you really wish to attempt cleaning even though the stability and security of your be cannot be guaranteed? And also note that we could spend a lot of time trying to fix it and still fail due to the number of files that have been infected. What would you like to do?
     
  8. geze

    geze Private E-2

    Hi TimW,

    I'm answering from my laptop.
    The infected PC we are discussing still on ESET Online Scanner (almost 19 hours now).
    I'll send the scan as soon is ready.

    In this time, I'm considering seriously your suggestion of a clean start, reinstalling Windows XP, but before to decide let me ask you the following:

    1- Can I recover the following file types: .doc ; .dwg ; .jpg ; .pdf ?
    2- If yes #1, what is the procedure to save them? Copying to an external Hard Drive and then running antivirus on the external hard drive afterwards?

    geze
     
  9. geze

    geze Private E-2

    Hi TimW,

    Here you have the ESETScan.

    Tks.

    geze
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, that would be the best procedure. I think we are probably too late in trying to fix this infection and a reformat and clean install would be the best avenue to take.
     
  11. geze

    geze Private E-2

    Hi TimW,

    What is the proper procedure to clean up an external hard drive and an USB stick?
    What is the software recommended?

    geze
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What are you meaning by "clean up"? Do you want to just reformat them so they can be used for doing the backups? If so, you can just right click on each drive and choose reformat.
     
  13. geze

    geze Private E-2

    Hi TimW,

    Sorry, I formulated my question wrong.

    This is the case:

    A- I have to copy (before to format the hard drive) my working files to an external HD.
    B- After that copy, I would like to make sure that in the external HD there are no viruses transfered from the infected pc.
    C- Do you reccomend any particular procedure and antivirus to deal with potentials Ramnit viruses transfered to the external HD?

    Is this question reasonable?

    geze
     
  14. geze

    geze Private E-2

    Thank you, TimW for all the time and energy invested in your website and helping others.
    I've learned a lot in the past week.

    Kind regards,

    geze
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you can transfer to the external, reformat your hard drive and do the clean install. Then once you have all your protection software installed and updated, re-run eSet scan with the external plugged in. Also run your AV software as well as SAS and MBAM on the external before replacing the files.
     
  16. geze

    geze Private E-2

    Thanks a lot again, TimW, much appreciated.

    Cheers,

    geze
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Hope it all works out for you. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds