![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
i have been hit hard by the following viruses
Win32/Ramnit.A /B /C attached is the log file from eset i followed your instruciton from other posts, i have combo installed, i ran the ESET once and it found 10,000 infected files and are now safe in Quarantine. What would my next step be, i would really appreciate your input and HELP. thanks David |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
Run eSet online scanner again. Each time it finds something, save the log and attach it, but go ahead and run the scan a second time. Then a third time until it comes up clean. Attach all those logs.
In the meantime, please follow these instructions: READ & RUN ME FIRST. Malware Removal Guide
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
|
#3
|
|||
|
|||
|
made 1 scan with super antispyware
and 1 with malwarebytes here are the logs |
|
#4
|
|||
|
|||
|
round 2 of ESET
your help is so much appreciated AROUND THE WHOLE WORLD KEEP UP WITH YOUR GREAT CAUSE OF MAKING PEOPLE SMILE EVERY DAY! THANKS DAVID |
|
#5
|
||||
|
||||
|
Please run it until you get a clean log. Attach each scan result and when you are clean, we may need to reinstall some of your programs.
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
| Sponsored links |
|
|
|
#6
|
|||
|
|||
|
i wish to take this moment
TO THANK YOU FOR ALL YOUR SUPPORT!.. i ran eset and its all clear. Finally what would you sugest is best to prevent this from happening again many thanks David |
|
#7
|
||||
|
||||
|
I would like to see a new MGLogs.zip just to be sure. You can run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).
Then attach the below logs: * C:\MGlogs.zip
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
|
#8
|
|||
|
|||
|
thanks
|
|
#9
|
||||
|
||||
|
You are far from clean, so let's do this:
Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished): Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now: Quote:
* Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it! If it is not on your Desktop, the below will not work. * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly. * If ComboFix tells you it needs to update to a new version, make sure you allow it to update. * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ): Code:
KILLALL::
RenV::
c:\program files\AVG\AVG9\avgtray .exe
c:\program files\Malwarebytes' Anti-Malware\mbam .exe
Folder::
C:\Documents and Settings\delluser\Application Data\Udqudu
C:\Program Files\aw
C:\Program Files\aw1
C:\Program Files\ses
C:\Program Files\sys1
C:\Program Files\sys2
C:\Program Files\sys4
C:\Program Files\sys5
c:\documents and settings\delluser\Application Data\Mukuv
c:\documents and settings\delluser\Application Data\Cyray
c:\documents and settings\delluser\Application Data\Goug
c:\documents and settings\delluser\Application Data\Apywgu
c:\documents and settings\delluser\Application Data\Duboyk
c:\documents and settings\delluser\Application Data\Ekrev
C:\Documents and Settings\delluser\Application Data\Uwanto
C:\Documents and Settings\delluser\Application Data\Enefgu
C:\Documents and Settings\delluser\Application Data\Owuta
Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"{80486FC6-62B2-35A5-0D77-61CB6BEF6DB1}"=-
"{6D567A04-D4AC-D79A-F33C-148A56312B02}"=-
"{664425DD-AF52-5DD2-BD4D-DCFFA4533C69}"=-
"Amotul"=-
"{775F5E89-80AD-D456-2EC6-C334E3BEB9F5}"=-
* At this point, you MUST EXIT ALL BROWSERS NOW before continuing! * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop. If it asks you to overide the previous file with the same name, click YES. * Now use your mouse to drag CFscript.txt on top of ComboFix.exe * Follow the prompts. * When it finishes, a log will be produced named c:\combofix.txt * I will ask for this log below Note: Do not mouseclick combofix's window while it is running. That may cause it to stall. Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). Then attach the below logs: * C:\ComboFix.txt * C:\MGlogs.zip
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
|
#10
|
|||
|
|||
|
i am really amazed by your dedication to help me out, thanks again on behalf of all of us.
David |
| Sponsored links |
|
|
|
#11
|
||||
|
||||
|
Looks good. Just use windows explorer to find and delete:
c:\documents and settings\delluser\Application Data\Uqynic C:\WINDOWS\Ybajobecebepaguh.dat If you are not having any other malware problems, it is time to do our final steps:
Support MajorGeeks with Geek Wear!
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Win32.Ramnit.C Problems | ESRaistlin | Malware Removal | 30 | 10-14-10 18:35 |
| Very persistent virus/worm Ramnit | Rattus | Malware Removal | 29 | 08-12-10 12:36 |
| Persistent ramnit.a virus | magnani | Malware Removal | 25 | 08-06-10 16:12 |